From 3ed0a48159b9500af1feda0915d0d5b31330d9f6 Mon Sep 17 00:00:00 2001 From: curben-bot <3048979-curben-bot@users.noreply.gitlab.com> Date: Mon, 12 Apr 2021 12:13:18 +0000 Subject: [PATCH] Filter updated: Mon, 12 Apr 2021 12:13:16 UTC --- urlhaus-filter-ag-online.txt | 528 +- urlhaus-filter-ag.txt | 538 +- urlhaus-filter-agh-online.txt | 511 +- urlhaus-filter-agh.txt | 276 +- urlhaus-filter-bind-online.conf | 62 +- urlhaus-filter-bind.conf | 86 +- urlhaus-filter-dnsmasq-online.conf | 62 +- urlhaus-filter-dnsmasq.conf | 86 +- urlhaus-filter-domains-online.txt | 511 +- urlhaus-filter-domains.txt | 276 +- urlhaus-filter-hosts-online.txt | 62 +- urlhaus-filter-hosts.txt | 86 +- urlhaus-filter-online.tpl | 62 +- urlhaus-filter-online.txt | 528 +- urlhaus-filter-rpz-online.conf | 64 +- urlhaus-filter-rpz.conf | 88 +- urlhaus-filter-snort2-online.rules | 7474 +++++++++++++------------- urlhaus-filter-snort3-online.rules | 7474 +++++++++++++------------- urlhaus-filter-suricata-online.rules | 7474 +++++++++++++------------- urlhaus-filter-unbound-online.conf | 62 +- urlhaus-filter-unbound.conf | 86 +- urlhaus-filter-vivaldi-online.txt | 528 +- urlhaus-filter-vivaldi.txt | 538 +- urlhaus-filter.tpl | 86 +- urlhaus-filter.txt | 538 +- 25 files changed, 14826 insertions(+), 13260 deletions(-) diff --git a/urlhaus-filter-ag-online.txt b/urlhaus-filter-ag-online.txt index 2fcd09e6..d3bd1a57 100644 --- a/urlhaus-filter-ag-online.txt +++ b/urlhaus-filter-ag-online.txt @@ -1,5 +1,5 @@ ! Title: Online Malicious URL Blocklist (AdGuard) -! Updated: Mon, 12 Apr 2021 00:12:54 UTC +! Updated: Mon, 12 Apr 2021 12:13:00 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -39,7 +39,6 @@ ||1.246.222.98$all ||1.246.223.10$all ||1.246.223.105$all -||1.246.223.109$all ||1.246.223.126$all ||1.246.223.127$all ||1.246.223.130$all @@ -70,7 +69,8 @@ ||1008691.com$all ||101.108.129.251$all ||101.108.130.121$all -||101.108.131.47$all +||101.108.131.99$all +||101.108.138.150$all ||101.16.183.179$all ||101.229.85.127$all ||101.255.36.154$all @@ -78,6 +78,8 @@ ||101.28.218.245$all ||101.28.76.34$all ||101.75.157.99$all +||101.99.91.200$all +||101.99.94.15$all ||102.130.115.14$all ||102.141.240.139$all ||103.113.99.79$all @@ -92,25 +94,18 @@ ||103.237.21.36$all ||103.238.228.3$all ||103.240.249.121$all -||103.4.117.26$all -||103.47.104.246$all ||103.79.112.254$all -||103.82.98.170$all +||103.82.81.37$all ||103.84.240.130$all ||103.84.241.94$all ||103.91.245.12$all -||103.91.245.13$all ||103.91.245.14$all -||103.91.245.16$all -||103.91.245.17$all -||103.91.245.27$all -||103.91.245.3$all +||103.91.245.19$all ||103.91.245.36$all -||103.91.245.46$all -||103.91.245.47$all +||103.91.245.48$all ||103.92.25.90$all ||103.92.25.95$all -||104.168.44.57$all +||103.97.184.180$all ||104.184.75.123$all ||104.206.93.94$all ||104.33.52.85$all @@ -121,6 +116,7 @@ ||106.105.33.43$all ||107.172.104.105$all ||107.172.141.115$all +||107.172.156.3$all ||107.172.249.148$all ||107.173.219.80$all ||107.173.23.240$all @@ -137,10 +133,10 @@ ||108.190.250.48$all ||108.239.155.26$all ||108.249.194.121$all -||109.104.151.108$all ||109.124.90.229$all ||109.233.196.232$all ||109.235.7.228$all +||109.248.58.238$all ||109.86.85.253$all ||109.95.200.102$all ||109.95.200.230$all @@ -156,13 +152,13 @@ ||110.248.251.194$all ||110.251.10.18$all ||110.253.213.198$all +||110.35.145.127$all ||110.35.208.21$all -||110.35.209.175$all -||110.35.223.92$all -||110.35.225.24$all +||110.35.221.77$all ||110.35.235.57$all +||110.35.249.21$all ||110.35.4.2$all -||111.118.88.128$all +||110.89.10.147$all ||111.118.88.61$all ||111.119.245.114$all ||111.125.67.125$all @@ -177,12 +173,9 @@ ||111.185.49.223$all ||111.38.103.114$all ||111.38.103.122$all -||111.38.104.141$all ||111.38.121.222$all -||111.38.121.223$all ||111.38.121.226$all ||111.38.123.136$all -||111.38.123.15$all ||111.38.123.200$all ||111.38.26.243$all ||111.38.8.81$all @@ -203,12 +196,8 @@ ||112.230.168.103$all ||112.232.0.112$all ||112.237.141.241$all -||112.237.144.226$all -||112.237.75.157$all -||112.237.99.207$all ||112.238.143.135$all ||112.238.190.207$all -||112.238.227.228$all ||112.238.39.2$all ||112.239.101.146$all ||112.240.216.17$all @@ -222,6 +211,7 @@ ||112.247.214.146$all ||112.247.240.226$all ||112.247.82.122$all +||112.248.109.156$all ||112.248.148.90$all ||112.248.63.212$all ||112.249.109.217$all @@ -241,6 +231,7 @@ ||112.27.124.143$all ||112.27.124.147$all ||112.27.124.149$all +||112.27.124.150$all ||112.27.124.158$all ||112.27.124.165$all ||112.27.124.175$all @@ -273,34 +264,34 @@ ||112.30.1.60$all ||112.30.1.90$all ||112.30.1.91$all +||112.30.110.30$all ||112.30.110.38$all ||112.30.110.45$all ||112.30.110.60$all ||112.30.35.237$all -||112.30.4.103$all ||112.30.4.118$all ||112.30.4.124$all ||112.30.4.53$all ||112.30.4.61$all ||112.30.4.68$all -||112.30.4.70$all ||112.30.4.73$all ||112.30.4.90$all ||112.31.0.113$all ||112.31.177.39$all -||112.31.211.135$all ||112.31.216.207$all -||112.31.240.239$all ||112.53.224.79$all ||112.53.227.66$all ||112.65.53.175$all +||112.72.162.159$all ||112.72.162.49$all ||112.72.175.147$all ||112.72.176.112$all +||112.72.176.84$all ||112.72.226.202$all ||112.80.215.101$all ||112.82.146.253$all ||112.82.224.139$all +||112.9.155.122$all ||112.93.29.211$all ||113.11.95.254$all ||113.118.249.97$all @@ -308,65 +299,77 @@ ||113.13.241.32$all ||113.161.58.249$all ||113.161.78.185$all +||113.194.131.72$all +||113.194.135.223$all +||113.226.42.250$all ||113.230.86.107$all ||113.231.184.245$all ||113.231.211.131$all ||113.254.169.251$all ||113.59.128.133$all +||113.59.136.39$all +||113.59.144.42$all ||113.59.149.125$all -||113.59.154.21$all -||113.59.180.40$all ||113.59.191.47$all ||113.61.204.205$all ||113.65.10.139$all -||113.88.153.5$all -||113.88.192.87$all +||113.88.123.22$all +||113.88.228.152$all ||113.89.43.165$all -||114.199.204.37$all ||114.199.253.235$all ||114.201.201.68$all ||114.224.203.128$all ||114.30.54.64$all -||114.35.254.7$all ||114.79.172.42$all ||115.165.216.112$all ||115.171.204.161$all ||115.42.47.36$all -||115.48.140.22$all -||115.49.77.222$all +||115.49.232.197$all +||115.50.172.22$all +||115.50.2.148$all ||115.51.106.238$all +||115.51.91.81$all ||115.53.203.161$all -||115.54.241.214$all +||115.54.212.175$all ||115.55.156.203$all +||115.55.7.9$all ||115.56.131.242$all ||115.56.133.96$all ||115.56.155.202$all -||115.56.178.168$all -||115.56.182.146$all -||115.56.182.151$all -||115.58.111.76$all -||115.58.132.140$all -||115.59.203.197$all ||115.59.214.205$all ||115.59.233.160$all ||115.59.252.120$all ||115.61.110.120$all +||115.61.167.21$all +||115.62.172.140$all +||115.62.26.113$all ||115.73.3.11$all ||115.75.217.79$all ||115.88.133.148$all ||115.92.174.231$all -||115.97.139.110$all +||116.108.92.154$all ||116.124.219.2$all ||116.206.164.46$all ||116.211.100.26$all +||117.194.162.12$all ||117.20.204.138$all ||117.20.204.5$all ||117.20.210.52$all +||117.20.220.126$all ||117.20.243.40$all ||117.201.205.232$all -||117.251.59.124$all +||117.202.64.149$all +||117.213.12.177$all +||117.213.47.94$all +||117.213.9.42$all +||117.215.249.250$all +||117.222.173.91$all +||117.222.175.134$all +||117.242.208.197$all +||117.247.201.45$all ||117.26.124.173$all ||117.63.113.146$all +||117.63.133.251$all ||117.63.53.15$all ||117.86.105.110$all ||118.101.7.28$all @@ -390,10 +393,9 @@ ||118.233.65.93$all ||118.42.125.246$all ||118.43.180.33$all +||118.79.113.239$all ||118.79.218.213$all ||118.79.50.203$all -||118.79.74.77$all -||118.91.41.135$all ||118.99.179.164$all ||118.99.183.235$all ||118.99.239.217$all @@ -412,6 +414,7 @@ ||119.179.43.1$all ||119.179.58.163$all ||119.18.38.144$all +||119.18.88.78$all ||119.180.106.217$all ||119.181.119.21$all ||119.182.97.232$all @@ -427,14 +430,14 @@ ||119.191.255.236$all ||119.204.30.144$all ||119.250.129.231$all -||119.251.105.221$all ||119.56.131.155$all ||119.56.143.46$all ||119.56.143.71$all ||119.56.148.115$all ||119.56.155.57$all -||119.56.166.36$all +||119.56.206.43$all ||119.96.38.150$all +||119.99.52.69$all ||12.132.113.2$all ||12.15.69.83$all ||12.178.187.6$all @@ -457,23 +460,20 @@ ||120.193.91.201$all ||120.193.91.202$all ||120.193.91.204$all -||120.193.91.208$all ||120.193.91.215$all ||120.193.91.233$all +||120.209.126.206$all ||120.209.126.235$all ||120.209.126.239$all -||120.209.126.25$all ||120.209.126.250$all ||120.209.126.60$all ||120.209.126.74$all ||120.209.99.127$all ||120.50.66.60$all ||120.50.93.115$all -||120.57.123.202$all ||120.6.8.11$all ||120.7.75.99$all ||120.83.79.42$all -||120.85.172.111$all ||121.100.114.164$all ||121.100.96.8$all ||121.121.44.222$all @@ -494,6 +494,7 @@ ||121.254.76.17$all ||121.61.96.158$all ||121.61.97.64$all +||121.8.107.214$all ||121.88.99.236$all ||122.100.150.204$all ||122.137.53.134$all @@ -505,7 +506,7 @@ ||122.232.227.128$all ||122.254.33.214$all ||123.0.240.58$all -||123.10.137.193$all +||123.10.32.252$all ||123.11.202.178$all ||123.110.124.244$all ||123.110.170.237$all @@ -513,7 +514,6 @@ ||123.110.19.248$all ||123.110.200.98$all ||123.110.238.188$all -||123.12.164.165$all ||123.129.2.28$all ||123.129.84.36$all ||123.130.208.52$all @@ -527,6 +527,7 @@ ||123.134.14.130$all ||123.135.20.164$all ||123.135.246.180$all +||123.14.95.26$all ||123.154.236.114$all ||123.159.8.100$all ||123.183.16.71$all @@ -552,11 +553,11 @@ ||123.241.148.58$all ||123.241.184.124$all ||123.28.217.23$all -||123.4.204.223$all -||123.4.251.81$all -||123.8.250.132$all -||123.9.193.253$all -||123.9.85.25$all +||123.4.242.19$all +||123.4.47.57$all +||123.5.148.182$all +||123.5.189.15$all +||123.9.36.120$all ||124.129.221.150$all ||124.129.76.230$all ||124.130.40.31$all @@ -592,24 +593,20 @@ ||125.40.1.235$all ||125.40.146.46$all ||125.40.3.71$all +||125.41.14.228$all ||125.43.82.59$all -||125.44.8.154$all ||125.45.186.88$all ||125.45.66.253$all -||125.47.244.8$all +||125.47.244.126$all ||125.47.74.230$all -||125.47.93.160$all ||126.39.155.210$all ||128.116.133.92$all -||13.114.247.134$all ||130.255.159.133$all -||134.119.186.214$all ||135.148.36.127$all ||138.99.204.224$all ||139.159.226.180$all ||139.170.173.198$all ||139.216.102.151$all -||14.102.17.222$all ||14.136.80.242$all ||14.138.8.215$all ||14.138.8.51$all @@ -623,10 +620,15 @@ ||14.50.129.248$all ||14.55.29.2$all ||140.237.12.32$all +||141.105.65.94$all ||142.11.216.5$all ||142.177.56.127$all +||143.198.120.58$all ||148.69.108.177$all ||149.255.15.134$all +||149.255.15.170$all +||149.255.15.29$all +||149.255.15.44$all ||149.255.15.99$all ||149.3.124.194$all ||14karatvisions.com$all @@ -646,9 +648,8 @@ ||162.191.165.238$all ||162.194.28.60$all ||162.209.98.174$all -||163.125.200.234$all +||162.245.221.121$all ||163.125.206.193$all -||163.53.206.228$all ||167.114.172.177$all ||170.81.238.178$all ||171.121.255.12$all @@ -686,17 +687,18 @@ ||175.201.104.192$all ||175.208.230.8$all ||175.213.25.192$all -||175.42.46.118$all ||176.111.174.35$all ||176.111.174.66$all ||176.111.174.67$all ||176.113.161.104$all ||176.113.161.121$all ||176.113.161.59$all +||176.113.161.65$all ||176.113.161.66$all ||176.113.161.71$all ||176.113.161.76$all ||176.113.161.84$all +||176.113.161.91$all ||176.113.161.95$all ||176.12.117.70$all ||176.123.7.115$all @@ -704,7 +706,6 @@ ||176.124.7.225$all ||176.221.188.251$all ||176.240.84.106$all -||177.11.92.78$all ||177.131.226.235$all ||177.54.82.154$all ||178.124.182.187$all @@ -712,7 +713,6 @@ ||178.150.174.65$all ||178.151.143.2$all ||178.165.122.141$all -||178.17.171.144$all ||178.175.0.145$all ||178.175.0.24$all ||178.175.1.179$all @@ -721,128 +721,130 @@ ||178.175.10.124$all ||178.175.10.182$all ||178.175.10.221$all +||178.175.10.247$all ||178.175.10.96$all +||178.175.100.104$all ||178.175.100.151$all +||178.175.101.212$all ||178.175.101.252$all ||178.175.102.207$all ||178.175.102.217$all ||178.175.102.25$all -||178.175.103.52$all +||178.175.103.14$all ||178.175.103.58$all ||178.175.104.112$all +||178.175.104.115$all ||178.175.105.67$all -||178.175.105.89$all ||178.175.106.160$all ||178.175.106.179$all -||178.175.106.199$all +||178.175.107.135$all ||178.175.107.142$all -||178.175.107.156$all ||178.175.107.224$all ||178.175.108.127$all ||178.175.108.173$all -||178.175.108.87$all ||178.175.109.165$all ||178.175.109.181$all +||178.175.11.100$all ||178.175.11.101$all ||178.175.11.139$all ||178.175.11.6$all ||178.175.110.191$all ||178.175.110.195$all -||178.175.111.190$all ||178.175.112.111$all ||178.175.112.183$all -||178.175.112.254$all ||178.175.112.85$all +||178.175.112.87$all ||178.175.113.174$all +||178.175.114.117$all ||178.175.114.151$all ||178.175.114.51$all ||178.175.115.106$all ||178.175.115.208$all ||178.175.116.254$all -||178.175.116.56$all -||178.175.117.110$all -||178.175.118.112$all -||178.175.118.129$all ||178.175.118.174$all ||178.175.118.41$all ||178.175.119.161$all ||178.175.119.43$all -||178.175.12.222$all ||178.175.12.68$all +||178.175.12.91$all ||178.175.120.12$all +||178.175.121.125$all +||178.175.121.130$all ||178.175.121.151$all ||178.175.121.169$all +||178.175.121.243$all +||178.175.121.77$all ||178.175.122.172$all -||178.175.122.28$all +||178.175.122.197$all ||178.175.122.47$all -||178.175.123.202$all ||178.175.123.53$all +||178.175.124.113$all ||178.175.124.38$all -||178.175.125.149$all ||178.175.125.218$all -||178.175.125.52$all ||178.175.126.129$all ||178.175.126.18$all ||178.175.126.234$all -||178.175.126.46$all +||178.175.126.43$all ||178.175.126.80$all ||178.175.127.202$all ||178.175.127.90$all -||178.175.14.222$all -||178.175.14.248$all -||178.175.14.34$all +||178.175.13.219$all ||178.175.15.19$all +||178.175.15.196$all ||178.175.15.232$all ||178.175.15.250$all ||178.175.15.72$all +||178.175.16.224$all ||178.175.16.26$all ||178.175.16.86$all -||178.175.17.13$all ||178.175.17.135$all ||178.175.17.14$all ||178.175.17.50$all -||178.175.17.54$all ||178.175.17.9$all -||178.175.19.163$all -||178.175.2.183$all +||178.175.18.177$all +||178.175.18.31$all ||178.175.2.189$all ||178.175.2.217$all +||178.175.2.23$all ||178.175.2.46$all ||178.175.2.71$all ||178.175.20.117$all ||178.175.20.126$all ||178.175.20.231$all ||178.175.21.194$all -||178.175.21.34$all +||178.175.21.53$all ||178.175.21.71$all ||178.175.22.120$all +||178.175.22.198$all ||178.175.22.206$all ||178.175.22.51$all +||178.175.22.74$all ||178.175.22.93$all ||178.175.22.94$all ||178.175.24.107$all ||178.175.24.176$all ||178.175.24.183$all -||178.175.24.232$all -||178.175.25.114$all -||178.175.25.56$all +||178.175.24.52$all +||178.175.25.162$all ||178.175.26.215$all ||178.175.27.151$all +||178.175.27.203$all ||178.175.27.32$all -||178.175.28.48$all +||178.175.27.43$all ||178.175.28.5$all ||178.175.29.135$all ||178.175.29.233$all -||178.175.29.35$all ||178.175.3.109$all ||178.175.30.187$all -||178.175.30.254$all ||178.175.30.71$all +||178.175.30.90$all ||178.175.31.128$all +||178.175.31.216$all ||178.175.31.55$all ||178.175.31.92$all ||178.175.32.34$all ||178.175.33.190$all +||178.175.33.233$all ||178.175.34.180$all ||178.175.34.222$all ||178.175.35.83$all @@ -853,18 +855,18 @@ ||178.175.36.250$all ||178.175.36.98$all ||178.175.37.10$all -||178.175.37.122$all ||178.175.37.149$all ||178.175.37.215$all ||178.175.37.234$all ||178.175.38.12$all ||178.175.38.74$all ||178.175.38.88$all -||178.175.39.157$all +||178.175.39.110$all ||178.175.39.158$all ||178.175.39.203$all ||178.175.39.210$all ||178.175.4.120$all +||178.175.4.14$all ||178.175.4.180$all ||178.175.4.225$all ||178.175.40.108$all @@ -873,87 +875,91 @@ ||178.175.41.139$all ||178.175.41.182$all ||178.175.41.217$all +||178.175.41.230$all ||178.175.41.68$all ||178.175.42.221$all ||178.175.42.28$all ||178.175.42.46$all ||178.175.43.114$all ||178.175.43.217$all -||178.175.43.238$all +||178.175.43.90$all ||178.175.44.186$all ||178.175.44.38$all ||178.175.44.56$all ||178.175.44.78$all -||178.175.45.125$all ||178.175.45.234$all +||178.175.46.110$all ||178.175.46.113$all -||178.175.46.196$all -||178.175.46.208$all ||178.175.47.11$all ||178.175.47.122$all +||178.175.47.127$all ||178.175.47.2$all ||178.175.47.222$all ||178.175.47.75$all ||178.175.47.80$all ||178.175.47.99$all +||178.175.48.164$all ||178.175.48.185$all ||178.175.48.194$all ||178.175.48.223$all +||178.175.49.104$all +||178.175.49.253$all ||178.175.49.30$all ||178.175.49.51$all ||178.175.49.54$all ||178.175.49.82$all -||178.175.5.254$all +||178.175.5.223$all ||178.175.5.44$all ||178.175.50.217$all ||178.175.50.3$all ||178.175.50.42$all ||178.175.50.54$all ||178.175.50.68$all -||178.175.51.177$all +||178.175.51.117$all ||178.175.51.2$all +||178.175.52.114$all +||178.175.52.139$all ||178.175.52.15$all ||178.175.52.176$all ||178.175.52.181$all ||178.175.52.24$all +||178.175.52.255$all ||178.175.53.214$all ||178.175.53.231$all ||178.175.53.62$all ||178.175.53.79$all +||178.175.53.87$all ||178.175.54.100$all -||178.175.54.196$all +||178.175.54.119$all +||178.175.54.78$all +||178.175.55.118$all ||178.175.55.170$all ||178.175.55.60$all ||178.175.55.99$all ||178.175.56.30$all ||178.175.56.64$all ||178.175.56.74$all -||178.175.57.112$all +||178.175.57.121$all ||178.175.57.145$all ||178.175.58.12$all -||178.175.58.235$all +||178.175.58.130$all +||178.175.58.18$all ||178.175.59.103$all -||178.175.59.106$all ||178.175.59.12$all -||178.175.59.158$all -||178.175.6.144$all -||178.175.6.180$all -||178.175.60.158$all -||178.175.60.49$all -||178.175.60.7$all -||178.175.61.250$all +||178.175.59.173$all +||178.175.59.8$all +||178.175.6.201$all +||178.175.6.203$all +||178.175.61.212$all ||178.175.61.28$all -||178.175.62.137$all +||178.175.62.130$all ||178.175.62.151$all ||178.175.62.206$all -||178.175.63.223$all ||178.175.63.53$all ||178.175.64.116$all ||178.175.65.234$all ||178.175.65.237$all -||178.175.66.140$all ||178.175.66.186$all -||178.175.66.214$all ||178.175.67.28$all ||178.175.67.65$all ||178.175.68.140$all @@ -964,9 +970,7 @@ ||178.175.68.35$all ||178.175.68.4$all ||178.175.68.5$all -||178.175.69.18$all ||178.175.7.113$all -||178.175.7.19$all ||178.175.7.198$all ||178.175.70.108$all ||178.175.70.177$all @@ -977,40 +981,37 @@ ||178.175.71.69$all ||178.175.72.208$all ||178.175.72.220$all +||178.175.72.58$all ||178.175.74.223$all ||178.175.75.94$all ||178.175.76.146$all ||178.175.76.221$all ||178.175.76.33$all +||178.175.76.34$all ||178.175.76.8$all -||178.175.77.47$all ||178.175.78.118$all -||178.175.78.125$all ||178.175.78.250$all ||178.175.79.128$all ||178.175.79.146$all ||178.175.79.198$all +||178.175.79.27$all ||178.175.8.119$all -||178.175.8.13$all -||178.175.8.130$all ||178.175.8.40$all -||178.175.81.114$all ||178.175.81.144$all ||178.175.81.189$all ||178.175.82.110$all ||178.175.82.73$all ||178.175.83.125$all +||178.175.83.17$all +||178.175.84.146$all ||178.175.84.154$all ||178.175.84.201$all ||178.175.84.237$all ||178.175.85.190$all -||178.175.86.117$all ||178.175.86.49$all -||178.175.86.59$all ||178.175.87.151$all ||178.175.87.161$all ||178.175.87.202$all -||178.175.87.207$all ||178.175.87.227$all ||178.175.88.102$all ||178.175.88.130$all @@ -1018,34 +1019,31 @@ ||178.175.88.204$all ||178.175.88.85$all ||178.175.89.152$all -||178.175.89.69$all +||178.175.89.195$all +||178.175.9.217$all ||178.175.9.223$all -||178.175.9.24$all ||178.175.90.137$all ||178.175.90.236$all ||178.175.90.3$all ||178.175.90.79$all +||178.175.91.243$all ||178.175.91.3$all ||178.175.91.97$all ||178.175.92.170$all -||178.175.93.115$all +||178.175.92.213$all ||178.175.93.120$all +||178.175.93.204$all ||178.175.93.234$all ||178.175.93.42$all -||178.175.93.98$all -||178.175.94.248$all -||178.175.94.27$all ||178.175.95.105$all ||178.175.95.54$all +||178.175.95.83$all ||178.175.96.136$all ||178.175.96.177$all -||178.175.96.198$all ||178.175.96.225$all ||178.175.97.248$all -||178.175.97.70$all ||178.175.98.63$all ||178.175.99.45$all -||178.175.99.90$all ||178.19.183.14$all ||178.205.101.33$all ||178.21.164.68$all @@ -1073,7 +1071,9 @@ ||180.177.104.65$all ||180.177.180.6$all ||180.177.242.73$all +||180.177.5.36$all ||180.218.5.171$all +||180.248.80.38$all ||180.66.111.36$all ||180.66.53.93$all ||180.94.170.166$all @@ -1090,40 +1090,45 @@ ||181.49.236.4$all ||181.49.59.162$all ||182.112.177.134$all -||182.114.88.240$all -||182.114.88.247$all -||182.115.176.253$all +||182.113.4.247$all +||182.114.194.183$all ||182.116.102.190$all -||182.116.35.52$all +||182.117.29.27$all ||182.119.200.55$all +||182.119.23.75$all +||182.119.48.230$all ||182.120.16.22$all ||182.120.192.88$all ||182.120.34.180$all -||182.121.73.158$all +||182.121.200.137$all +||182.121.205.246$all ||182.122.254.7$all +||182.126.109.194$all +||182.126.126.162$all ||182.126.87.210$all ||182.126.87.246$all -||182.127.213.136$all +||182.127.207.187$all +||182.127.80.240$all ||182.160.98.250$all ||182.233.0.252$all ||182.235.252.31$all ||182.53.197.62$all -||182.59.170.157$all ||182.88.27.89$all ||183.105.104.83$all ||183.109.169.45$all +||183.141.61.174$all ||183.17.145.112$all ||183.188.144.204$all -||183.188.146.216$all -||183.83.109.216$all +||183.49.86.54$all ||183.83.14.20$all ||183.97.40.9$all ||184.164.185.41$all ||184.175.115.10$all ||184.74.149.230$all ||185.106.209.68$all -||185.107.3.8$all ||185.117.2.107$all +||185.117.21.212$all +||185.132.53.182$all ||185.172.110.209$all ||185.172.110.235$all ||185.174.101.41$all @@ -1140,14 +1145,13 @@ ||185.245.96.94$all ||185.26.113.95$all ||185.34.16.231$all +||185.38.142.194$all ||185.55.1.182$all ||185.68.230.207$all ||185.81.154.208$all ||185.81.157.186$all ||185.82.217.185$all ||185.82.217.213$all -||185.82.219.160$all -||185.82.219.161$all ||185.82.219.219$all ||185.82.219.80$all ||186.151.144.85$all @@ -1161,7 +1165,6 @@ ||186.28.60.184$all ||186.34.4.40$all ||186.73.188.132$all -||186.73.188.134$all ||187.12.10.98$all ||187.135.141.192$all ||187.188.124.229$all @@ -1173,12 +1176,15 @@ ||188.152.41.141$all ||188.169.178.50$all ||188.169.179.127$all +||188.169.199.59$all ||188.169.30.30$all ||188.169.36.163$all +||188.169.45.140$all ||188.242.242.144$all ||188.69.251.12$all ||188.83.202.25$all -||189.201.250.184$all +||189.171.22.132$all +||189.175.214.112$all ||189.252.184.115$all ||190.0.42.106$all ||190.109.178.139$all @@ -1193,7 +1199,6 @@ ||190.122.112.42$all ||190.122.112.76$all ||190.130.20.14$all -||190.141.117.41$all ||190.147.16.184$all ||190.159.240.9$all ||190.210.214.130$all @@ -1209,19 +1214,20 @@ ||190.98.37.200$all ||190.98.41.33$all ||191.255.248.220$all -||192.153.57.94$all ||192.210.175.130$all +||192.227.185.106$all ||192.227.220.55$all ||192.227.228.67$all +||192.99.221.230$all ||192.99.240.77$all ||194.113.107.243$all ||194.147.142.230$all -||194.15.36.167$all ||194.152.35.139$all ||194.38.20.199$all ||195.139.126.51$all ||195.228.231.218$all ||195.24.94.187$all +||195.5.3.162$all ||196.202.26.182$all ||196.218.48.82$all ||196.221.148.90$all @@ -1229,15 +1235,12 @@ ||197.159.2.106$all ||197.50.27.115$all ||198.23.133.218$all -||198.23.174.104$all -||198.23.207.121$all +||198.23.213.61$all ||198.23.251.105$all -||198.46.132.132$all ||1am.co.nz$all ||2.239.22.188$all ||2.36.231.201$all ||2.37.149.230$all -||2.37.203.65$all ||2.45.111.158$all ||2.45.4.24$all ||2.55.125.182$all @@ -1248,11 +1251,11 @@ ||2.83.152.16$all ||2.indexsinas.me:811/64.exe$all ||2.indexsinas.me:811/86.exe$all +||2.indexsinas.me:811/c64.exe$all ||20.185.42.197$all ||200.105.167.98$all ||200.111.189.70$all ||200.194.4.24$all -||200.2.161.171$all ||200.29.105.207$all ||200.30.132.50$all ||201.170.46.2$all @@ -1263,14 +1266,13 @@ ||202.107.233.41$all ||202.111.131.236$all ||202.166.217.54$all -||202.182.125.175$all ||202.29.95.12$all ||202.4.124.58$all -||202.44.228.125$all ||202.51.176.114$all ||202.51.191.174$all ||202.74.236.9$all ||203.109.201.243$all +||203.130.69.205$all ||203.159.80.128$all ||203.159.80.129$all ||203.159.80.164$all @@ -1297,12 +1299,12 @@ ||210.180.237.212$all ||210.216.152.122$all ||210.216.153.142$all -||210.57.237.70$all ||210.57.245.109$all ||210.68.242.114$all ||211.187.132.204$all ||211.187.75.220$all ||211.200.160.239$all +||211.203.111.207$all ||211.204.215.157$all ||211.210.66.179$all ||211.210.93.93$all @@ -1311,7 +1313,6 @@ ||211.237.120.13$all ||211.237.246.137$all ||211.238.83.238$all -||211.247.5.96$all ||212.122.86.105$all ||212.156.215.178$all ||212.46.197.114$all @@ -1321,7 +1322,7 @@ ||213.14.173.117$all ||213.149.190.193$all ||213.163.104.160$all -||213.163.104.99$all +||213.163.104.20$all ||213.163.113.225$all ||213.163.113.51$all ||213.163.114.202$all @@ -1338,7 +1339,7 @@ ||213.163.118.227$all ||213.163.126.176$all ||213.163.126.201$all -||213.163.126.7$all +||213.163.127.204$all ||213.163.127.250$all ||213.163.127.46$all ||213.189.178.163$all @@ -1358,7 +1359,6 @@ ||218.2.40.34$all ||218.234.165.18$all ||218.238.246.3$all -||218.32.118.1$all ||218.35.207.119$all ||218.35.227.133$all ||218.35.68.35$all @@ -1368,11 +1368,12 @@ ||218.79.103.159$all ||218.93.102.63$all ||218.93.102.75$all +||219.154.113.171$all ||219.154.127.194$all -||219.154.137.93$all -||219.156.73.171$all +||219.155.226.205$all ||219.157.136.212$all -||219.157.139.165$all +||219.157.14.239$all +||219.157.178.196$all ||219.157.37.210$all ||219.241.6.180$all ||219.68.1.148$all @@ -1387,7 +1388,6 @@ ||219.85.145.194$all ||21robo.com$all ||220.126.237.74$all -||220.132.106.247$all ||220.173.160.185$all ||220.200.22.163$all ||220.81.134.72$all @@ -1395,7 +1395,9 @@ ||221.124.78.15$all ||221.13.150.74$all ||221.14.162.20$all +||221.14.47.204$all ||221.15.127.60$all +||221.15.182.72$all ||221.15.3.50$all ||221.157.191.178$all ||221.160.136.213$all @@ -1413,18 +1415,17 @@ ||221.232.183.167$all ||221.235.137.36$all ||221.3.68.16$all +||222.107.145.56$all ||222.108.17.64$all ||222.118.248.149$all ||222.119.65.145$all -||222.132.125.138$all ||222.135.9.5$all ||222.137.122.105$all ||222.137.139.86$all -||222.137.170.17$all ||222.137.72.66$all ||222.138.133.186$all -||222.138.17.203$all ||222.139.21.190$all +||222.140.163.181$all ||222.140.17.245$all ||222.187.9.178$all ||222.211.72.66$all @@ -1447,9 +1448,9 @@ ||23.24.213.121$all ||23.243.149.13$all ||23.243.21.167$all -||23.92.213.108$all ||23.94.190.101$all ||23.95.122.24$all +||23.95.122.25$all ||24.103.74.180$all ||24.11.141.134$all ||24.119.158.74$all @@ -1520,9 +1521,7 @@ ||27.213.255.202$all ||27.213.66.112$all ||27.213.84.74$all -||27.214.37.129$all ||27.215.139.242$all -||27.215.190.172$all ||27.215.212.209$all ||27.215.253.149$all ||27.215.71.243$all @@ -1534,7 +1533,6 @@ ||27.217.191.58$all ||27.218.135.3$all ||27.219.132.71$all -||27.219.151.83$all ||27.219.160.112$all ||27.219.176.72$all ||27.219.83.244$all @@ -1550,16 +1548,14 @@ ||27.35.154.13$all ||27.35.212.124$all ||27.35.58.5$all -||27.40.120.108$all -||27.40.73.175$all +||27.40.79.170$all ||27.41.36.97$all -||27.45.90.246$all -||27.5.44.190$all ||31.0.98.131$all ||31.11.51.57$all ||31.13.23.180$all ||31.168.124.130$all ||31.168.146.199$all +||31.168.16.68$all ||31.168.179.83$all ||31.168.184.59$all ||31.168.191.243$all @@ -1609,7 +1605,6 @@ ||39.113.245.254$all ||39.113.98.136$all ||39.114.137.102$all -||39.115.0.100$all ||39.117.31.162$all ||39.162.104.119$all ||39.162.98.216$all @@ -1670,27 +1665,34 @@ ||40.88.2.151$all ||41.139.209.46$all ||41.165.130.43$all -||41.190.63.174$all ||41.193.192.100$all ||41.219.185.171$all ||41.226.60.115$all +||41.72.203.82$all +||41.76.157.2$all ||41.86.18.147$all ||41.86.18.152$all -||41.86.18.204$all -||41.86.19.146$all -||41.86.19.206$all -||41.86.21.28$all -||41.86.21.60$all -||41.86.5.198$all +||41.86.21.38$all +||41.86.21.59$all +||41.86.5.103$all +||41.86.5.197$all +||41.86.5.48$all ||42.202.101.181$all ||42.202.101.199$all +||42.224.171.165$all ||42.224.176.27$all +||42.224.254.220$all +||42.224.4.110$all +||42.227.222.189$all +||42.227.225.253$all ||42.228.40.143$all -||42.228.60.114$all +||42.230.143.162$all +||42.233.97.141$all +||42.235.84.85$all ||42.236.161.72$all ||42.236.212.157$all +||42.237.114.80$all ||42.238.141.250$all -||42.56.15.227$all ||42.61.99.155$all ||42.82.217.241$all ||43.230.207.204$all @@ -1709,6 +1711,7 @@ ||45.144.225.27$all ||45.148.10.47$all ||45.148.10.94$all +||45.15.143.191$all ||45.176.108.248$all ||45.176.109.205$all ||45.176.110.146$all @@ -1717,6 +1720,7 @@ ||45.229.53.148$all ||45.27.253.137$all ||45.51.104.59$all +||45.77.9.151$all ||45.85.90.131$all ||45.9.148.37$all ||45.92.108.35$all @@ -1737,8 +1741,8 @@ ||46.42.118.86$all ||46.42.86.128$all ||46.97.76.242$all +||47.136.96.53$all ||47.145.152.26$all -||47.151.23.172$all ||47.157.97.71$all ||47.16.131.51$all ||47.21.202.98$all @@ -1758,6 +1762,7 @@ ||5.14.122.233$all ||5.188.62.111$all ||5.95.226.154$all +||50.115.174.103$all ||50.115.174.106$all ||50.121.91.255$all ||50.247.83.66$all @@ -1782,32 +1787,39 @@ ||58.240.147.97$all ||58.241.78.55$all ||58.242.91.219$all -||58.249.73.208$all +||58.249.22.24$all ||58.249.75.128$all +||58.249.75.146$all +||58.249.77.141$all ||58.249.80.36$all -||58.252.176.140$all ||58.253.15.184$all ||58.51.219.200$all ||58.72.165.153$all ||58.72.165.39$all ||59.0.211.161$all ||59.102.168.189$all -||59.126.26.220$all ||59.151.202.3$all ||59.151.214.4$all -||59.151.237.51$all -||59.151.246.125$all ||59.173.135.51$all ||59.175.63.177$all ||59.23.114.97$all ||59.26.181.228$all ||59.30.12.254$all -||59.60.117.163$all +||59.50.23.23$all +||59.89.242.116$all +||59.92.217.215$all +||59.92.218.82$all +||59.93.21.140$all +||59.93.21.172$all +||59.94.182.212$all +||59.95.175.49$all +||59.97.170.146$all ||60.13.61.12$all ||60.209.122.57$all ||60.209.216.23$all ||60.209.233.94$all ||60.211.6.112$all +||60.211.80.216$all ||60.212.100.83$all ||60.212.111.39$all ||60.212.206.246$all @@ -1815,31 +1827,30 @@ ||60.212.220.167$all ||60.212.254.178$all ||60.213.83.55$all +||60.214.53.159$all ||60.214.85.149$all ||60.217.177.196$all ||60.217.86.208$all -||60.220.159.240$all -||60.253.15.104$all -||60.253.39.88$all ||60.253.4.72$all ||60.253.51.127$all ||60.253.60.174$all ||60.253.8.81$all -||60.254.36.135$all ||60.7.10.121$all ||60.7.8.43$all ||61.146.108.150$all +||61.163.131.67$all ||61.179.91.194$all ||61.247.224.66$all +||61.3.150.101$all ||61.52.101.143$all +||61.52.186.186$all ||61.52.241.252$all ||61.52.57.40$all ||61.52.9.166$all +||61.52.97.68$all ||61.52.98.43$all ||61.52.99.161$all ||61.53.117.152$all -||61.53.249.58$all -||61.53.74.236$all ||61.54.103.56$all ||61.56.180.67$all ||61.56.181.7$all @@ -1871,7 +1882,6 @@ ||66.108.199.144$all ||66.57.55.210$all ||66.74.7.197$all -||66.91.21.31$all ||66.97.181.196$all ||67.245.151.203$all ||67.8.138.101$all @@ -1933,6 +1943,7 @@ ||74.64.139.223$all ||74.75.165.81$all ||75.127.141.52$all +||75.83.102.27$all ||75.99.213.61$all ||76.170.11.82$all ||76.178.22.145$all @@ -1942,14 +1953,12 @@ ||76.84.134.33$all ||76.89.107.69$all ||76.95.12.137$all -||77.111.182.31$all ||77.237.25.210$all ||77.71.50.153$all ||77.89.203.238$all ||77st.net$all ||78.138.98.134$all ||78.145.224.45$all -||78.187.141.144$all ||78.187.41.200$all ||78.188.106.235$all ||78.188.168.64$all @@ -1970,7 +1979,6 @@ ||80.107.89.207$all ||80.19.101.218$all ||80.211.181.77$all -||80.217.12.7$all ||80.99.128.61$all ||81.136.146.213$all ||81.165.44.109$all @@ -1987,7 +1995,6 @@ ||81.92.36.96$all ||82.103.108.72$all ||82.135.196.130$all -||82.166.212.178$all ||82.166.85.112$all ||82.207.61.194$all ||82.209.250.155$all @@ -2038,14 +2045,17 @@ ||85.105.208.25$all ||85.105.224.141$all ||85.105.241.2$all -||85.108.133.19$all ||85.214.149.236$all ||85.241.39.182$all +||85.250.147.134$all ||85.64.181.50$all ||85.74.215.180$all ||85.97.130.227$all ||86.35.43.220$all +||86.98.23.78$all +||87.117.11.46$all ||87.172.19.130$all +||87.251.71.78$all ||87du.vip$all ||88.119.171.253$all ||88.129.208.43$all @@ -2072,7 +2082,6 @@ ||8poieq.bn.files.1drv.com$all ||90.152.144.139$all ||91.132.197.39$all -||91.138.215.5$all ||91.177.139.132$all ||91.187.103.32$all ||91.212.150.241$all @@ -2087,6 +2096,7 @@ ||92.54.237.237$all ||92.83.62.139$all ||92.85.18.138$all +||93.157.63.221$all ||93.159.169.190$all ||93.173.235.110$all ||93.21.224.154$all @@ -2100,13 +2110,13 @@ ||94.136.69.199$all ||94.143.53.34$all ||94.154.17.170$all +||94.154.82.190$all ||94.200.16.22$all ||94.224.83.208$all ||94.53.120.109$all ||94.85.0.3$all ||95.132.129.250$all ||95.133.158.20$all -||95.154.20.231$all ||95.158.19.130$all ||95.170.113.227$all ||95.170.201.34$all @@ -2142,7 +2152,6 @@ ||adithimedia.com$all ||adithimedia.memengers.com$all ||admin.erapor.smk-alasror.net$all -||admin.gentbcn.org$all ||admin.grandoceanvilla.com$all ||admission.kmctartskuttippuram.org$all ||adventureexplorer.in$all @@ -2158,6 +2167,7 @@ ||aiqtest.com$all ||ajpharmaholding.com$all ||akdvidyalaya.com$all +||al-wahd.com$all ||alasdemariposas.org$all ||alberts.diamondrelationscrm.us$all ||alemelektronik.com$all @@ -2198,7 +2208,6 @@ ||artedibujoyarquitectura.com$all ||arwenyapi.com$all ||ask-regard.call-save.biz$all -||asucssa.live$all ||atfile.com$all ||athenacapsg.com$all ||atlasconcreteworks.com$all @@ -2210,15 +2219,17 @@ ||automaticrefreshments.com$all ||avadhanagames.com$all ||aventuramotorhome.com$all +||awumad01.top$all +||awuqze02.top$all ||ayahuascasp.com.br$all ||ayamallah.com$all -||aycconsultoriaempresarial.com$all ||azmeasurement.com$all ||azraktours.com$all ||b.r.uce.lee.b.es.t@zytrox.tk$all ||b2b.toptanakaryakit.com.tr$all ||backgrounds.pk$all ||badeggdesign.com$all +||bakamla.go.id$all ||balealgodon.mx$all ||bangkok-orchids.com$all ||bangladeshunbound.com$all @@ -2239,7 +2250,6 @@ ||bespokeweddings.ie$all ||bestcarenepal.com$all ||betone.co.kr$all -||betycopaints.com$all ||beveragesmiami.solucioneslink.com$all ||bhavaniengineering.com$all ||bigmikesupplies.co.za$all @@ -2252,6 +2262,7 @@ ||birdi.elin.co.za$all ||birminghamlink.org$all ||bitbucket.org/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe$all +||bitbucket.org/clubhousedev/clubhouse/downloads/clubhousepc.exe$all ||bitbucket.org/dvdfv/anjj/downloads/jami.exe$all ||bitbucket.org/heyhoeee/heyhoename1/downloads/1234.exe$all ||bitbucket.org/jpavelski/chpock/downloads/4.exe$all @@ -2299,7 +2310,6 @@ ||bitbucket.org/tanake5518/fi/downloads/clientrevers.txt$all ||bitbucket.org/tanake5518/fi/downloads/dcrat.exe$all ||bitbucket.org/tanake5518/fi/downloads/dllservices.exe$all -||bitbucket.org/tanake5518/fi/downloads/dllservices2.exe$all ||bitbucket.org/tanake5518/fi/downloads/exe_morris.mcdermott.exe$all ||bitbucket.org/tanake5518/fi/downloads/hans.txt$all ||bitbucket.org/tanake5518/fi/downloads/hulu.txt$all @@ -2382,23 +2392,23 @@ ||capitalgroup-kw.com$all ||capoeiraventrelivre.com$all ||cashyinvestment.org$all +||casiomaneflirt.cf$all ||catchpoolshetlands.co.uk$all ||cazyacustomfurniture.com$all ||cbn.hypervoizd.com$all ||ccauthority.net$all ||cd.textfiles.com/hmatrix/data/hack1226.exe$all ||cdaonline.com.ar$all -||cdn-10049480.file.myqcloud.com$all -||cdn.discordapp.com/attachments/712408764354920490/829413679866839120/echelon_protected.exe$all ||cdn.discordapp.com/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq$all +||cdn.discordapp.com/attachments/775238059083038744/829993648186851338/pslmlyfnpzgsgitrwwvalcfunumfmac$all ||cdn.discordapp.com/attachments/816070119281131570/816070273254162442/all.txt$all ||cdn.discordapp.com/attachments/825372018244583454/826848185246023750/loaddd.exe$all ||cdn.discordapp.com/attachments/825372018244583454/826848348342059008/zeppelin.exe$all ||cdn.discordapp.com/attachments/825372018244583454/826848405258633277/build.exe$all +||cdn.discordapp.com/attachments/825372018244583454/830455061724528690/v1.exe$all ||cdn.discordapp.com/attachments/826198252025675816/826537386485612574/china.png$all ||cdn.discordapp.com/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin$all ||cdn.discordapp.com/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe$all -||cdn.discordapp.com/attachments/829721030112182363/829724335526510622/dcratbuild.exe$all ||cec.asso.ac-amiens.fr$all ||cellas.sk$all ||cendekiabinaaksara.com$all @@ -2413,9 +2423,9 @@ ||chiptune.com/razor/rzr-winner_intro.zip$all ||cible-energy.com$all ||cifeer.net$all +||citiconstructioncorp.com$all ||citihits.lk$all ||citssolutions.co.za$all -||citycapproperty.ru$all ||cityglobalgospel.com$all ||civi.istmejia.com$all ||cleanbydesignllc.com$all @@ -2426,8 +2436,8 @@ ||codeload.github.com/meteoradminz/hidden-tear/zip/master$all ||codsambal.com$all ||colfincas.com/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/$all -||colinde.pricesne.com$all ||colorpak.pl$all +||columbia.aula-web.net$all ||community.reimclub.com$all ||competancy.indigoconsult.net$all ||conceptimagine.ro$all @@ -2437,9 +2447,11 @@ ||consulateins.solucioneslink.com$all ||contributeindustry.com$all ||copelandscapes.com$all +||corwin-tommie06f.ru.com$all ||coulsongraphics.com$all ||count.mail.163.com.impactmedfoundation.com$all ||covid19.cyberschool.or.id$all +||covid19vaccinations.hopto.org$all ||cr-sq.com$all ||craftech.nxtnet.ga$all ||crearechile.cl$all @@ -2502,6 +2514,7 @@ ||dl.198424.com$all ||dl.installcdn-aws.com$all ||dl.packetstormsecurity.net$all +||dl.pandasecur.com$all ||dl.rina-roleplay.com$all ||dnn.alibuf.com$all ||dns.alibuf.com$all @@ -2549,6 +2562,7 @@ ||drive.google.com/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv$all ||drive.google.com/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben$all ||drive.google.com/uc?export=download&id=1d0ij6qkgrf6irywv6ftk1m7p5l3weh3a$all +||drive.google.com/uc?export=download&id=1dzx_cflers_zntlrip3fhbxb5who03u0$all ||drive.google.com/uc?export=download&id=1gprlk2mcrl6law-zk5r0pjogaqrxwepd$all ||drive.google.com/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei$all ||drive.google.com/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr$all @@ -2575,6 +2589,7 @@ ||drive.google.com/uc?export=download&id=1voqnsh0cmxl5hty4zpc18pgnkud5rtvy$all ||drive.google.com/uc?export=download&id=1vy1nx5zefluh5ewihr-6pcndlyex7xcm$all ||drive.google.com/uc?export=download&id=1wpqa2nnnktbhzs4j0r-erosvgyaagi_a$all +||drive.google.com/uc?export=download&id=1xbp7hvw2ybwjrftbvdkjvwzrfuk4ope9$all ||drive.google.com/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e$all ||drive.google.com/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi$all ||drive.google.com/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58$all @@ -2611,11 +2626,11 @@ ||ennovate.elin.co.za$all ||equimination.ee$all ||erp.nanotechproautocare.com$all +||esaja09.top$all ||escola.probommar.org.br$all ||eservices.immigration.gov.lk$all ||esnconsultants.com$all ||essentia.org.br$all -||ethereality.info$all ||eubanks7.com$all ||europeanzonexxi.com$all ||evertkok.nl/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe$all @@ -2645,7 +2660,7 @@ ||fisconline.bar$all ||fisconline.casa$all ||fix-america-now.org$all -||fixauto.illumetechnology.com$all +||fkd.derpcity.ru$all ||flexypay.dsquaregroup.com$all ||flintspin.com$all ||flyingbuddhadesign.com$all @@ -2666,7 +2681,6 @@ ||futbolpr.com$all ||futuregraphics.com.ar$all ||g.pinmonkey.xyz$all -||gaditastour.com$all ||gametwogame.com$all ||garciadogshow.com$all ||garenanow.myvnc.com$all @@ -2697,7 +2711,6 @@ ||goldmen.in$all ||gpotecnosystems.com$all ||gracejukes.com$all -||greataccesstoserver.com$all ||grupoinmare.com$all ||gruposelt.000webhostapp.com$all ||gs.monerorx.com$all @@ -2728,19 +2741,15 @@ ||hmpmall.co.kr$all ||hoagietesting10.com$all ||hoayeuthuong-my.sharepoint.com$all -||holmesservices.mobiledevsite.co$all ||homefindersolutions.com$all ||hometownchick.com$all -||hongluosi.com$all ||hookedupboatclub.com$all ||hostingparacolombia.com$all ||hostzaa.com$all -||houstonshutters.site$all ||hqdecig.com/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/$all ||hr2019.vrcom7.com$all ||hsecaravans.co.uk/wp-admin/suy/$all ||hseda.com$all -||hsmwebapp.com$all ||htownbars.com$all ||hubtech.co.za$all ||huellacero.cl$all @@ -2766,6 +2775,7 @@ ||incrediblepixels.com$all ||incredicole.com$all ||indonesias.me:9998/64.exe$all +||indonesias.me:9998/c64.exe$all ||indrasbikaner.com$all ||infair.vn$all ||infovator.com$all @@ -2791,6 +2801,8 @@ ||it123.ru$all ||italiandirezione.casa$all ||itc-demo.softgig.co.ke$all +||itsrlytry.000webhostapp.com$all +||jaishomo.info$all ||jamiekaylive.com$all ||jamshed.pk$all ||jansen-heesch.nl$all @@ -2823,12 +2835,11 @@ ||karer.by$all ||karmakoincodes.weebly.com/uploads/3/2/8/8/3288864/karma_koin_codes.exe$all ||katanvetov.co.il$all -||kautilyaclasses.com/ds/index.html$all +||katelynn9506a.ru.com$all ||kensingtondriving.com$all ||ketofitnessexpert.com$all ||kevinjewelry.com.co$all ||keywatch.yourpageserver.com$all -||kihn-delaney30gn.ru.com$all ||kingssa.co.za$all ||kjcpromo.com$all ||kleinendeli.co.za$all @@ -2839,7 +2850,6 @@ ||ktb.sch.id$all ||kuaizip.com/down/affiliate/kuaizip_setup_10029.exe$all ||kubatoglubaklava.com.tr$all -||kullumanalitours.com$all ||kumaralok.in$all ||kwanfromhongkong.com$all ||kz.sldov.ru$all @@ -2899,7 +2909,6 @@ ||maksi.feb.unib.ac.id$all ||malaya.tv$all ||malwarecoding.github.io$all -||managed.oss-cn-beijing.aliyuncs.com$all ||managemysalon.in$all ||manantialesdelnorte.uy$all ||manhtien.net$all @@ -2942,6 +2951,7 @@ ||microblading.mirliandias.com.br$all ||microcomm-group.com$all ||mikhailmotoringschool.com$all +||mills-skyla30ec.com$all ||mingguanwms.com$all ||minpic.de/k/big5/1giof6/$all ||minuevavida.org$all @@ -2960,6 +2970,7 @@ ||moreirawag.ac.ug$all ||morrobaydrugandgift.com/wp-contentbak/t9m/$all ||motorcomunicacion.com$all +||moumitas.com$all ||msacontabil.com.br$all ||mumgee.co.za$all ||muzimbiti.xigubo.co.mz$all @@ -3015,6 +3026,7 @@ ||nyeh2o.com.au$all ||obseques-conseils.com$all ||oecteam.com$all +||ohe.ie$all ||ohsewgorgeous.co.uk$all ||oldschoolvalue.s3.amazonaws.com/spreadsheets/osv_stock_valuation-sample-dummy.exe$all ||oleholeh.memangbeda.website$all @@ -3038,6 +3050,7 @@ ||onedrive.live.com/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135$all ||onedrive.live.com/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732$all ||onedrive.live.com/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4$all +||onedrive.live.com/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc$all ||onedrive.live.com/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc$all ||onedrive.live.com/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0$all ||onedrive.live.com/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu$all @@ -3068,6 +3081,7 @@ ||onedrive.live.com/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw$all ||onedrive.live.com/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0$all ||onedrive.live.com/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a$all +||onedrive.live.com/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4$all ||onedrive.live.com/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo$all ||onedrive.live.com/download?cid=15d9646f4dbf9553&resid=15d9646f4dbf9553%21110&authkey=ag0eg1lha_lwgi0$all ||onedrive.live.com/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte$all @@ -3259,12 +3273,14 @@ ||onedrive.live.com/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8$all ||onedrive.live.com/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq$all ||onedrive.live.com/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug$all +||onedrive.live.com/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua$all ||onedrive.live.com/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe$all ||onedrive.live.com/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i$all ||onedrive.live.com/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa$all ||onedrive.live.com/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe$all ||onedrive.live.com/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m$all ||onedrive.live.com/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi$all +||onedrive.live.com/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21198&authkey=akq4jrbjm6spd9m$all ||onedrive.live.com/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi$all ||onedrive.live.com/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e$all ||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90$all @@ -3558,7 +3574,6 @@ ||onedrive.live.com/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm$all ||onedrive.live.com/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta$all ||online.creedglobal.in$all -||open.rawntech.com$all ||open.warehousesaas.co.uk$all ||opolis.io$all ||optimus.com.sg$all @@ -3639,6 +3654,7 @@ ||pujashoppe.in$all ||punchdialogues.com$all ||punjabdevelopersassociation.com.pk$all +||pvcprinting.co.uk$all ||qadir.tickfa.ir$all ||qatarglobalconsulting.com$all ||qjbutterflyevents.co.za/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/$all @@ -3677,9 +3693,9 @@ ||readymmade.com$all ||recyclethesurplus.com$all ||redbats.co.in$all +||redboxmultimedia.com$all ||redchillicrackers.com$all ||reifenquick.de$all -||relaxindulge.co.nz$all ||renehavis.com.ua$all ||repatriacioncolombia.com$all ||res.uf1.cn$all @@ -3687,7 +3703,6 @@ ||reseller.digimitra.in$all ||reseller.itechbrasil.com$all ||resuco.net$all -||revolet-sa.com$all ||rezkabum.ru$all ||rhema.com.sg$all ||richmondminerals.co.zm$all @@ -3702,6 +3717,7 @@ ||ronnietucker.co.uk$all ||roomsvc.servegate.kr$all ||roshnijewellery.com$all +||rotronics.com.ph$all ||rsgym.net$all ||rubazar.pro$all ||rubycityvietnam.com$all @@ -3731,6 +3747,7 @@ ||schoolbustracker.softgig.co.ke$all ||sculetus.nl$all ||secure-doc-reader.com$all +||secure.activedirect.xyz$all ||segalsmetals.elin.co.za$all ||sellmyphonela.com$all ||selltechtoday.com$all @@ -3741,7 +3758,9 @@ ||sericaasia.com$all ||servicemhkd.myvnc.com$all ||servicemhkd80.myvnc.com$all +||serviciovirtual.com.ar$all ||sexologistpakistan.net$all +||sgb.ac.ke$all ||sgessy.com.br$all ||shaheentbfoundation.com$all ||shahikhana.cstdevs.com$all @@ -3781,7 +3800,6 @@ ||sobethuacademy.com$all ||soft.110route.com$all ||soft.officelabo.net$all -||sogecoenergy.com$all ||sohs.conceptechs.info$all ||solar.amazingtribe.lk$all ||somcorbera.cat$all @@ -3795,7 +3813,6 @@ ||spetsesyachtcharter.gr$all ||spititourism.com$all ||spittinfire.com$all -||springbedspetroleum.com$all ||src1.minibai.com$all ||sreenivasapaintingworks.com$all ||sriglobalit.com$all @@ -3806,6 +3823,11 @@ ||staging.apparelpunch.com$all ||starcountry.net$all ||static.3001.net$all +||stdynbnbnewagedevixz.dns.army$all +||stdynmxwllminoragest.dns.army$all +||stdyunitedkesokokgst.dns.army$all +||stdyworkfinetraingst.dns.army$all +||stdyzgchgcloudgostxs.dns.army$all ||stiau.iuc.ac$all ||sticker.jewsjuice.com$all ||stiepancasetia.ac.id$all @@ -3822,10 +3844,12 @@ ||storage.googleapis.com/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt$all ||store.ericalgarin.com$all ||stott-thompson.co.uk$all +||stratexec.co.za$all ||streetdemo.yourpageserver.com$all ||suboldesign.com$all ||sumerians.org$all ||sunaryem.com.tr$all +||sunbrero.com.au$all ||sunmarkholidays.com$all ||support-4-free.com$all ||support.clz.kr$all @@ -3905,7 +3929,6 @@ ||toplevel.com.br$all ||topmask.co.za$all ||torresquinterocorp.com$all -||towme.services$all ||toyotacollege.ac.th$all ||tpke.hu$all ||translaterjemah.com$all @@ -3932,7 +3955,6 @@ ||unyazitelecom.com$all ||up.llw0.com$all ||upcbpta.com$all -||used-jeans.fr$all ||useformoney.000webhostapp.com$all ||users.skynet.be/crisanar/defis/jek_crackme1.7.zip$all ||uss.ac.th$all @@ -3942,7 +3964,6 @@ ||vcah.co.uk$all ||vectarts.com$all ||vegadelcasero.cl$all -||velma-harber30ku.com$all ||vendas.lidiacarmeli.com.br$all ||veterinariadrpopui.com$all ||vfocus.net$all @@ -3960,7 +3981,7 @@ ||vniel.co.kr/gnuboard/data/scan/amowvegfrt9ja/$all ||vniel.co.kr/gnuboard/data/scan/fu6jvxzzs46uqlp7l/$all ||vocalterra.com$all -||vokasi.ub.ac.id$all +||vokasi.ub.ac.id/wuk/kuqyslbgavnwlmcuk0qalhxifzp4mgze8anlcewu1pa8fw4lfex0y/$all ||vologroup.com.br$all ||voteyouramerica.dekitout.com$all ||vpts.co.za$all @@ -3988,6 +4009,7 @@ ||weinsteincounseling.com$all ||wfinance.com.br$all ||whcms.yourpageserver.com$all +||whiteglovetailgate.com$all ||whiteresponse.com$all ||wi522012.ferozo.com$all ||wikalen.co.za$all @@ -4018,7 +4040,7 @@ ||yeq.i.u.j.ia.n.3@zytrox.tk$all ||ylfpremium.com$all ||yoast.yourpageserver.com$all -||yp.hnggzyjy.cn/common/yz.vbs$all +||yp.hnggzyjy.cn$all ||yummyyogaudaipur.com$all ||yzkzixun.com$all ||ziyker4gaming@zytrox.tk$all diff --git a/urlhaus-filter-ag.txt b/urlhaus-filter-ag.txt index ec7a3431..5f6a305b 100644 --- a/urlhaus-filter-ag.txt +++ b/urlhaus-filter-ag.txt @@ -1,5 +1,5 @@ ! Title: Malicious URL Blocklist (AdGuard) -! Updated: Mon, 12 Apr 2021 00:12:54 UTC +! Updated: Mon, 12 Apr 2021 12:13:00 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -1391,6 +1391,7 @@ ||101.0.34.225$all ||101.0.34.229$all ||101.0.34.230$all +||101.0.34.236$all ||101.0.34.244$all ||101.0.34.247$all ||101.0.34.253$all @@ -1657,6 +1658,7 @@ ||101.108.131.81$all ||101.108.131.89$all ||101.108.131.92$all +||101.108.131.99$all ||101.108.132.0$all ||101.108.132.109$all ||101.108.132.110$all @@ -1808,6 +1810,7 @@ ||101.108.137.77$all ||101.108.138.108$all ||101.108.138.109$all +||101.108.138.150$all ||101.108.138.155$all ||101.108.138.160$all ||101.108.138.174$all @@ -6073,6 +6076,7 @@ ||103.91.245.45$all ||103.91.245.46$all ||103.91.245.47$all +||103.91.245.48$all ||103.91.245.49$all ||103.91.245.5$all ||103.91.245.54$all @@ -8785,6 +8789,7 @@ ||107.172.153.90$all ||107.172.156.122$all ||107.172.156.153$all +||107.172.156.3$all ||107.172.157.125$all ||107.172.157.131$all ||107.172.157.176$all @@ -12196,6 +12201,7 @@ ||111.92.81.107$all ||111.92.81.109$all ||111.92.81.111$all +||111.92.81.112$all ||111.92.81.113$all ||111.92.81.116$all ||111.92.81.118$all @@ -17652,6 +17658,7 @@ ||112.248.108.109$all ||112.248.108.18$all ||112.248.108.182$all +||112.248.109.156$all ||112.248.109.95$all ||112.248.11.123$all ||112.248.110.120$all @@ -20362,6 +20369,7 @@ ||112.9.149.240$all ||112.9.153.32$all ||112.9.154.61$all +||112.9.155.122$all ||112.9.157.102$all ||112.9.158.247$all ||112.9.160.95$all @@ -23895,6 +23903,7 @@ ||113.194.131.162$all ||113.194.131.197$all ||113.194.131.210$all +||113.194.131.72$all ||113.194.132.207$all ||113.194.132.253$all ||113.194.132.44$all @@ -23909,6 +23918,7 @@ ||113.194.133.9$all ||113.194.134.64$all ||113.194.135.154$all +||113.194.135.223$all ||113.194.135.230$all ||113.194.135.238$all ||113.194.135.63$all @@ -26566,6 +26576,7 @@ ||113.88.122.63$all ||113.88.122.78$all ||113.88.123.145$all +||113.88.123.22$all ||113.88.123.235$all ||113.88.124.109$all ||113.88.124.119$all @@ -26937,6 +26948,7 @@ ||113.88.211.95$all ||113.88.224.159$all ||113.88.228.13$all +||113.88.228.152$all ||113.88.228.16$all ||113.88.228.211$all ||113.88.228.73$all @@ -27191,6 +27203,7 @@ ||113.88.65.37$all ||113.88.65.38$all ||113.88.65.48$all +||113.88.65.49$all ||113.88.65.54$all ||113.88.65.80$all ||113.88.66.213$all @@ -27397,6 +27410,7 @@ ||113.89.247.90$all ||113.89.248.112$all ||113.89.248.181$all +||113.89.4.189$all ||113.89.4.201$all ||113.89.4.7$all ||113.89.4.74$all @@ -27664,6 +27678,7 @@ ||113.9.241.101$all ||113.9.29.128$all ||113.9.94.126$all +||113.90.133.38$all ||113.90.135.225$all ||113.90.135.231$all ||113.90.160.138$all @@ -28335,6 +28350,7 @@ ||114.223.238.75$all ||114.223.244.108$all ||114.223.28.254$all +||114.223.43.7$all ||114.223.48.158$all ||114.223.61.204$all ||114.223.63.197$all @@ -29093,6 +29109,7 @@ ||114.235.211.48$all ||114.235.211.60$all ||114.235.211.88$all +||114.235.213.31$all ||114.235.22.32$all ||114.235.222.230$all ||114.235.222.24$all @@ -30062,6 +30079,7 @@ ||114.97.224.73$all ||114.97.225.120$all ||114tv.cc$all +||115.110.193.166$all ||115.120.136.248$all ||115.120.204.211$all ||115.127.96.194$all @@ -34706,6 +34724,7 @@ ||115.49.232.129$all ||115.49.232.177$all ||115.49.232.185$all +||115.49.232.197$all ||115.49.232.20$all ||115.49.232.204$all ||115.49.232.210$all @@ -37076,6 +37095,7 @@ ||115.50.172.21$all ||115.50.172.212$all ||115.50.172.216$all +||115.50.172.22$all ||115.50.172.223$all ||115.50.172.225$all ||115.50.172.236$all @@ -37430,6 +37450,7 @@ ||115.50.2.128$all ||115.50.2.132$all ||115.50.2.141$all +||115.50.2.148$all ||115.50.2.149$all ||115.50.2.159$all ||115.50.2.179$all @@ -42352,6 +42373,7 @@ ||115.51.91.62$all ||115.51.91.66$all ||115.51.91.70$all +||115.51.91.81$all ||115.51.91.98$all ||115.51.92.1$all ||115.51.92.114$all @@ -45316,6 +45338,7 @@ ||115.54.212.163$all ||115.54.212.17$all ||115.54.212.173$all +||115.54.212.175$all ||115.54.212.180$all ||115.54.212.183$all ||115.54.212.185$all @@ -49425,6 +49448,7 @@ ||115.55.7.241$all ||115.55.7.55$all ||115.55.7.60$all +||115.55.7.9$all ||115.55.7.92$all ||115.55.70.113$all ||115.55.71.231$all @@ -57124,6 +57148,7 @@ ||115.59.248.228$all ||115.59.25.113$all ||115.59.25.169$all +||115.59.250.37$all ||115.59.250.52$all ||115.59.252.114$all ||115.59.252.12$all @@ -59307,6 +59332,7 @@ ||115.61.167.185$all ||115.61.167.196$all ||115.61.167.207$all +||115.61.167.21$all ||115.61.167.225$all ||115.61.167.227$all ||115.61.167.230$all @@ -59815,6 +59841,7 @@ ||115.61.186.106$all ||115.61.186.11$all ||115.61.186.114$all +||115.61.186.139$all ||115.61.186.144$all ||115.61.186.153$all ||115.61.186.158$all @@ -60696,6 +60723,7 @@ ||115.62.171.71$all ||115.62.171.81$all ||115.62.172.135$all +||115.62.172.140$all ||115.62.172.145$all ||115.62.172.173$all ||115.62.172.200$all @@ -60754,6 +60782,7 @@ ||115.62.25.100$all ||115.62.26.100$all ||115.62.26.102$all +||115.62.26.113$all ||115.62.26.114$all ||115.62.26.120$all ||115.62.26.123$all @@ -66693,6 +66722,7 @@ ||115.96.199.129$all ||115.96.199.132$all ||115.96.199.138$all +||115.96.199.146$all ||115.96.199.160$all ||115.96.199.163$all ||115.96.199.165$all @@ -91492,6 +91522,7 @@ ||116.106.77.111$all ||116.108.32.244$all ||116.108.71.196$all +||116.108.92.154$all ||116.109.108.32$all ||116.109.132.2$all ||116.109.156.14$all @@ -93313,6 +93344,7 @@ ||116.68.96.98$all ||116.68.96.99$all ||116.68.97.1$all +||116.68.97.100$all ||116.68.97.102$all ||116.68.97.104$all ||116.68.97.117$all @@ -93431,6 +93463,7 @@ ||116.68.99.129$all ||116.68.99.132$all ||116.68.99.139$all +||116.68.99.152$all ||116.68.99.155$all ||116.68.99.158$all ||116.68.99.159$all @@ -114169,6 +114202,7 @@ ||117.194.162.117$all ||117.194.162.118$all ||117.194.162.119$all +||117.194.162.12$all ||117.194.162.120$all ||117.194.162.121$all ||117.194.162.122$all @@ -116158,6 +116192,7 @@ ||117.201.197.124$all ||117.201.199.181$all ||117.201.199.230$all +||117.201.200.106$all ||117.201.200.236$all ||117.201.201.33$all ||117.201.202.154$all @@ -119706,6 +119741,7 @@ ||117.213.12.130$all ||117.213.12.148$all ||117.213.12.158$all +||117.213.12.177$all ||117.213.12.208$all ||117.213.12.218$all ||117.213.12.219$all @@ -121203,6 +121239,7 @@ ||117.213.9.1$all ||117.213.9.177$all ||117.213.9.203$all +||117.213.9.42$all ||117.213.9.58$all ||117.213.9.71$all ||117.213.9.77$all @@ -121559,6 +121596,7 @@ ||117.215.249.174$all ||117.215.249.175$all ||117.215.249.181$all +||117.215.249.196$all ||117.215.249.197$all ||117.215.249.199$all ||117.215.249.20$all @@ -121571,6 +121609,7 @@ ||117.215.249.241$all ||117.215.249.242$all ||117.215.249.245$all +||117.215.249.250$all ||117.215.249.251$all ||117.215.249.255$all ||117.215.249.27$all @@ -124073,6 +124112,7 @@ ||117.222.175.122$all ||117.222.175.13$all ||117.222.175.130$all +||117.222.175.134$all ||117.222.175.135$all ||117.222.175.136$all ||117.222.175.138$all @@ -126040,6 +126080,7 @@ ||117.247.201.42$all ||117.247.201.43$all ||117.247.201.44$all +||117.247.201.45$all ||117.247.201.47$all ||117.247.201.49$all ||117.247.201.56$all @@ -128764,6 +128805,7 @@ ||117.63.124.134$all ||117.63.127.23$all ||117.63.130.19$all +||117.63.133.251$all ||117.63.151.77$all ||117.63.156.234$all ||117.63.157.34$all @@ -130764,6 +130806,7 @@ ||118.79.112.110$all ||118.79.112.230$all ||118.79.112.54$all +||118.79.113.239$all ||118.79.113.7$all ||118.79.114.198$all ||118.79.114.78$all @@ -137073,6 +137116,7 @@ ||119.99.251.129$all ||119.99.30.19$all ||119.99.50.91$all +||119.99.52.69$all ||119.99.63.42$all ||11bybbsny.com$all ||11degrees.org$all @@ -145678,6 +145722,7 @@ ||123.10.32.196$all ||123.10.32.200$all ||123.10.32.239$all +||123.10.32.252$all ||123.10.32.87$all ||123.10.32.95$all ||123.10.33.112$all @@ -153468,6 +153513,7 @@ ||123.14.95.219$all ||123.14.95.24$all ||123.14.95.248$all +||123.14.95.26$all ||123.14.96.154$all ||123.14.96.157$all ||123.14.96.209$all @@ -155849,6 +155895,7 @@ ||123.4.242.146$all ||123.4.242.152$all ||123.4.242.163$all +||123.4.242.19$all ||123.4.242.199$all ||123.4.242.204$all ||123.4.242.21$all @@ -156238,6 +156285,7 @@ ||123.4.47.248$all ||123.4.47.25$all ||123.4.47.32$all +||123.4.47.57$all ||123.4.48.128$all ||123.4.48.40$all ||123.4.48.70$all @@ -159050,6 +159098,7 @@ ||123.5.188.85$all ||123.5.188.86$all ||123.5.188.87$all +||123.5.188.9$all ||123.5.188.93$all ||123.5.188.97$all ||123.5.189.101$all @@ -159063,6 +159112,7 @@ ||123.5.189.14$all ||123.5.189.145$all ||123.5.189.147$all +||123.5.189.15$all ||123.5.189.150$all ||123.5.189.151$all ||123.5.189.154$all @@ -161246,6 +161296,7 @@ ||123.9.117.236$all ||123.9.117.245$all ||123.9.118.130$all +||123.9.118.183$all ||123.9.118.79$all ||123.9.119.209$all ||123.9.119.47$all @@ -162414,6 +162465,7 @@ ||123.9.35.198$all ||123.9.35.6$all ||123.9.35.88$all +||123.9.36.120$all ||123.9.36.188$all ||123.9.36.222$all ||123.9.36.6$all @@ -168263,6 +168315,7 @@ ||125.41.14.219$all ||125.41.14.22$all ||125.41.14.220$all +||125.41.14.228$all ||125.41.14.232$all ||125.41.14.235$all ||125.41.14.237$all @@ -188680,6 +188733,7 @@ ||143.198.220.102$all ||143.198.48.37$all ||143.198.54.180$all +||143.198.54.233$all ||143.198.63.143$all ||143.198.65.195$all ||143.198.65.229$all @@ -188946,6 +189000,7 @@ ||149.255.15.134$all ||149.255.15.138$all ||149.255.15.143$all +||149.255.15.170$all ||149.255.15.172$all ||149.255.15.180$all ||149.255.15.182$all @@ -188954,8 +189009,10 @@ ||149.255.15.213$all ||149.255.15.235$all ||149.255.15.27$all +||149.255.15.29$all ||149.255.15.38$all ||149.255.15.43$all +||149.255.15.44$all ||149.255.15.87$all ||149.255.15.99$all ||149.255.36.133$all @@ -190159,6 +190216,7 @@ ||157.90.24.103$all ||157.90.244.110$all ||157.90.244.177$all +||157.90.8.28$all ||157.97.133.128$all ||157.97.17.46$all ||157.97.2.215$all @@ -191391,6 +191449,7 @@ ||162.244.81.158$all ||162.244.81.204$all ||162.244.81.55$all +||162.245.221.121$all ||162.246.15.229$all ||162.246.20.117$all ||162.246.20.236$all @@ -203058,6 +203117,7 @@ ||178.175.10.224$all ||178.175.10.240$all ||178.175.10.244$all +||178.175.10.247$all ||178.175.10.248$all ||178.175.10.251$all ||178.175.10.254$all @@ -203089,6 +203149,7 @@ ||178.175.10.98$all ||178.175.10.99$all ||178.175.100.101$all +||178.175.100.104$all ||178.175.100.106$all ||178.175.100.109$all ||178.175.100.11$all @@ -203239,6 +203300,7 @@ ||178.175.101.21$all ||178.175.101.210$all ||178.175.101.211$all +||178.175.101.212$all ||178.175.101.213$all ||178.175.101.217$all ||178.175.101.219$all @@ -203340,6 +203402,7 @@ ||178.175.102.179$all ||178.175.102.183$all ||178.175.102.184$all +||178.175.102.186$all ||178.175.102.188$all ||178.175.102.189$all ||178.175.102.190$all @@ -203517,6 +203580,7 @@ ||178.175.104.110$all ||178.175.104.112$all ||178.175.104.114$all +||178.175.104.115$all ||178.175.104.116$all ||178.175.104.12$all ||178.175.104.120$all @@ -203863,6 +203927,7 @@ ||178.175.107.127$all ||178.175.107.13$all ||178.175.107.133$all +||178.175.107.135$all ||178.175.107.136$all ||178.175.107.138$all ||178.175.107.140$all @@ -204187,6 +204252,7 @@ ||178.175.109.96$all ||178.175.109.98$all ||178.175.11.0$all +||178.175.11.100$all ||178.175.11.101$all ||178.175.11.104$all ||178.175.11.105$all @@ -204614,6 +204680,7 @@ ||178.175.112.81$all ||178.175.112.85$all ||178.175.112.86$all +||178.175.112.87$all ||178.175.112.89$all ||178.175.112.90$all ||178.175.112.97$all @@ -205646,6 +205713,7 @@ ||178.175.121.12$all ||178.175.121.122$all ||178.175.121.123$all +||178.175.121.125$all ||178.175.121.129$all ||178.175.121.130$all ||178.175.121.133$all @@ -206304,6 +206372,7 @@ ||178.175.126.38$all ||178.175.126.4$all ||178.175.126.41$all +||178.175.126.43$all ||178.175.126.44$all ||178.175.126.46$all ||178.175.126.48$all @@ -206499,6 +206568,7 @@ ||178.175.13.212$all ||178.175.13.213$all ||178.175.13.216$all +||178.175.13.219$all ||178.175.13.220$all ||178.175.13.221$all ||178.175.13.222$all @@ -206602,6 +206672,7 @@ ||178.175.14.251$all ||178.175.14.27$all ||178.175.14.28$all +||178.175.14.29$all ||178.175.14.3$all ||178.175.14.32$all ||178.175.14.33$all @@ -206671,6 +206742,7 @@ ||178.175.15.190$all ||178.175.15.194$all ||178.175.15.195$all +||178.175.15.196$all ||178.175.15.197$all ||178.175.15.198$all ||178.175.15.199$all @@ -206987,6 +207059,7 @@ ||178.175.18.250$all ||178.175.18.253$all ||178.175.18.27$all +||178.175.18.31$all ||178.175.18.32$all ||178.175.18.36$all ||178.175.18.37$all @@ -207170,6 +207243,7 @@ ||178.175.2.224$all ||178.175.2.225$all ||178.175.2.226$all +||178.175.2.23$all ||178.175.2.230$all ||178.175.2.234$all ||178.175.2.236$all @@ -207448,6 +207522,7 @@ ||178.175.22.187$all ||178.175.22.188$all ||178.175.22.194$all +||178.175.22.198$all ||178.175.22.203$all ||178.175.22.206$all ||178.175.22.207$all @@ -207490,6 +207565,7 @@ ||178.175.22.67$all ||178.175.22.69$all ||178.175.22.72$all +||178.175.22.74$all ||178.175.22.75$all ||178.175.22.78$all ||178.175.22.83$all @@ -207725,6 +207801,7 @@ ||178.175.25.155$all ||178.175.25.156$all ||178.175.25.159$all +||178.175.25.162$all ||178.175.25.163$all ||178.175.25.164$all ||178.175.25.166$all @@ -207989,6 +208066,7 @@ ||178.175.27.25$all ||178.175.27.252$all ||178.175.27.253$all +||178.175.27.26$all ||178.175.27.30$all ||178.175.27.32$all ||178.175.27.34$all @@ -207998,6 +208076,7 @@ ||178.175.27.39$all ||178.175.27.4$all ||178.175.27.41$all +||178.175.27.43$all ||178.175.27.46$all ||178.175.27.47$all ||178.175.27.48$all @@ -208411,6 +208490,7 @@ ||178.175.30.80$all ||178.175.30.81$all ||178.175.30.86$all +||178.175.30.90$all ||178.175.30.91$all ||178.175.30.93$all ||178.175.30.96$all @@ -208689,6 +208769,7 @@ ||178.175.33.228$all ||178.175.33.23$all ||178.175.33.231$all +||178.175.33.233$all ||178.175.33.234$all ||178.175.33.236$all ||178.175.33.239$all @@ -209642,6 +209723,7 @@ ||178.175.41.225$all ||178.175.41.229$all ||178.175.41.23$all +||178.175.41.230$all ||178.175.41.231$all ||178.175.41.235$all ||178.175.41.237$all @@ -209999,6 +210081,7 @@ ||178.175.44.89$all ||178.175.44.9$all ||178.175.44.90$all +||178.175.44.93$all ||178.175.44.95$all ||178.175.44.96$all ||178.175.45.10$all @@ -210214,6 +210297,7 @@ ||178.175.46.54$all ||178.175.46.55$all ||178.175.46.59$all +||178.175.46.60$all ||178.175.46.61$all ||178.175.46.63$all ||178.175.46.65$all @@ -210244,6 +210328,7 @@ ||178.175.47.12$all ||178.175.47.122$all ||178.175.47.126$all +||178.175.47.127$all ||178.175.47.128$all ||178.175.47.132$all ||178.175.47.139$all @@ -210374,6 +210459,7 @@ ||178.175.48.161$all ||178.175.48.162$all ||178.175.48.163$all +||178.175.48.164$all ||178.175.48.168$all ||178.175.48.17$all ||178.175.48.172$all @@ -210587,6 +210673,7 @@ ||178.175.5.22$all ||178.175.5.221$all ||178.175.5.222$all +||178.175.5.223$all ||178.175.5.226$all ||178.175.5.227$all ||178.175.5.229$all @@ -210844,6 +210931,7 @@ ||178.175.52.11$all ||178.175.52.111$all ||178.175.52.112$all +||178.175.52.114$all ||178.175.52.115$all ||178.175.52.118$all ||178.175.52.119$all @@ -210903,6 +210991,7 @@ ||178.175.52.249$all ||178.175.52.250$all ||178.175.52.252$all +||178.175.52.255$all ||178.175.52.31$all ||178.175.52.33$all ||178.175.52.34$all @@ -211036,6 +211125,7 @@ ||178.175.53.83$all ||178.175.53.85$all ||178.175.53.86$all +||178.175.53.87$all ||178.175.53.9$all ||178.175.53.90$all ||178.175.53.94$all @@ -211139,6 +211229,7 @@ ||178.175.54.71$all ||178.175.54.72$all ||178.175.54.74$all +||178.175.54.78$all ||178.175.54.80$all ||178.175.54.81$all ||178.175.54.87$all @@ -211159,6 +211250,7 @@ ||178.175.55.113$all ||178.175.55.114$all ||178.175.55.117$all +||178.175.55.118$all ||178.175.55.119$all ||178.175.55.121$all ||178.175.55.125$all @@ -211368,6 +211460,7 @@ ||178.175.57.102$all ||178.175.57.103$all ||178.175.57.104$all +||178.175.57.105$all ||178.175.57.108$all ||178.175.57.11$all ||178.175.57.112$all @@ -211482,6 +211575,7 @@ ||178.175.58.125$all ||178.175.58.126$all ||178.175.58.127$all +||178.175.58.130$all ||178.175.58.133$all ||178.175.58.139$all ||178.175.58.14$all @@ -211504,6 +211598,7 @@ ||178.175.58.175$all ||178.175.58.177$all ||178.175.58.178$all +||178.175.58.18$all ||178.175.58.183$all ||178.175.58.185$all ||178.175.58.188$all @@ -211723,6 +211818,8 @@ ||178.175.6.196$all ||178.175.6.198$all ||178.175.6.2$all +||178.175.6.201$all +||178.175.6.203$all ||178.175.6.204$all ||178.175.6.205$all ||178.175.6.207$all @@ -211909,6 +212006,7 @@ ||178.175.61.206$all ||178.175.61.209$all ||178.175.61.210$all +||178.175.61.212$all ||178.175.61.214$all ||178.175.61.217$all ||178.175.61.219$all @@ -211976,6 +212074,7 @@ ||178.175.62.122$all ||178.175.62.123$all ||178.175.62.128$all +||178.175.62.130$all ||178.175.62.134$all ||178.175.62.137$all ||178.175.62.141$all @@ -212638,6 +212737,7 @@ ||178.175.68.161$all ||178.175.68.162$all ||178.175.68.164$all +||178.175.68.165$all ||178.175.68.166$all ||178.175.68.167$all ||178.175.68.17$all @@ -213270,6 +213370,7 @@ ||178.175.72.53$all ||178.175.72.54$all ||178.175.72.56$all +||178.175.72.58$all ||178.175.72.6$all ||178.175.72.61$all ||178.175.72.65$all @@ -213666,6 +213767,7 @@ ||178.175.76.27$all ||178.175.76.29$all ||178.175.76.33$all +||178.175.76.34$all ||178.175.76.36$all ||178.175.76.37$all ||178.175.76.43$all @@ -213950,6 +214052,7 @@ ||178.175.79.244$all ||178.175.79.247$all ||178.175.79.253$all +||178.175.79.27$all ||178.175.79.30$all ||178.175.79.31$all ||178.175.79.38$all @@ -214424,6 +214527,7 @@ ||178.175.83.156$all ||178.175.83.158$all ||178.175.83.167$all +||178.175.83.17$all ||178.175.83.176$all ||178.175.83.18$all ||178.175.83.180$all @@ -214692,6 +214796,7 @@ ||178.175.85.230$all ||178.175.85.231$all ||178.175.85.234$all +||178.175.85.235$all ||178.175.85.242$all ||178.175.85.243$all ||178.175.85.244$all @@ -215525,6 +215630,7 @@ ||178.175.92.208$all ||178.175.92.210$all ||178.175.92.211$all +||178.175.92.213$all ||178.175.92.214$all ||178.175.92.215$all ||178.175.92.218$all @@ -215634,6 +215740,7 @@ ||178.175.93.200$all ||178.175.93.202$all ||178.175.93.203$all +||178.175.93.204$all ||178.175.93.205$all ||178.175.93.207$all ||178.175.93.210$all @@ -215920,6 +216027,7 @@ ||178.175.95.79$all ||178.175.95.80$all ||178.175.95.82$all +||178.175.95.83$all ||178.175.95.85$all ||178.175.95.86$all ||178.175.95.88$all @@ -218519,6 +218627,7 @@ ||180.177.104.65$all ||180.177.180.6$all ||180.177.242.73$all +||180.177.5.36$all ||180.177.76.161$all ||180.177.80.11$all ||180.178.104.86$all @@ -218626,7 +218735,9 @@ ||180.188.241.91$all ||180.188.241.99$all ||180.188.247.140$all +||180.188.247.172$all ||180.188.247.181$all +||180.188.247.218$all ||180.188.247.26$all ||180.188.252.185$all ||180.188.252.37$all @@ -222743,6 +222854,7 @@ ||182.113.4.209$all ||182.113.4.223$all ||182.113.4.226$all +||182.113.4.247$all ||182.113.4.64$all ||182.113.4.68$all ||182.113.4.88$all @@ -223713,6 +223825,7 @@ ||182.114.193.245$all ||182.114.193.70$all ||182.114.194.116$all +||182.114.194.183$all ||182.114.194.184$all ||182.114.194.206$all ||182.114.194.210$all @@ -235189,6 +235302,7 @@ ||182.119.23.62$all ||182.119.23.70$all ||182.119.23.74$all +||182.119.23.75$all ||182.119.23.9$all ||182.119.23.90$all ||182.119.23.91$all @@ -235634,6 +235748,7 @@ ||182.119.48.200$all ||182.119.48.205$all ||182.119.48.217$all +||182.119.48.230$all ||182.119.48.242$all ||182.119.48.250$all ||182.119.48.255$all @@ -238505,6 +238620,7 @@ ||182.121.123.1$all ||182.121.123.122$all ||182.121.123.124$all +||182.121.123.134$all ||182.121.123.141$all ||182.121.123.142$all ||182.121.123.16$all @@ -239957,6 +240073,7 @@ ||182.121.200.115$all ||182.121.200.119$all ||182.121.200.127$all +||182.121.200.137$all ||182.121.200.143$all ||182.121.200.151$all ||182.121.200.161$all @@ -240149,6 +240266,7 @@ ||182.121.205.223$all ||182.121.205.228$all ||182.121.205.237$all +||182.121.205.246$all ||182.121.205.251$all ||182.121.205.39$all ||182.121.205.47$all @@ -246644,6 +246762,7 @@ ||182.126.109.133$all ||182.126.109.146$all ||182.126.109.150$all +||182.126.109.194$all ||182.126.109.20$all ||182.126.109.25$all ||182.126.109.255$all @@ -247409,6 +247528,7 @@ ||182.126.126.150$all ||182.126.126.16$all ||182.126.126.161$all +||182.126.126.162$all ||182.126.126.170$all ||182.126.126.176$all ||182.126.126.181$all @@ -251639,6 +251759,7 @@ ||182.127.207.156$all ||182.127.207.158$all ||182.127.207.162$all +||182.127.207.187$all ||182.127.207.218$all ||182.127.207.226$all ||182.127.207.247$all @@ -252695,6 +252816,7 @@ ||182.127.80.184$all ||182.127.80.192$all ||182.127.80.229$all +||182.127.80.240$all ||182.127.80.85$all ||182.127.80.89$all ||182.127.81.114$all @@ -253359,6 +253481,7 @@ ||182.235.29.89$all ||182.236.124.160$all ||182.239.129.154$all +||182.240.132.164$all ||182.240.132.203$all ||182.240.213.4$all ||182.240.214.81$all @@ -255111,6 +255234,7 @@ ||182.57.105.110$all ||182.57.105.161$all ||182.57.105.167$all +||182.57.105.175$all ||182.57.106.118$all ||182.57.106.190$all ||182.57.106.237$all @@ -260598,6 +260722,7 @@ ||183.141.54.112$all ||183.141.55.239$all ||183.141.60.120$all +||183.141.61.174$all ||183.141.61.39$all ||183.142.11.225$all ||183.142.115.155$all @@ -261262,6 +261387,7 @@ ||183.17.227.102$all ||183.17.227.109$all ||183.17.227.113$all +||183.17.227.148$all ||183.17.227.162$all ||183.17.227.172$all ||183.17.227.187$all @@ -261821,6 +261947,7 @@ ||183.49.47.56$all ||183.49.85.243$all ||183.49.85.247$all +||183.49.86.54$all ||183.49.87.144$all ||183.49.87.220$all ||183.49.87.27$all @@ -261909,6 +262036,7 @@ ||183.83.103.117$all ||183.83.104.165$all ||183.83.104.44$all +||183.83.104.55$all ||183.83.104.68$all ||183.83.105.181$all ||183.83.105.21$all @@ -262500,6 +262628,7 @@ ||185.117.119.71$all ||185.117.155.20$all ||185.117.2.107$all +||185.117.21.212$all ||185.117.75.111$all ||185.117.75.201$all ||185.117.75.248$all @@ -262589,6 +262718,7 @@ ||185.132.53.161$all ||185.132.53.166$all ||185.132.53.167$all +||185.132.53.182$all ||185.132.53.185$all ||185.132.53.186$all ||185.132.53.191$all @@ -263783,6 +263913,7 @@ ||185.36.59.11$all ||185.36.59.76$all ||185.36.81.43$all +||185.38.142.194$all ||185.38.142.236$all ||185.39.11.105$all ||185.39.183.48$all @@ -265141,6 +265272,7 @@ ||186.33.105.7$all ||186.33.105.8$all ||186.33.105.9$all +||186.33.107.74$all ||186.33.112.100$all ||186.33.112.101$all ||186.33.112.102$all @@ -267391,9 +267523,11 @@ ||189.170.12.149$all ||189.170.178.180$all ||189.170.40.102$all +||189.171.22.132$all ||189.171.31.166$all ||189.172.151.237$all ||189.174.35.248$all +||189.175.214.112$all ||189.176.68.26$all ||189.176.93.82$all ||189.177.144.215$all @@ -270026,6 +270160,7 @@ ||192.99.169.15$all ||192.99.208.196$all ||192.99.214.32$all +||192.99.221.230$all ||192.99.240.77$all ||192.99.242.13$all ||192.99.246.11$all @@ -273894,6 +274029,7 @@ ||202.164.138.156$all ||202.164.138.157$all ||202.164.138.158$all +||202.164.138.159$all ||202.164.138.160$all ||202.164.138.161$all ||202.164.138.162$all @@ -274150,6 +274286,7 @@ ||202.164.139.255$all ||202.164.139.26$all ||202.164.139.28$all +||202.164.139.29$all ||202.164.139.30$all ||202.164.139.31$all ||202.164.139.36$all @@ -274168,6 +274305,7 @@ ||202.164.139.52$all ||202.164.139.55$all ||202.164.139.56$all +||202.164.139.57$all ||202.164.139.58$all ||202.164.139.6$all ||202.164.139.60$all @@ -278154,6 +278292,7 @@ ||206.189.129.96$all ||206.189.131.31$all ||206.189.132.42$all +||206.189.135.162$all ||206.189.135.253$all ||206.189.138.82$all ||206.189.140.181$all @@ -282801,6 +282940,7 @@ ||219.154.113.157$all ||219.154.113.161$all ||219.154.113.163$all +||219.154.113.171$all ||219.154.113.172$all ||219.154.113.177$all ||219.154.113.181$all @@ -285162,6 +285302,7 @@ ||219.155.226.188$all ||219.155.226.194$all ||219.155.226.198$all +||219.155.226.205$all ||219.155.226.225$all ||219.155.226.43$all ||219.155.226.50$all @@ -288414,6 +288555,7 @@ ||219.157.138.38$all ||219.157.138.63$all ||219.157.139.165$all +||219.157.14.239$all ||219.157.14.85$all ||219.157.140.190$all ||219.157.140.255$all @@ -288876,6 +289018,7 @@ ||219.157.178.171$all ||219.157.178.179$all ||219.157.178.192$all +||219.157.178.196$all ||219.157.178.201$all ||219.157.178.205$all ||219.157.178.21$all @@ -291046,6 +291189,7 @@ ||219.157.48.44$all ||219.157.48.45$all ||219.157.48.46$all +||219.157.48.5$all ||219.157.48.51$all ||219.157.48.58$all ||219.157.48.59$all @@ -294211,6 +294355,7 @@ ||221.14.47.162$all ||221.14.47.182$all ||221.14.47.189$all +||221.14.47.204$all ||221.14.47.225$all ||221.14.47.46$all ||221.14.47.77$all @@ -295627,6 +295772,7 @@ ||221.15.182.29$all ||221.15.182.40$all ||221.15.182.48$all +||221.15.182.72$all ||221.15.182.9$all ||221.15.182.94$all ||221.15.183.104$all @@ -297170,6 +297316,7 @@ ||221.15.53.25$all ||221.15.53.42$all ||221.15.53.46$all +||221.15.53.55$all ||221.15.53.57$all ||221.15.53.62$all ||221.15.53.74$all @@ -307792,6 +307939,7 @@ ||222.140.163.15$all ||222.140.163.159$all ||222.140.163.179$all +||222.140.163.181$all ||222.140.163.184$all ||222.140.163.188$all ||222.140.163.208$all @@ -312936,6 +313084,7 @@ ||23.95.116.135$all ||23.95.116.144$all ||23.95.122.24$all +||23.95.122.25$all ||23.95.122.47$all ||23.95.13.131$all ||23.95.13.158$all @@ -323163,6 +323312,7 @@ ||27.40.71.3$all ||27.40.72.200$all ||27.40.73.175$all +||27.40.79.170$all ||27.40.79.70$all ||27.40.82.129$all ||27.40.82.201$all @@ -347530,6 +347680,7 @@ ||31.168.126.45$all ||31.168.146.199$all ||31.168.153.60$all +||31.168.16.68$all ||31.168.177.37$all ||31.168.178.71$all ||31.168.179.83$all @@ -356494,6 +356645,7 @@ ||41.143.247.190$all ||41.143.31.149$all ||41.143.57.149$all +||41.143.69.12$all ||41.144.143.214$all ||41.144.159.85$all ||41.146.243.74$all @@ -358755,6 +358907,7 @@ ||42.224.171.138$all ||42.224.171.162$all ||42.224.171.163$all +||42.224.171.165$all ||42.224.171.168$all ||42.224.171.193$all ||42.224.171.196$all @@ -360540,6 +360693,7 @@ ||42.224.254.199$all ||42.224.254.205$all ||42.224.254.207$all +||42.224.254.220$all ||42.224.254.224$all ||42.224.254.226$all ||42.224.254.228$all @@ -361066,6 +361220,7 @@ ||42.224.4.0$all ||42.224.4.1$all ||42.224.4.100$all +||42.224.4.110$all ||42.224.4.112$all ||42.224.4.12$all ||42.224.4.120$all @@ -365234,6 +365389,7 @@ ||42.227.222.143$all ||42.227.222.158$all ||42.227.222.174$all +||42.227.222.189$all ||42.227.222.229$all ||42.227.222.244$all ||42.227.222.43$all @@ -365269,6 +365425,7 @@ ||42.227.225.154$all ||42.227.225.181$all ||42.227.225.209$all +||42.227.225.253$all ||42.227.225.45$all ||42.227.225.49$all ||42.227.225.81$all @@ -369139,6 +369296,7 @@ ||42.230.142.79$all ||42.230.142.82$all ||42.230.143.130$all +||42.230.143.162$all ||42.230.143.17$all ||42.230.143.174$all ||42.230.143.176$all @@ -373512,6 +373670,7 @@ ||42.232.169.202$all ||42.232.169.203$all ||42.232.169.209$all +||42.232.169.211$all ||42.232.169.219$all ||42.232.169.22$all ||42.232.169.223$all @@ -375217,6 +375376,7 @@ ||42.233.96.52$all ||42.233.96.71$all ||42.233.97.10$all +||42.233.97.141$all ||42.233.97.149$all ||42.233.97.157$all ||42.233.97.160$all @@ -379856,6 +380016,7 @@ ||42.235.84.52$all ||42.235.84.54$all ||42.235.84.73$all +||42.235.84.85$all ||42.235.84.87$all ||42.235.84.88$all ||42.235.84.97$all @@ -381067,6 +381228,7 @@ ||42.237.114.252$all ||42.237.114.48$all ||42.237.114.50$all +||42.237.114.80$all ||42.237.114.87$all ||42.237.115.169$all ||42.237.115.175$all @@ -384953,6 +385115,7 @@ ||45.15.143.158$all ||45.15.143.170$all ||45.15.143.175$all +||45.15.143.191$all ||45.15.143.253$all ||45.15.25.65$all ||45.15.253.88$all @@ -386147,6 +386310,7 @@ ||45.229.54.198$all ||45.229.54.199$all ||45.229.54.200$all +||45.229.54.201$all ||45.229.54.202$all ||45.229.54.203$all ||45.229.54.204$all @@ -386248,6 +386412,7 @@ ||45.229.55.71$all ||45.229.55.75$all ||45.229.55.79$all +||45.229.55.80$all ||45.229.55.83$all ||45.229.55.85$all ||45.229.55.98$all @@ -386931,6 +387096,7 @@ ||45.77.78.41$all ||45.77.79.163$all ||45.77.88.79$all +||45.77.9.151$all ||45.77.97.236$all ||45.77.98.62$all ||45.78.21.150$all @@ -393506,6 +393672,7 @@ ||58.249.75.128$all ||58.249.75.13$all ||58.249.75.14$all +||58.249.75.146$all ||58.249.75.158$all ||58.249.75.159$all ||58.249.75.169$all @@ -393567,6 +393734,7 @@ ||58.249.77.105$all ||58.249.77.119$all ||58.249.77.12$all +||58.249.77.141$all ||58.249.77.142$all ||58.249.77.144$all ||58.249.77.147$all @@ -393904,6 +394072,7 @@ ||58.249.86.20$all ||58.249.86.202$all ||58.249.86.203$all +||58.249.86.214$all ||58.249.86.227$all ||58.249.86.242$all ||58.249.86.31$all @@ -394952,6 +395121,7 @@ ||59.126.128.92$all ||59.126.13.182$all ||59.126.132.4$all +||59.126.132.42$all ||59.126.136.62$all ||59.126.139.144$all ||59.126.148.122$all @@ -398976,6 +399146,7 @@ ||59.5.192.126$all ||59.5.204.218$all ||59.5.230.140$all +||59.50.23.23$all ||59.50.28.100$all ||59.51.10.111$all ||59.51.10.55$all @@ -401274,6 +401445,7 @@ ||59.92.217.210$all ||59.92.217.211$all ||59.92.217.214$all +||59.92.217.215$all ||59.92.217.217$all ||59.92.217.218$all ||59.92.217.219$all @@ -402443,6 +402615,7 @@ ||59.93.21.137$all ||59.93.21.138$all ||59.93.21.14$all +||59.93.21.140$all ||59.93.21.141$all ||59.93.21.146$all ||59.93.21.147$all @@ -403725,6 +403898,7 @@ ||59.94.182.208$all ||59.94.182.21$all ||59.94.182.210$all +||59.94.182.212$all ||59.94.182.216$all ||59.94.182.217$all ||59.94.182.22$all @@ -404616,6 +404790,7 @@ ||59.95.175.46$all ||59.95.175.47$all ||59.95.175.48$all +||59.95.175.49$all ||59.95.175.5$all ||59.95.175.50$all ||59.95.175.51$all @@ -412479,6 +412654,7 @@ ||60.211.80.189$all ||60.211.80.208$all ||60.211.80.213$all +||60.211.80.216$all ||60.211.80.5$all ||60.211.80.9$all ||60.211.81.125$all @@ -413134,6 +413310,7 @@ ||60.214.52.40$all ||60.214.52.50$all ||60.214.52.96$all +||60.214.53.159$all ||60.214.53.170$all ||60.214.53.183$all ||60.214.53.242$all @@ -422642,6 +422819,7 @@ ||60.254.88.6$all ||60.254.88.91$all ||60.254.89.110$all +||60.254.89.158$all ||60.254.89.160$all ||60.254.89.191$all ||60.254.89.195$all @@ -425720,6 +425898,7 @@ ||61.3.149.196$all ||61.3.149.197$all ||61.3.149.216$all +||61.3.149.244$all ||61.3.149.253$all ||61.3.149.26$all ||61.3.149.3$all @@ -425734,6 +425913,7 @@ ||61.3.149.86$all ||61.3.149.89$all ||61.3.150.0$all +||61.3.150.101$all ||61.3.150.104$all ||61.3.150.121$all ||61.3.150.140$all @@ -425775,9 +425955,11 @@ ||61.3.151.90$all ||61.3.152.205$all ||61.3.152.26$all +||61.3.153.224$all ||61.3.154.201$all ||61.3.154.21$all ||61.3.156.130$all +||61.3.156.17$all ||61.3.18.2$all ||61.3.18.216$all ||61.3.23.66$all @@ -426741,6 +426923,7 @@ ||61.52.186.181$all ||61.52.186.184$all ||61.52.186.185$all +||61.52.186.186$all ||61.52.186.192$all ||61.52.186.195$all ||61.52.186.207$all @@ -429680,6 +429863,7 @@ ||61.52.97.57$all ||61.52.97.61$all ||61.52.97.64$all +||61.52.97.68$all ||61.52.97.69$all ||61.52.97.72$all ||61.52.97.74$all @@ -434631,7 +434815,7 @@ ||65.99.158.218$all ||65.99.176.17$all ||650x.com$all -||654tyfcdr4654fytfy.top$all +||654tyfcdr4654fytfy.top/syzsnntnps.vx$all ||65k2.com$all ||66-gifts.com$all ||66.103.9.249$all @@ -435393,7 +435577,7 @@ ||6gue98ddw4220152.freebackup.site$all ||6hffgq.dm.files.1drv.com$all ||6hu.xyz$all -||6ip.us$all +||6ip.us/$all ||6iptv.com$all ||6itokam.com$all ||6ixbling.com/wp-admin/tv9qgaxqruvcumabdu/$all @@ -437826,6 +438010,7 @@ ||80.92.189.5$all ||80.92.189.70$all ||80.92.204.14$all +||80.92.204.57$all ||80.93.182.219$all ||80.99.128.61$all ||80001.me$all @@ -439034,6 +439219,7 @@ ||85.245.162.144$all ||85.247.247.175$all ||85.25.213.151$all +||85.250.147.134$all ||85.250.36.135$all ||85.255.1.93$all ||85.26.250.86$all @@ -439211,6 +439397,7 @@ ||86.7.86.4$all ||86.82.137.79$all ||86.91.10.91$all +||86.98.23.78$all ||860259.com$all ||8650hwvaapy.realbrjuridico.email$all ||866appliance.com$all @@ -439328,6 +439515,7 @@ ||87.248.61.60$all ||87.249.204.194$all ||87.251.235.167$all +||87.251.71.78$all ||87.251.82.211$all ||87.253.0.196$all ||87.253.1.206$all @@ -439903,6 +440091,7 @@ ||89.148.233.85$all ||89.148.234.101$all ||89.148.234.165$all +||89.148.234.217$all ||89.148.234.37$all ||89.148.235.94$all ||89.148.237.100$all @@ -441337,6 +441526,7 @@ ||93.157.62.102$all ||93.157.62.171$all ||93.157.62.58$all +||93.157.63.221$all ||93.157.63.244$all ||93.159.141.165$all ||93.159.141.166$all @@ -442953,7 +443143,19 @@ ||a.doko.moe$all ||a.gg.fm$all ||a.heritageandterre.com$all -||a.pomf.cat$all +||a.pomf.cat/avhmcy.exe$all +||a.pomf.cat/gziqpm.exe$all +||a.pomf.cat/ioxyfx.dat$all +||a.pomf.cat/kiwqkn.exe$all +||a.pomf.cat/madeuz.exe$all +||a.pomf.cat/nmzemw.exe$all +||a.pomf.cat/qhsyxo.exe$all +||a.pomf.cat/qqksvz.exe$all +||a.pomf.cat/uhfhfh.pif$all +||a.pomf.cat/vmwdhb.zip$all +||a.pomf.cat/yckrnz.exe$all +||a.pomf.cat/ymfxrc.jpg$all +||a.pomf.cat/yygruz.exe$all ||a.pomf.se$all ||a.pomf.space$all ||a.pomf.su$all @@ -447845,7 +448047,8 @@ ||anmocnhien.vn$all ||anmolanwar.com$all ||ann141.net$all -||anna.websaiting.ru$all +||anna.websaiting.ru/facturas-pendientes$all +||anna.websaiting.ru/facturas-pendientes/$all ||annaaluminium.annagroup.net$all ||annabelle-hamande.be$all ||annabphotography.co.uk$all @@ -448380,7 +448583,7 @@ ||app.boxrcdn.com$all ||app.bridgeimpex.org$all ||app.calag.at$all -||app.casetabs.com/n/p7nx8575$all +||app.casetabs.com$all ||app.catholicchurch.co.in$all ||app.choiphui.com$all ||app.cloudindustry.net$all @@ -450362,7 +450565,7 @@ ||atphitech.com$all ||atpn.ir$all ||atprofessional.org$all -||atpscan.global.hornetsecurity.com/index.php?atp_str=afw-6ropadyx-4diefo4dbv3e_xmh3-ype0mhrlsyeuhwsqoeebzlbafyf6_bdljtesgdugeymxapym1fsyhxkyylpvifpr0hnjo3w92mx4bqea-rhcujbljf7xs-ie79eig5o9b_hcfg9ygyzdkrnzco-swcs_bodliaxlfflgccv-hkcqkgjzmxadbpvzglcgsaecd8rv4if7ngcqkrxprwlykmzxyjhyncp2kigw8_rjsdchhxd9niyyjjb1jovi-wm8urvrdop7bvnkrinv2g2ef433yzwetxfwlzgfnehnqbtdbrst1zv1hncyrnd3tvjwjjwn-3c5irkywidug4sagusduvudmdsm6oim1nja1ody3mwvlzdyjojoj2og-0apvymvmjggu-mi8gg/$all +||atpscan.global.hornetsecurity.com$all ||atr.it$all ||atradex.com$all ||atragon.co.uk$all @@ -451152,6 +451355,8 @@ ||awsxb.xyz$all ||awsyscloud.com$all ||awtinfostore.co.business$all +||awumad01.top$all +||awuqze02.top$all ||ax-yogado.com$all ||axalize.vn$all ||axalta.grupojenrab.mx$all @@ -452576,8 +452781,7 @@ ||bbfr.cba.pl$all ||bbgiardinodoriente.it$all ||bbgk.de$all -||bbgroup.com.vn/wp-content/32451/$all -||bbgroup.com.vn/wp-content/statement/pwc9q80/4wugo9y-3518181981-77685-cl9yz8-1dbtjnuln9i/$all +||bbgroup.com.vn$all ||bbh-design.de$all ||bbhdata.com$all ||bbhs.org.ng$all @@ -453126,7 +453330,7 @@ ||bel-med-tour.ru$all ||belabargelro.com$all ||belair.btwstudio.ch$all -||belairinternet.com$all +||belairinternet.com/wp-includes/9c8gi-fhbzv-xflschcjz/$all ||belamater.com.br$all ||belangel.by$all ||belanja-berkah.xyz$all @@ -453247,7 +453451,8 @@ ||belz-development.de$all ||belznerdesign.de$all ||bem.fkep.unpad.ac.id$all -||bem.hukum.ub.ac.id$all +||bem.hukum.ub.ac.id/vdtdcc2636944/scan/rechnungszahlung/$all +||bem.hukum.ub.ac.id/wp-content/payments/012019/$all ||bem.unimal.ac.id$all ||bemagazine.club$all ||bemakeup.ru$all @@ -454035,10 +454240,7 @@ ||bierne-les-villages.fr$all ||biese.eu$all ||bietthubien.org$all -||bietthudep902.com/rwevpv/026/kaufvertrag_026_21052020.zip$all -||bietthudep902.com/rwevpv/984295264/kaufvertrag_984295264_21052020.zip$all -||bietthudep902.com/rwevpv/kaufvertrag_098_21052020.zip$all -||bietthudep902.com/rwevpv/kaufvertrag_74788472_21052020.zip$all +||bietthudep902.com$all ||bietthulambach.com$all ||bietthulienkegamuda.net$all ||bietthumau.com$all @@ -454587,6 +454789,7 @@ ||bitbucket.org/busrakulcu/busra-kulcu/downloads/browserguncelleme.apk$all ||bitbucket.org/busrakulcu/busra-kulcu/downloads/browserguncellemesi.apk$all ||bitbucket.org/bzr-company/fortune/downloads/miner.exe$all +||bitbucket.org/clubhousedev/clubhouse/downloads/clubhousepc.exe$all ||bitbucket.org/codedevelop/sourse/downloads/az.exe$all ||bitbucket.org/conan2019/download/downloads/clipper.exe$all ||bitbucket.org/coverengineer/2020/downloads/main.exe$all @@ -458521,7 +458724,7 @@ ||callpetercatering.com$all ||callrealtyaz.com$all ||callshaal.com$all -||callsmaster.com$all +||callsmaster.com/azureink.co.uk/sec_zone/us/sign/com/open_docs/$all ||calltoprimus.ru$all ||calltorepair.com/assets/09erzff/$all ||callumstokes.com$all @@ -460357,6 +460560,7 @@ ||cdn.discordapp.com/attachments/775201330172133379/785293636388519936/dhl_receipt.img$all ||cdn.discordapp.com/attachments/775238059083038744/818196372763181116/qtuar$all ||cdn.discordapp.com/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq$all +||cdn.discordapp.com/attachments/775238059083038744/829993648186851338/pslmlyfnpzgsgitrwwvalcfunumfmac$all ||cdn.discordapp.com/attachments/775303846645334037/784920798212784158/x2.exe$all ||cdn.discordapp.com/attachments/775537284656791553/779777829800771584/androidupdate.apk$all ||cdn.discordapp.com/attachments/775587299214753796/776303350953017414/ozsl506$all @@ -460588,6 +460792,7 @@ ||cdn.discordapp.com/attachments/825372018244583454/826848185246023750/loaddd.exe$all ||cdn.discordapp.com/attachments/825372018244583454/826848348342059008/zeppelin.exe$all ||cdn.discordapp.com/attachments/825372018244583454/826848405258633277/build.exe$all +||cdn.discordapp.com/attachments/825372018244583454/830455061724528690/v1.exe$all ||cdn.discordapp.com/attachments/825686740106870837/825687235973087262/chucks5000_leiqr231.bin$all ||cdn.discordapp.com/attachments/825686740106870837/825688243248562176/tobi5000_pskkckhmf118.bin$all ||cdn.discordapp.com/attachments/825686740106870837/825982118672597042/newdoggy5000_splqq85.bin$all @@ -460666,7 +460871,7 @@ ||cdnpic.mgyun.com$all ||cdnrep.reimage.com/prot/protectorpackagerr2023.exe$all ||cdnrep.reimage.com/ver/reimagepackage1874x64b.exe$all -||cdnrep.reimageplus.com$all +||cdnrep.reimageplus.com/rqt/reimagerepair.exe$all ||cdnxh.net$all ||cdoconsult.com.br$all ||cdolechon.com$all @@ -461479,7 +461684,7 @@ ||cheematransxpressinc.com$all ||cheerchile.cl$all ||cheerfulgiversneverlack.com$all -||cheerfullydo.com$all +||cheerfullydo.com/data/nhtlrr/94046/nbar_94046_29052020.zip$all ||cheesecakery.com.br$all ||cheetahridge.mediadevstaging.com$all ||chef-solutions.dreamscape.co.in$all @@ -462439,7 +462644,7 @@ ||clarte-thailand.com$all ||clashofclansgems.nl$all ||clasificados.diaadianews.com$all -||clasificadosmaule.com/wp-content/sites/szs9n6pvn37fgafd911ss_osiby1-753587659577/$all +||clasificadosmaule.com$all ||class.britishonline.co$all ||class.snph.ir$all ||classbrain.net$all @@ -462779,8 +462984,7 @@ ||clock.noixun.com$all ||clocktowercommunications.com/wp-admin/sre9o6j/$all ||clodflarechk.com$all -||clodura.ai/wp-content/qq46l73r-xole-35619/$all -||clodura.ai/wp-content/vlfqxilre/$all +||clodura.ai$all ||clone.affordable.cm$all ||clone.system-standex.dk$all ||cloned.in$all @@ -462970,7 +463174,9 @@ ||cmecobrancas.com$all ||cmelik.com$all ||cmessagers.com$all -||cmg.asia$all +||cmg.asia/wp-content/uploads/asifb-0wxsmxdavkvdu2_okcqpxaws-nk/$all +||cmg.asia/wp-content/uploads/dok/bkmrgzxziezodqvcvwbtcqinn/$all +||cmg.asia/wp-content/uploads/inc/rvvm3ragsf/$all ||cmg.ma$all ||cmgroup.com.ua$all ||cmhighschool.edu.bd$all @@ -465606,7 +465812,7 @@ ||cuadros.pe$all ||cuahangphongthuy.net$all ||cuahangstore.com$all -||cuahangvattu.com$all +||cuahangvattu.com/cofd/closed_sector/458kmxdg6a0ywt_wum4a4kmr01g2_cloud/46311257516564_txxafmu2a/$all ||cualtis.com$all ||cuanhomxingfanhapkhau.com$all ||cuasotinhoc.net$all @@ -466048,17 +466254,7 @@ ||d.qiluwl.com$all ||d.teamworx.ph$all ||d.techmartbd.com$all -||d.top4top.io/m_18677sx8h1.mp4$all -||d.top4top.io/p_101949r3r1.jpg$all -||d.top4top.io/p_12014tn3x1.jpg$all -||d.top4top.io/p_1519dkp831.jpg$all -||d.top4top.io/p_1567m7an31.png$all -||d.top4top.io/p_1638e5yhh1.jpg$all -||d.top4top.io/p_16819gzhe1.jpg$all -||d.top4top.io/p_1681wdig21.jpg$all -||d.top4top.io/p_169387gdp1.jpg$all -||d.top4top.io/p_1978um31.jpg$all -||d.top4top.io/p_794twvdh1.jpg$all +||d.top4top.io$all ||d.top4top.net$all ||d.ttr3p.com$all ||d04.data39.helldata.com$all @@ -468151,11 +468347,7 @@ ||deposayim.ml$all ||depositoclara.com.br$all ||depot7.com$all -||depozituldegeneratoare.ro/jgipmpwb0g$all -||depozituldegeneratoare.ro/jgipmpwb0g/$all -||depozituldegeneratoare.ro/open-invoices/$all -||depozituldegeneratoare.ro/past-due-invoices/$all -||depozituldegeneratoare.ro/telekom/rechnung/112018/$all +||depozituldegeneratoare.ro$all ||depraetere.net$all ||deprealty.ru$all ||depressionted.com$all @@ -469972,7 +470164,8 @@ ||dl-675423.store-downloads.com$all ||dl-80076342.md-downloads.com$all ||dl-97674424.md-downloads.com$all -||dl-gameplayer.dmm.com$all +||dl-gameplayer.dmm.com/product/apkggame/giga_baldrbringerextendcode/giga_baldrbringerextendcode/win/src/content/data/data/uninstall.exe$all +||dl-gameplayer.dmm.com/product/apkggame/nel_narikiri/nel_narikiri/win/src/content/data/%e3%81%aa%e3%82%8a%e3%81%8d%e3%82%8a%e3%83%90%e3%82%ab%e3%83%83%e3%83%97%e3%83%ab%ef%bc%81.exe$all ||dl-link.link$all ||dl-link.live$all ||dl-link.network$all @@ -470292,9 +470485,10 @@ ||dl.imht.ir$all ||dl.installcdn-aws.com$all ||dl.mqego.com$all -||dl.mydown.com$all +||dl.mydown.com/download/be5abe2da15f5d91d4f29cbf80d5d581/509451398_6/newsoft/tsbrowser_724_4.0.7.20.exe$all ||dl.ossdown.fun$all ||dl.packetstormsecurity.net$all +||dl.pandasecur.com$all ||dl.popupgrade.com$all ||dl.repairlabshost.com$all ||dl.rina-roleplay.com$all @@ -470815,8 +471009,7 @@ ||doc-0s-68-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/q5qe5q1uvep35ccrbr1g80sub349agop/1543320000000/05984462313861663074/*/19esasjydhkmq-f80tgnobrth0yudmgzy$all ||doc-0s-68-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/stiolst1g6i8vasis6jegpqd2b04imod/1543327200000/05984462313861663074/*/19esasjydhkmq-f80tgnobrth0yudmgzy$all ||doc-0s-70-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/6i0lbore8mloquf0s0inmqhshir3jrs8/1542996000000/08141031105246785918/*/1frfmibmbtnbemiolrz9aktbpn7jsr6sr?e=download$all -||doc-0s-7c-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/5bvsb5ttjjkmftcv00posgt0a2lsq6pq/1579680000000/03683026262266078671/*/16rew7icapzdfonn9ubjb-owowh_uiuk5?e=download$all -||doc-0s-7c-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/ml48mc3h16rmkppielv4ukafil7iun3f/1580112000000/11177655664072506190/*/1nybpfnssg325879zor4tfv-8jgmxnlj2?e=download$all +||doc-0s-7c-docs.googleusercontent.com$all ||doc-0s-80-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/nc8mtg3folbcd5haj9bc709btbqsqnoh/1578895200000/09593966995115687919/*/1k8z46ungjn3fizc5ih1syhdji3zbao1w?e=download$all ||doc-0s-8c-docs.googleusercontent.com/docs/securesc/4jc3o0kkf5136n14s0obie5i3338237o/crl1nl7rrivhhkpl1l4rck0f9km8v2t5/1579795200000/11177655664072506190/09384270791473589425/1m-hgvq0i-3aqo0w0pgga_sqanki6ahj3?e=download&authuser=0&nonce=3jhgojl8vukmm&user=09384270791473589425&hash=qa8cgr1tgr33cqmmn859u2qkmrrbrk5m$all ||doc-0s-8s-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/8ne944b43812vrcuv9954p7n8r2suam3/1547575200000/07335649321361492730/*/1dypty3z5gun_lf52eicq3h2hezuqwpkq?e=download$all @@ -470831,8 +471024,7 @@ ||doc-0s-bs-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/ene3b5nenits168gjf4lnni1kuie3jnr/1552039200000/11569688848916399575/*/1hgnjd29qwsmeort3zpfpwxxm8fdd3ygq?e=download$all ||doc-0s-c8-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/4b7n6eqfl7n5boc61bjf0q7b5mksc6lp/1555516800000/16964281332718813838/*/1qerkwklbb2tcmxsqrvylgwn7viz4xhhy$all ||doc-0s-c8-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/uumujnqdoksb2iq336es2fnlcgjkfjop/1601921475000/08069565659861269988/*/1hqi4mjve0ifpo5vwi0okysf2eakt1ljz$all -||doc-10-0c-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/gc8dsf1456d9gmibfmg7o25gs6ectrmo/1551816000000/14063452590226117103/*/1_jo_vxwckb1cbttkzgd7nmqezfuujvhb?e=download$all -||doc-10-0c-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/nhbo71cjafudtbkd3ls3bismqvuj8ig6/1549828800000/14063452590226117103/*/1_jo_vxwckb1cbttkzgd7nmqezfuujvhb?e=download$all +||doc-10-0c-docs.googleusercontent.com$all ||doc-10-28-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/r5fjotq4qok8a7pk9sain44inha7ocft/1580104800000/13535128519197762172/*/1topkmo_eawlxskmpgmjbhsgrjusoj8kc?e=download$all ||doc-10-34-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/hgrdjpkp37sdv3rd3miim43hdd84tv71/1580364000000/06792381463910506630/*/1yrlvbuhbbtzusz9amngr4c6_x7i0db6u?e=download$all ||doc-10-44-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/sg56hqhomngdvphgv21g37ft31vqvjql/1581605100000/08658714528148673336/*/1jzbbjgpebq0xdke_vvydr_dmxwsxuef4?e=download$all @@ -470850,7 +471042,7 @@ ||doc-10-88-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/gs4tf9lgm5e90i6qvfvo78fvi78b2ba7/1579701600000/01423698199670842299/*/1fpnbcmqkjsh5dp_kwvkbusccnzjezbyo?e=download$all ||doc-10-8g-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/bkavgvoa0anttjt05vct2lecdjdofugu/1552564800000/10901782374314873973/*/1os_ldyiqmoy8rhs0ylu3odlgfmf7cdk0$all ||doc-10-8o-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/djvcoprs7ik42sgsnpcn1rhauljdcper/1579586400000/10077574138565375691/*/1zcfkyuetnb51zhkvmx3hm3r7xb2himqu?e=download$all -||doc-10-8s-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/r4rrt36iqlpu59et4hbr6bdvscb5lcno/1547150400000/07335649321361492730/*/1k4wwzw-ai239shkc3qbksuv4rpimdmio?e=download$all +||doc-10-8s-docs.googleusercontent.com$all ||doc-10-98-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/8h1v715bmm41gaeni9q0ca6vqpfptos9/1580104800000/03594737999780208267/*/1csdtiyql0cldrstrazrnftmoubtfzwkk?e=download$all ||doc-10-98-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/99uiri3hlipm4tt7mrai16mbv23797h2/1579003200000/03594737999780208267/*/17eycga79cao3bkde5ov9lh7j_sz1iv-l?e=download$all ||doc-10-98-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/dvfn4tg87qm827b127b5ibb5uo3k8god/1579939200000/03594737999780208267/*/1sd3mqdidoetuy3tmzwujjx2s9kbv6zra?e=download$all @@ -475759,6 +475951,7 @@ ||drive.google.com/uc?export=download&id=1dyhilkcw_idrwtoquewgui5bz3eounv5$all ||drive.google.com/uc?export=download&id=1dz8-iw3l5e1shc2unot8s6v5bweh5n3j$all ||drive.google.com/uc?export=download&id=1dzw-mtd4b5a3jvccvvkdcjsd-bsoqst0$all +||drive.google.com/uc?export=download&id=1dzx_cflers_zntlrip3fhbxb5who03u0$all ||drive.google.com/uc?export=download&id=1e-5ug_mz0zphngg9huvc1mzpx4_qfaw7$all ||drive.google.com/uc?export=download&id=1e-eglblcxhjqkum_hk8mvkg1-p3uvh8n$all ||drive.google.com/uc?export=download&id=1e-gyqr_ugzsyy31zw40u-cprrw15-_tw$all @@ -478035,6 +478228,7 @@ ||drive.google.com/uc?export=download&id=1xbdlhwd5vdtco07vt5-ac0u37e-nycgg$all ||drive.google.com/uc?export=download&id=1xbeqbw67xz4iqpu8dgmdrlkpa6kzotes$all ||drive.google.com/uc?export=download&id=1xbfd2msdcw6hm2swjxtogmijoiuefkqe$all +||drive.google.com/uc?export=download&id=1xbp7hvw2ybwjrftbvdkjvwzrfuk4ope9$all ||drive.google.com/uc?export=download&id=1xbwjfdd21zot8vazb0egqi5kuzw90t7o$all ||drive.google.com/uc?export=download&id=1xc1vhtuzdeuqp-hkpnrix8ursqwurrel$all ||drive.google.com/uc?export=download&id=1xc5botlfmsw23xotatnddimh8r-btiv7$all @@ -489095,7 +489289,7 @@ ||ec2-54-207-92-161.sa-east-1.compute.amazonaws.com$all ||ec2-54-212-231-68.us-west-2.compute.amazonaws.com$all ||ec2-54-94-215-87.sa-east-1.compute.amazonaws.com$all -||ec2euc1.boxcloud.com/d/1/a1!1v6vibwx7vlie5y8jj5xm5ipoc9jdxze8ck08lu22jdqvqu0y23hledgazmxqbcukhlgg95jbfv9p6e7n10-td4omxyxferhngbpik8idewoo81utbhmygy4yzt8uxvxi_dnrwzvwtlndrqwk6hotxffg8jkpj8-j3bybrd7yw7n9nyzemoqeelvbjthue6wa3yuozggyesvvg1o6919_nqqhatm_0mampn9-_jtxf4s-ugi1s9il7i1vz-euwgqoqgfey5ojdw8thvvonrqk07jcvnmdwqnxx73l0zvlypuue7zjxsucd5ngxrgnlrokmgqml3gqmvtclnbzspt-4hcnbybe8gfkg2psuvv1aq_omqri7_jbjnodn0k3rmscvbihzzjag_jacj95hxys2nqu5-avfi3mcsbykrgcfcd0f0ubmxy8_u-adp_am2uyu7wjbtlhrmdeya-wvab9_d_rsbzn6qhbobnfb-ijabnqe8ynoztvmmj5-48vxc-gimyw84qv5vvoewlfuazz6lhawnqlsehdoko20t5tsgdq-ixnr9upyrvqgkqg9hpkx37rcfrizch7msfmqqhgbz-2kepa7cuisq2u8z21psh44kaslvzjjckzbjxaazonnqpicscjypbbx8vqrtok7qhix5gnjmofxjghi8dnzcdrvrzwwf9qowdqzmqle38iykwpk_43qarzcyv53ecglsevfziyq5bqgscnvlv9ypi3dlnhklmijhb_-nal1ma_y7hazsqeqks-c-_2pporvy4fabaa7ppnt7cji5vsu1jcfdqk3xg_voorzho8qzmelylrsddbg1k4rbzk7hhqwn_sbr0owykfhvovjqzq1lssanl7n3sjbh_adgrgglq2ojvyqsklvlnet4-3dr8qnksaaphkhmfzaggxffhkiuks7n6dth09683x8t1ape47jo8a3du24wyvolahwxr0i91czhb9fphq2_qbhc66ww4pynr2kvclrajdii50jao1znpe0nbdtqdqc9c4dladdwtrfnh-1lywnfvm1szr-fky7qtf9ysdut3htypftcw-zwftt5yxvxpff6-xxcd599rg8fr2-inwced5f8d3vc_lu3sy9p_-mfnsp_urjy0f9rcy3lnsgb_$all +||ec2euc1.boxcloud.com$all ||ec2test.ga$all ||ec3-design.com$all ||ecadigital.com$all @@ -491452,6 +491646,7 @@ ||esaarc.com$all ||esacbd.com$all ||esagarautomobiles.com$all +||esaja09.top$all ||esanjobs.org$all ||esar.weenets.com$all ||esascom.com$all @@ -497631,7 +497826,7 @@ ||genrjw.dm.files.1drv.com$all ||genstaff.gov.kg$all ||gentcreativa.com$all -||gentecoyol.com$all +||gentecoyol.com/riot-vanguard/hb/$all ||gentesanluis.com$all ||gentiane-salers.com$all ||gentlechirocenter.com$all @@ -500592,8 +500787,7 @@ ||gvpcdpgc.edu.in$all ||gvpmacademy.co.za$all ||gvsme.com$all -||gw.daelimcloud.com/website/mail/attachedfile/largefiledownload.aspx?key=mjqtuleptqynziynzymrkleptc0mjcyntmmvfjdsz1zjk1ot1rjpu4%3d$all -||gw.daelimcloud.com/website/mail/attachedfile/largefiledownload.aspx?key=odgtuleptq0mjgzntqmrkleptc2otc4mtimvfjdsz1zjk1ot1rjpu4%3d$all +||gw.daelimcloud.com$all ||gw.hitlin.com$all ||gwangjuhotels.kr$all ||gwavellc.com$all @@ -503505,7 +503699,20 @@ ||hotelwaldblick.com$all ||hotexpress.co$all ||hotfacts.org$all -||hotgifts.online$all +||hotgifts.online/1291994a7f3a5816fb62a8f825076dfb/winboxscan.exe$all +||hotgifts.online/1da70a31e6545d7c5611b2410a4dc351/updateprofile.exe$all +||hotgifts.online/616127c527f57b3aff6bbbf3e00c48d7/winboxscan.exe$all +||hotgifts.online/6ab91d75132f7aa1085b1cea8df09d05/winboxscan.exe$all +||hotgifts.online/71eb063309e71fb131b8fec3804e8ce9/updateprofile.exe$all +||hotgifts.online/73a5c1a5cb2a3c4095bad22fd413d98e/winboxscan.exe$all +||hotgifts.online/9050b32a16e63abe28c544048fdebafc/winboxscan.exe$all +||hotgifts.online/9db8ff1707781393a2f8f4843028bf62/updateprofile.exe$all +||hotgifts.online/a7b6d8f0cc006e65b9f5707c817a8523/winboxscan.exe$all +||hotgifts.online/app/app.exe$all +||hotgifts.online/app/app171.exe$all +||hotgifts.online/app/e7.exe$all +||hotgifts.online/app/watchdog.exe$all +||hotgifts.online/bc751a3f103b5151e09550385e5e50d3/updateprofile.exe$all ||hotilife.com$all ||hotissue.xyz$all ||hotkine.com$all @@ -503895,7 +504102,8 @@ ||hukuen-motokare.xyz$all ||hukuki.site$all ||hukukportal.com$all -||hukum.ub.ac.id$all +||hukum.ub.ac.id/order/document.zip?0774181353[document_pdf________________________________________________________________%20.exe]$all +||hukum.ub.ac.id/order/document.zip?0774181353[document_pdf________________________________________________________________+.exe%5d$all ||hukum.unwiku.ac.id$all ||hulianwang114.com$all ||huliot.in$all @@ -504225,7 +504433,7 @@ ||i.cubeupload.com/euev6n.jpg$all ||i.cubeupload.com/ez3vpt.jpg$all ||i.cubeupload.com/gmetap.jpg$all -||i.fiery.me/5vdk.png$all +||i.fiery.me$all ||i.fluffy.cc$all ||i.funtourspt.eu$all ||i.imgur.com/3zblzb6.png$all @@ -507651,6 +507859,7 @@ ||itspsc.com.ua$all ||itspueh.nl$all ||itsquare.yrcreations.com$all +||itsrlytry.000webhostapp.com$all ||itssprout.com$all ||itstelecom.com.br$all ||itsweezle.com$all @@ -507853,7 +508062,7 @@ ||j-stage.jp$all ||j-toputvoutfitters.com$all ||j.kyryl.ru$all -||j.top4top.io/p_14674n4b11.jpg$all +||j.top4top.io$all ||j11g9xecuxe43xu.xyz$all ||j12z7407gwtzk.xyz$all ||j13.biz$all @@ -507989,6 +508198,7 @@ ||jaipurweddingphotography.com$all ||jairathsnatural.ca$all ||jairozapata.000webhostapp.com$all +||jaishomo.info$all ||jaishritours.com$all ||jaiswalsupplement.com$all ||jajadomains.com$all @@ -512119,7 +512329,7 @@ ||kodim0112sabang.com$all ||kodingeko.com$all ||kodip.nfile.net$all -||kodjdsjsdjf.tk$all +||kodjdsjsdjf.tk/mine.exe$all ||kodlacan.site$all ||kodmuje.com$all ||kodolios.000webhostapp.com$all @@ -514923,10 +515133,7 @@ ||library.cifor.org$all ||library.dhl-xom.com$all ||library.iainbengkulu.ac.id$all -||library.mju.ac.th/2018/cfjdes/$all -||library.mju.ac.th/2018/mnnw0cr-ptv5a-370268/$all -||library.mju.ac.th/2018/rn-72c-0657/$all -||library.mju.ac.th/2018/zoipdun1a0/$all +||library.mju.ac.th$all ||library.phibi.my.id$all ||library.piet.co.in$all ||library.strophicmusic.com$all @@ -515634,7 +515841,7 @@ ||livecigarevent.com$all ||livecricketscorecard.info$all ||livedaynews.com$all -||livedemo00.template-help.com$all +||livedemo00.template-help.com/28736_site/hoeflertext.font.com$all ||livedownload.in$all ||livedrumtracks.com$all ||livefarma.com$all @@ -515669,7 +515876,7 @@ ||livestreams.vn$all ||livesuitesapartdaire.com$all ||livesurgerycourse.ir$all -||liveswinburneeduau-my.sharepoint.com$all +||liveswinburneeduau-my.sharepoint.com/:u:/g/personal/101937439_student_swin_edu_au/eqsmp3lwkfzfr0zegn-tkiqb6agjne8t4rqyjhktmzur6w?e=zl6yl7&download=1$all ||liveswindow.casa$all ||liveswindow.cyou$all ||liveswindows.bar$all @@ -516868,7 +517075,8 @@ ||luzconsulting.com.br$all ||luzevida.com.br$all ||luzfloral.com$all -||luzy.vn$all +||luzy.vn/wp-admin/protected-box/5n0ddpmuc-eqlu1o1befow-wzj8lfwj-9ega3umab/795789-ppeclz1q1bf/christmas_card/$all +||luzy.vn/wp-content/etrac/p7d8lzxe7p/r8d492343724021xd3b2760u727yqdsbnpw5r/$all ||luzzeri.com$all ||lvajnczdy.cf$all ||lvcfund.org.vn$all @@ -520025,7 +520233,7 @@ ||mecgwl.ac.in$all ||mechanicaltools.club$all ||mechanicsthatcometoyou.com$all -||mecharnise.ir$all +||mecharnise.ir/ca3/fre.php$all ||mechathrones.com$all ||mechauto.co.za$all ||mechdesign.com$all @@ -520753,7 +520961,7 @@ ||menziesadvisory-my.sharepoint.com$all ||menzway.com$all ||meogiambeo.com$all -||meohaybotui.com$all +||meohaybotui.com/qitjgi/$all ||meolamdephay.com$all ||mepsgen.com$all ||mera.ddns.net$all @@ -521075,9 +521283,7 @@ ||mfomjr.com$all ||mfotovideo.ro$all ||mfpburundi.bi$all -||mfpc.org.my//wp-content/plugins/formcraft3/stub2_encrypted_ba9409f.bin$all -||mfpc.org.my/wp-admin/images/stb_encrypted_5b6e930.bin$all -||mfpc.org.my/wp-admin/meta/stb_encrypted_a322e7f.bin$all +||mfpc.org.my$all ||mfppanel.xyz$all ||mfpvision.com$all ||mfronza.com.br$all @@ -526298,7 +526504,7 @@ ||nhadatquan2.xyz$all ||nhadatthienthoi.com$all ||nhadephungyen.com$all -||nhadepkientruc.net$all +||nhadepkientruc.net/wp-content/ogi3nl90/$all ||nhahangdaihung.com$all ||nhahanghaivuong.vn$all ||nhahanglegiang.vn$all @@ -526523,7 +526729,8 @@ ||nikanpolimer.ir$all ||nikastroi.ru$all ||nikavkuchyni.sk$all -||nikayu.com$all +||nikayu.com/mpvjl0awc9zkv$all +||nikayu.com/mpvjl0awc9zkv/$all ||nikbox.ru$all ||nikeshyadav.com$all ||nikhil.webscript.co.in$all @@ -531785,7 +531992,7 @@ ||option47.us$all ||optioncapitalgroup.ru$all ||optionrp.com$all -||optionscity.com$all +||optionscity.com/wp-content/wptouch-data/debug/safebrowsing.exe$all ||optisaving.com$all ||optitechsa.co.za$all ||optocen.ru$all @@ -532096,7 +532303,7 @@ ||osheoufhusheoghuesd.ru/m.exe$all ||osheoufhusheoghuesd.ru/o.exe$all ||osheoufhusheoghuesd.ru/t.exe$all -||oshi.at$all +||oshi.at/qbpahk/$all ||oshiscafe.com/wp-admin/5dm/$all ||oshodrycleaning.com$all ||oshonafitness.com$all @@ -541948,7 +542155,68 @@ ||posmicrosystems.com$all ||posnxqmp.ru$all ||pospeeps.com$all -||posqit.net$all +||posqit.net/0/56021017.exe$all +||posqit.net/0/5911097.exe$all +||posqit.net/0/6013277.exe$all +||posqit.net/0/6502301.exe$all +||posqit.net/0/80177.exe$all +||posqit.net/00/6508908.exe$all +||posqit.net/8t/4460139.exe$all +||posqit.net/8t/50173309.exe$all +||posqit.net/b/5003037.exe$all +||posqit.net/b/9051077.jpg$all +||posqit.net/ctw/1011.hta$all +||posqit.net/ctw/2055970$all +||posqit.net/ctw/96053407$all +||posqit.net/ctw/96053407.hta$all +||posqit.net/ctw/9908793$all +||posqit.net/ctw/scan091019$all +||posqit.net/f1/scan-document-shipment-info$all +||posqit.net/f1/scan-document-shipment-info.hta$all +||posqit.net/ge/20610444.jpg$all +||posqit.net/ge/206440.exe$all +||posqit.net/ge/4509700.exe$all +||posqit.net/ge/50010378.jpg$all +||posqit.net/ge/5013447.exe$all +||posqit.net/iy/5607087.exe$all +||posqit.net/pe/0362035.exe$all +||posqit.net/pe/0578102.exe$all +||posqit.net/pe/08437.exe$all +||posqit.net/pe/0955576.exe$all +||posqit.net/pe/1050700.exe$all +||posqit.net/pe/1101708.exe$all +||posqit.net/pe/11045830.exe$all +||posqit.net/pe/1106778.exe$all +||posqit.net/pe/2117636.exe$all +||posqit.net/pe/60380.exe$all +||posqit.net/pe/60589.exe$all +||posqit.net/pe/myfile5.exe$all +||posqit.net/pe/scan-05458.exe$all +||posqit.net/qq/05700301.exe$all +||posqit.net/qq/0621777.exe$all +||posqit.net/qq/0629107.exe$all +||posqit.net/qq/1035661.exe$all +||posqit.net/qq/7800132.exe$all +||posqit.net/qq/78045109.exe$all +||posqit.net/tt/440789.exe$all +||posqit.net/tt/741003.exe$all +||posqit.net/tt/850135.exe$all +||posqit.net/tt/89051102.exe$all +||posqit.net/tt/90461777.exe$all +||posqit.net/ty/20601907.jpg$all +||posqit.net/vcv/120131078.exe$all +||posqit.net/vcv/2031078.exe$all +||posqit.net/vcv/306517.exe$all +||posqit.net/w/03305177$all +||posqit.net/w/6006077.exe$all +||posqit.net/w/9078950$all +||posqit.net/w/9078950.hta$all +||posqit.net/xl/08971130$all +||posqit.net/xl/2013544$all +||posqit.net/xl/50333087$all +||posqit.net/xl/6090970$all +||posqit.net/xl/6090970.hta$all +||posqit.net/xl/new%20order.exe$all ||possessionnow.com$all ||possible.re$all ||possopagar.com.br$all @@ -542599,7 +542867,14 @@ ||prisidmart.com$all ||priskat.net$all ||prism-photo.com$all -||prisma.fp.ub.ac.id$all +||prisma.fp.ub.ac.id/wp-content/amazon/en/information/012019/$all +||prisma.fp.ub.ac.id/wp-content/orders_details/012019/$all +||prisma.fp.ub.ac.id/wp-content/plugins/hpcrs-sdpvl_nr-tk/inv/70971forpo/264773867145/us_us/open-past-due-orders/$all +||prisma.fp.ub.ac.id/wp-content/us_us/info/copy_invoice/wzddw-n2xu_ngxm-z41/$all +||prisma.fp.ub.ac.id/wp-content/us_us/xerox/invoice_number/fhbq-zwqr_um-fg/$all +||prisma.fp.ub.ac.id/wp-content/xerox/midy-2g_ftbtdf-2yo/$all +||prisma.fp.ub.ac.id/wp-content/xldld_li-wbbm/xt/attachments/02_19$all +||prisma.fp.ub.ac.id/wp-content/xldld_li-wbbm/xt/attachments/02_19/$all ||prismaxis.com$all ||prismfox.com$all ||prismware.ml$all @@ -543214,9 +543489,7 @@ ||protect-us.mimecast.com/s/7ihcc82oqycqx96qh15qw5$all ||protect-us.mimecast.com/s/c27ac0rx9ru80p3fw0bgj$all ||protect-us.mimecast.com/s/qki9c73wxjupxq5ps8qcm_$all -||protect.mimecast-offshore.com/s/ip17cn9blzfnq4n4h4tudd?domain=meraqsa.com/$all -||protect.mimecast-offshore.com/s/loqwcg5rvpcjndxqc76apn?domain=ronakfence.ir/$all -||protect.mimecast-offshore.com/s/rd0zcjqxyvf8w6o3igppxq?domain=ronakfence.ir/$all +||protect.mimecast-offshore.com$all ||protect2.fireeye.com/v1/url?k=59eacb3c-0560e9d5-59ed97de-0cc47ad93e2e-0f5e34e79adab692&q=1&e=e7991bbc-cc93-4814-a8f2-fd6d6950b0d5&u=https%3a%2f%2fwww.mediafire.com%2ffile%2fs2uyxs8t8kbuyye%2fdocumentos_de_env%25cdo.7z%2ffile$all ||protect2.fireeye.com/v1/url?k=6d0c09d2-33bdd2b2-6d0f7943-86e2237f51fb-ab55eb53c2dfee1f&q=1&e=358c9b57-d351-4b0f-80cf-d0755ec21127&u=https://pottershousedurban.co.za/cgi-bin/file/xzbx0cb5wywuw5/179vj6b9dpsp7advozp/$all ||protectiadatelor.biz$all @@ -543303,7 +543576,7 @@ ||proxy-ipv4.com$all ||proxy.2u0apcm6ylhdy7s.com$all ||proxy.hueaudio.com$all -||proxy.qualtrics.com/proxy/?url=https%3a%2f%2fuark.qualtrics.com%2fcp%2ffile.php%3ff%3df_0imyt11iuwaovez&token=vazkfd%2bfsrcuyx5fyunax24zxgk5dxrgqszm%2bpoz8fw%3d$all +||proxy.qualtrics.com$all ||proxygrnd.xyz$all ||proxyholding.com$all ||proxyresume.com$all @@ -544801,7 +545074,6 @@ ||r100.youth.tc.edu.tw$all ||r10instagram.com$all ||r10ticaret.xyz$all -||r20.rs6.net/tn.jsp?f=001jyht2t3omeetiei35oqstjgs_9nzk9sjylnhtbb0ao4bhans77uolbdrrwaaelcy_xfpwz_v9kt7buybu0v7bxkhuwlnsftzi2_8ddimoio4s1lnjpwd3da7cbyogtmhkf5obn3ysllinftl_gcxaufwxn0bz8fxjf4yvhjb-3gtb-da07vpp0qazekjwo7a9udmhkol3peul1z7wczztkps5tadshty&c=sda7vzhezlmymcpvzhysvdoo2nf8acki9xwyb_wfzgl7nntihduz-a==&ch=hl2va1psqpoi_ueanwygza8msuiyrkcqkgylcfuiihszmkx0z2mngg==$all ||r22lm.siaraya.com$all ||r257.com.br$all ||r2consulting.net$all @@ -546023,6 +546295,7 @@ ||redlogisticsmaroc.com$all ||redloop.io$all ||redlotusevents.com$all +||redm1az1.000webhostapp.com$all ||redmag.by$all ||redmanns-way.com/jeff-intervention-txqikkf/engines/$all ||redmarcial.ossmarcial.com$all @@ -547229,6 +547502,7 @@ ||rkcable.co.in$all ||rkfplumbing.co.uk$all ||rkinstitute.org$all +||rkkrstdygorgiousejbg.dns.army$all ||rkkrstdygorgiousejds.dns.army$all ||rkkrstdygorgiousejtw.dns.army$all ||rklkpgcollege.com$all @@ -547800,6 +548074,7 @@ ||rotoblast.org$all ||rotor.olsztyn.pl$all ||rotoscoop.com$all +||rotronics.com.ph$all ||rott-mtr.de$all ||rotterdammeetings.nl$all ||rotulosalarcon.com$all @@ -548223,7 +548498,7 @@ ||runmureed.com$all ||runmyweb.com$all ||runnected.kaiman.fr$all -||runnerbd.com$all +||runnerbd.com/newsletter/en/new-order-upcoming/hri-monthly-invoice/$all ||runnerschool.com$all ||running-bike.com$all ||runningcrewteam.com$all @@ -549987,7 +550262,7 @@ ||savemyfile.3utilities.com$all ||savemyseatnow.com$all ||saveraahealthcare.com$all -||saveserpnow.com/install6.exe$all +||saveserpnow.com$all ||saveserpresults.com$all ||savestudio.com$all ||savetax.idfcmf.com$all @@ -550710,6 +550985,7 @@ ||secure-web.cisco.com/12p009aocmii6iiuifqwgjpcu-ewgqlh2h4pycujvqyyjdohuhrgob5qmrolhcqr9n-pbdoznxvkopqofjrmcqy3gfwuj1ncre4meocugzr7ugdrxzjszl0b6pteou6fmdsru5wkh-qxded6wnpabjahxl4f4s_3tsq2grwblnjvljmbcbd5ibddpp1gnqsn5l1mih_hvf4bu54lqudh2japy0nxrdq1uwbhxrm0quhdebucbhdpo1ljxudy-27k2q5k9ou2n4l-gx4yemlbzmlofuz1df6nbqrlicsbpu5jr3dopul0acmfrbb-81lmomroc3fvvoa3bqpqdbxh3dlilolz7d7rwdozhmj8t31iid32byxqvsz2a94jsdhh9fcmb14cbi_w87ulqbgiouomra-9jqitmh1qeskzybv_i2rqadqpqkxnkmuuonvujbyhea8h3hgsc1nzsjrklwbziejw9rgppqghinmhxxky-5zzws52dx_-dphrfzlneslgrotnwhduh6y2w9dyrkw/http%3a%2f%2fsunkids.dp.ua%2fwp-admin%2fsecure.accs.docs.com%2f/$all ||secure-web.cisco.com/1vypgccgybkpf1prxej5fch8svg1xkv3nb66tqfrxc7b-vvmo2x8ynyl6ve6p1hwliztoeqwvhtiuwhztww5t2lr5vpbiq1dn3u1vjqp1tvxya02acmwwop-on54zcaz5navelmk7-v6zttoqfoxvtwlgki6y4fhgvtvhyxpbb4yl3cdoqq_ls0op2xlollina9lzbkmsf3qnomb7u7fet03ntqq9zachjl14--vqb16lmwxgany-cfcl8fdbak2uatzcnrcfkqjdw4xsdlqlvdf0lf747nwb76rt0f6h-mkxb3vfytjqjqqlhkgpyt0ekwkujzekgwjspvmakcm-pq/https%3a%2f%2fwww.dropbox.com%2fs%2fm02dp4122ei0p50%2fcertificate%25208205.doc%3fdl%3d1/$all ||secure.accounts.resourses.com$all +||secure.activedirect.xyz$all ||secure.anchorssb.co$all ||secure.app-amazon.com.recovery-account.amazon.com.alphatravelmongolia.com$all ||secure.bodybuilderabs.net$all @@ -551439,7 +551715,7 @@ ||service.dawat.fr$all ||service.drnjithendran.com$all ||service.eftformotherissues.com$all -||service.ezsoftwareupdater.com$all +||service.ezsoftwareupdater.com/updates/2/whsetup.exe$all ||service.heritageimagingcenter.com$all ||service.hybridhomesteam.com$all ||service.idealfurnitureoutlet.com$all @@ -551955,13 +552231,7 @@ ||sharebook.tk$all ||sharechautari.com$all ||shared-cnd.com$all -||shared.outlook.inky.com/link?domain=laminingraphics.co.za/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdkf9pwjauxb9ln5hjbon4qkunbsodf5yts8jdeqgdvr1pn8aav7vfxbdfzz3n3f_of2srsak2zntlwfty7ihqqgpyjyntojwg2xgp2mgpyfajzddjcwgjbak6tqgmvbpdv2oohekx6btusc6gijnte3tjiioihr4zzq4wjljvv3vfqxgdjzcgwqwicg2hkqlqsdz8lbtsirq7jscmbypadgxnsxdzoqrznkesheikdj2tei1o6zaddmw67fk35d7bpbgki1ks12wcy6b_qsrlnpipxcwku3a7nl4m-hp2xtshey9fkfpvmqdzzh3q_gbip4dh_vxw4eupo-4f48u08_n6cqmynuo7qwkldycerecc25x00_qjjwg8tp7p-rvs9w8veomv.meucihnyythleerey63ykklm6wi3yajo85mjvegtysle7fhbaieanqqjbjnskm2wmbtocdroz8yldff_ab3ipunej1yo3qo/$all -||shared.outlook.inky.com/link?domain=laminingraphics.co.za/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxtue1rwkaq_s97tgyvdwykwkykxvwkqwlcqkab0wzc2ytdjdau_veupzaehuhn-5j3xrwcyzkf7cg1aihneqinfmagtgqhroni4rguxqfdf0dgzuikps1banhya2nuezuldkvdnntx-h_pjfdilxotdyugcjr31l7iqftjyf3vsiciulypuhqkcdaxiirau7dvlnsdugpmkopgdgov6nvgputdmcfvzem0ztmzzelicvj19jrrin2ynvwxfljxu1xefldczep9jafy5e8vbtao_d5z635t8wqx5x1048vfelvkpvkqjp48eafdhfms85sptslervvitzhhy-zg6-eo16fh-3cwzqejpdpawrq01ufsupyhvxpqcp63399svn8akcagug.meucie6d9mxuzck5v8rhoqlm3oksbgukynxeilyxhhowpoq2aieagl_05exfu06imv0cnpgztc9get1eg-yy5b42-7fmdhm//$all -||shared.outlook.inky.com/link?domain=www.toziba.ir&t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdkn1ugkauhn9lry0ekk31svpn2wherrfcqg6wyq67omsiqtn373lvpjdfmmdmznwjiygtas3qgvrq5bg-amec5iamifqsiwoymh2anxicsnjjkd1ukpap93mohgmivdlr4y9aow5qkew5msv6onddp8l6iblorcg830hbszxowukuwx7hircdvex4iw2v-9xdf2xpnxzemw-71orev5b-fs2qlrejkqxaifogr1ilgkrmgb5z1kahtepwiuehwxloalr5ustmro3ng8tpzxxcu8y4xzizlrnw10poluvuxbpn1hldlr0nuehsdxjtx4wvu8npimwvgr--ws51b17aqp8yvxnugfza6b1gzszpyh4_brbi8bhackuhcnootvsiqypdyv5_wy2vofr5bwmpgle.meuciqdwg66mmqf8atpdht-lpyuss3dbd_soh1bljxzzbxwc1aigv1wkcnavv4nw3os570ta3z-muscagqqnti3dgc9p6js/$all -||shared.outlook.inky.com/link?domain=www.toziba.ir&t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxduf1vgjau_s99dqa4t-mtbcbortbrpqqhireoqmmllilisv--8rrkj-fm3pp1jrqbxuzogu6lajgr-gscydidneklueqkyghxataqeskap0d1icdpx5-xhepmyfztb4u_1er9gwqlls0inmoz6zpd1y8ybaougl6eioelie1pd1fvuhzk2mfxau_wb173mbp_9kvnloytl6c1ida15m5hc9eynkkqkaruwsinajexjjmyy87akjxrhm55fe5yxhmndvmrtoiww3ewve8cwlmrcpelfi7smoghdistd2_pyu4jwk0iz-ncvdrjbzn2vt13vv4de76-4cqhacp8i-kpt7tl7cfos3vxc_otje5d44bihawljjdnkjsnzktprjwzkcv_2xpzzdhpl9e5g6k.meucigd6xwariut2lkiettiajcosxyluv7ub6nhbepewswmwaiea4mzpunjaca7lslweyqnda4gpvqjwhufuenzur1jmp64/$all -||shared.outlook.inky.com/link?domain=www.toziba.ir&t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdunfugkaq_jd7tqby28qtte2siucq4akhiquccnh36heusom_93hq0odndjazm7p7jrqbtgtkoxmvihjsn4atsxnae0sfiliaq_yjwemmigieajwaghr4flxxomyqraaocn-olxohlupdgzsxe7prokpvd5qbqawg1wcoobwjkz3ufhzxrsqdhoeov97zesjd3ud42czjzno6tbykppb0q2sllrejuqukofjgvoh2meqyo3nmwrvhrrxjjy_wjowcvdf-eyutqxtbpcsvrxzwosy4xzirljn8gab75zz7x9l-wuzbwemg7on1all8m9bux-5uz2yu_7siifpeuvfexnqvcu5-4aze-6xfvs5svlghmixjb1iockmarmeqzkscgzgr_7818pqjn19jvyhz.meyciqdjb9hlkixl4sz_rt8-tj8v7t6tzcbxfjgcuyhbc8ixuwihapwstswmgpu_k43h-va03ffjltif7n-k3qrucylug8il/$all -||shared.outlook.inky.com/link?domain=www.toziba.ir/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxduf1vgjau_s99dqa4t-mtbcbortbrpqqhireoqmmllilisv--8rrkj-fm3pp1jrqbxuzogu6lajgr-gscydidneklueqkyghxataqeskap0d1icdpx5-xhepmyfztb4u_1er9gwqlls0inmoz6zpd1y8ybaougl6eioelie1pd1fvuhzk2mfxau_wb173mbp_9kvnloytl6c1ida15m5hc9eynkkqkaruwsinajexjjmyy87akjxrhm55fe5yxhmndvmrtoiww3ewve8cwlmrcpelfi7smoghdistd2_pyu4jwk0iz-ncvdrjbzn2vt13vv4de76-4cqhacp8i-kpt7tl7cfos3vxc_otje5d44bihawljjdnkjsnzktprjwzkcv_2xpzzdhpl9e5g6k.meucigd6xwariut2lkiettiajcosxyluv7ub6nhbepewswmwaiea4mzpunjaca7lslweyqnda4gpvqjwhufuenzur1jmp64//$all -||shared.outlook.inky.com/link?domain=www.toziba.ir/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdunfugkaq_jd7tqby28qtte2siucq4akhiquccnh36heusom_93hq0odndjazm7p7jrqbtgtkoxmvihjsn4atsxnae0sfiliaq_yjwemmigieajwaghr4flxxomyqraaocn-olxohlupdgzsxe7prokpvd5qbqawg1wcoobwjkz3ufhzxrsqdhoeov97zesjd3ud42czjzno6tbykppb0q2sllrejuqukofjgvoh2meqyo3nmwrvhrrxjjy_wjowcvdf-eyutqxtbpcsvrxzwosy4xzirljn8gab75zz7x9l-wuzbwemg7on1all8m9bux-5uz2yu_7siifpeuvfexnqvcu5-4aze-6xfvs5svlghmixjb1iockmarmeqzkscgzgr_7818pqjn19jvyhz.meyciqdjb9hlkixl4sz_rt8-tj8v7t6tzcbxfjgcuyhbc8ixuwihapwstswmgpu_k43h-va03ffjltif7n-k3qrucylug8il//$all +||shared.outlook.inky.com$all ||shared.pdffiller.com/1395f7beaf30f1943ac9e1b9800a8fbf/8c7dd922ad47494fc02c388e12c00eac/cdecfead5bd78cb1c29f931bc49ad2db.exe?t=1549302986$all ||shareddocuments.ml$all ||shareddynamics.com$all @@ -556488,9 +556758,11 @@ ||stdymjventsluzcafsrp.dns.army$all ||stdymorcmmylntwincdq.dns.army$all ||stdymorcmmylntwinstr.dns.army$all +||stdynbnbnewagedevixz.dns.army$all ||stdynbnbnewagedevsmn.dns.army$all ||stdynbnbnewagedevxaz.dns.army$all ||stdyneverwalkachinese2loneinlifekstgqm.ydns.eu$all +||stdynmxwllminoragest.dns.army$all ||stdyperezluzcafeyzst.dns.navy$all ||stdypmrimelimtwstogy.dns.army$all ||stdypycsslwinnerscot.dns.army$all @@ -556521,6 +556793,7 @@ ||stdytopreoneenversrw.dns.army$all ||stdytopreoneenvervaj.dns.army$all ||stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu$all +||stdyunitedkesokokgst.dns.army$all ||stdyunitedkesokostdr.dns.army$all ||stdyunitedkesokostri.dns.navy$all ||stdyunitedkesokostxc.dns.army$all @@ -556530,7 +556803,9 @@ ||stdyworkfineanotherrainbowlomoyentwkgls.duckdns.org$all ||stdyworkfinesanotherrainbowlomoyentstfcp.ydns.eu$all ||stdyworkfinesanotherrainbowlomoyentstgot.ydns.eu$all +||stdyworkfinetraingst.dns.army$all ||stdyzgchgcloudgostgt.dns.army$all +||stdyzgchgcloudgostxs.dns.army$all ||steadyrestmanufacturers.com$all ||steak.wpress.dk$all ||steakhouse.com.ua$all @@ -558724,7 +558999,7 @@ ||strengthandvigour.com$all ||strengthrer.com$all ||strenover.ga$all -||stressing.pw/spike/svchost.exe$all +||stressing.pw$all ||stressnada.com$all ||stretchpilates.fit$all ||strewn.org$all @@ -559434,8 +559709,7 @@ ||supercutscissors.com$all ||superdad.id$all ||superdigitalguy.xyz$all -||superdomain1709.info/c4fxp3oiuoyf.67w$all -||superdomain1709.info/kuycdsjte.jdz$all +||superdomain1709.info$all ||superdot.rs$all ||superecruiters.com$all ||superfacil.center$all @@ -559544,7 +559818,9 @@ ||support.mdsol.com$all ||support.nordenrecycling.com$all ||support.nuvemit.com$all -||support.pubg.com$all +||support.pubg.com/attachments/token/t6cno6ywz3wf4svnnwt5weowd/$all +||support.pubg.com/attachments/token/t6cno6ywz3wf4svnnwt5weowd/?name=hsjloader.exe$all +||support.pubg.com/attachments/token/t6cno6ywz3wf4svnnwt5weowd?name=hsjloader.exe$all ||support.redbook.aero$all ||support.revolus.xyz$all ||support.servu.co.uk$all @@ -559905,7 +560181,7 @@ ||swicoservers.co.uk$all ||swieradowbiega.pl$all ||swifck.xmr.ac$all -||swift-cloud.com$all +||swift-cloud.com/storage/doc/statement.doc$all ||swiftbusinesspay.com$all ||swiftee.co.uk$all ||swiftender.com$all @@ -560828,7 +561104,11 @@ ||targas.de$all ||targat-china.com$all ||target-events.com$all -||target-support.online$all +||target-support.online/exe/softsetting.exe$all +||target-support.online/old/upload/ddd5.exe$all +||target-support.online/old/upload/emter.exe$all +||target-support.online/old/upload/socks.exe$all +||target-support.online/old/upload/test32.exe$all ||target2cloud.com$all ||targetbizbd.com$all ||targetcm.net$all @@ -562443,7 +562723,9 @@ ||thachastew.com$all ||thachvietstone.com$all ||thadathilfarmresort.com$all -||thaddeusarmstrong.com$all +||thaddeusarmstrong.com/wp-content/txxwd-me7gh-slgzwqla/$all +||thaddeusarmstrong.com/wp-content/txxwd-me7gh-slgzwqla//$all +||thaddeusarmstrong.com/wp-content/wrx/$all ||thadinnoo.co$all ||thagreymatter.com$all ||thai-chana.asia$all @@ -564243,7 +564525,17 @@ ||tlcid.org$all ||tlckids-or.ga$all ||tlcmoto.com$all -||tldrbox.top$all +||tldrbox.top/1.exe$all +||tldrbox.top/11.exe$all +||tldrbox.top/2$all +||tldrbox.top/2.exe$all +||tldrbox.top/3$all +||tldrbox.top/32.exe$all +||tldrbox.top/4$all +||tldrbox.top/5$all +||tldrbox.top/6$all +||tldrbox.top/64.exe$all +||tldrbox.top/v$all ||tldrnet.top$all ||tlextreme.com$all ||tlfthelifefactory.com.au$all @@ -565921,7 +566213,7 @@ ||ts.7rb.xyz$all ||ts0ev73.com$all ||tsal.com$all -||tsapparel.com.my/fd66e6.php$all +||tsapparel.com.my$all ||tsareva-garden.ru$all ||tsatsi.co.za$all ||tsauctions.com$all @@ -566158,7 +566450,7 @@ ||tunnelview.co.uk$all ||tunuvo.com$all ||tuobrasocial.com.ar$all -||tuoitrethainguyen.vn/moah-ky0x_u-t9/invoice/en_en/new-order/$all +||tuoitrethainguyen.vn$all ||tupibaje.com$all ||tupperware.michaelroberge.ca$all ||tur.000webhostapp.com$all @@ -567972,7 +568264,9 @@ ||unlimited.nu$all ||unlimitedbags.club$all ||unlimitedfreightco.com$all -||unlimitedimportandexport.com$all +||unlimitedimportandexport.com/wp-content/plugins/all-in-one-wp-migration/lib/bread.exe$all +||unlimitedimportandexport.com/wp-content/plugins/all-in-one-wp-migration/lib/cvxjr.exe$all +||unlimitedimportandexport.com/wp-content/plugins/all-in-one-wp-migration/lib/jkzse.exe$all ||unlock-king.com$all ||unlock2.neagoeandrei.com$all ||unlockall.neagoeandrei.com$all @@ -568362,7 +568656,7 @@ ||url.emailprotection.link/?bgmvicpuho15c9_q9hiofgnmkaco0q_lujjcaeowkfik_hdtt1uqmbkpovhxykckgjoqoytv_u0g2umkhd4mbi9ms8vo3vliq2clouuaa6no2a7ij5ljfsouoeememvmi/$all ||url.emailprotection.link/?bizyxbw1fdagsfcc1n6ep1awpdx9dr0brnjjqwgyaofpw98limviipvrszjnzzluclpeqqdywfxwnwudvwrljcufuhl2_nha0bs8wz9jmbahcciikbseljewayzbe_cnd/$all ||url.sg/rwtho$all -||url2.mailanyone.net/v1/?m=1hibcm-0003zv-63&i=57e1b682&c=sb1blj46bk32u6f729r5t_slvkx-heewxh20_zdn9-3ktcc0-kn35fykilpydgeyvrbwqwb5h__fk383wtdakqftjlelxz06jbaglri5jmujnydjkasqxwdtg2hn-_be1dzrnthvvhigyhm_tvbew342habp8dtit9jjlieuc2x-ipgdgipe7y_c9jhe69532gmnxozb5wifjfbstzicagmtpg6yxmreaf0sq2dgo-ksy54hetfhn6gwm4kiw2vvcqx17a9bm6ykn8bwpwdjwg/$all +||url2.mailanyone.net$all ||url3.mailanyone.net$all ||url5459.41southbar.com$all ||url675.textilmallorca.com$all @@ -568605,7 +568899,32 @@ ||utting.org$all ||utv.sakeronline.se$all ||utv1.enliden.net$all -||uujian.cn$all +||uujian.cn/browser/apk/100-2.9.apk$all +||uujian.cn/browser/apk/101-2.9.1.apk$all +||uujian.cn/browser/apk/102-2.9.2.apk$all +||uujian.cn/browser/apk/103-2.9.3.apk$all +||uujian.cn/browser/apk/104-2.9.4.apk$all +||uujian.cn/browser/apk/105-2.9.5.apk$all +||uujian.cn/browser/apk/106-2.9.6.apk$all +||uujian.cn/browser/apk/107-2.9.7.apk$all +||uujian.cn/browser/apk/108-2.9.8.apk$all +||uujian.cn/browser/apk/88-2.7.apk$all +||uujian.cn/browser/apk/89-2.7.1.apk$all +||uujian.cn/browser/apk/90-2.7.2.apk$all +||uujian.cn/browser/apk/91-2.7.3.apk$all +||uujian.cn/browser/apk/92-2.7.4.apk$all +||uujian.cn/browser/apk/93-2.7.5.apk$all +||uujian.cn/browser/apk/94-2.8.apk$all +||uujian.cn/browser/apk/95-2.8.1.apk$all +||uujian.cn/browser/apk/96-2.8.2.apk$all +||uujian.cn/browser/apk/97-2.8.3.apk$all +||uujian.cn/browser/apk/98-2.8.4.apk$all +||uujian.cn/browser/apk/99-2.8.5.apk$all +||uujian.cn/browser/apk/beta.apk$all +||uujian.cn/browser/apk/browser-l.apk$all +||uujian.cn/browser/apk/browser.apk$all +||uujian.cn/browser/apk/m3u8loader.apk$all +||uujian.cn/browser/apk/test.apk$all ||uumove.com$all ||uurty87e8rt7rt.com$all ||uutiset.helppokoti.fi$all @@ -570633,7 +570952,7 @@ ||voingani.it$all ||voip96.ru$all ||voipminic.com$all -||vokasi.ub.ac.id$all +||vokasi.ub.ac.id/wuk/kuqyslbgavnwlmcuk0qalhxifzp4mgze8anlcewu1pa8fw4lfex0y/$all ||vokzalrf.ru$all ||vol.agency$all ||vol2.pw$all @@ -571273,7 +571592,9 @@ ||washuis.nl$all ||wasidora.com$all ||wasilewski-online.de$all -||wasimjee.com$all +||wasimjee.com/wp-content/themes/host/languages/kia.zip$all +||wasimjee.com/wp-content/themes/host/languages/msg.jpg$all +||wasimjee.com/wp-content/themes/host/ordomain/msg.jpg$all ||wasino.co.th$all ||wasobd.net$all ||waspha.com$all @@ -572878,7 +573199,8 @@ ||woatinkwoo.com$all ||woclawoffers.fun$all ||wocomm.marketingmindz.com$all -||wodfitapparel.fr$all +||wodfitapparel.fr/wp-content/themes/cleayn/6o00s4g8/$all +||wodfitapparel.fr/wp-content/themes/fagri/oknuyqlfr/$all ||wodmetaldom.pl$all ||wodsuit.com$all ||woelf.in$all @@ -575596,9 +575918,9 @@ ||yoyoso.nz$all ||yoyoteacher.cn$all ||yp.dcyazilim.com$all -||yp.hnggzyjy.cn/common/yz.vbs$all +||yp.hnggzyjy.cn$all ||ypbb.or.id$all -||ypddf.org/en/nr/$all +||ypddf.org$all ||ypicsdy.cf$all ||ypko-55.gq$all ||ypom.com.br$all @@ -575762,7 +576084,9 @@ ||yuti.kr$all ||yuvann.com$all ||yuvikadvertisments.com$all -||yuwaraja.vokasi.ub.ac.id$all +||yuwaraja.vokasi.ub.ac.id/vendors/https://document/4tb6lng9d2aaadfd/$all +||yuwaraja.vokasi.ub.ac.id/vendors/https:/document/4tb6lng9d2aaadfd/$all +||yuwaraja.vokasi.ub.ac.id/vendors/overview/5utm325651630390125u6bd6ce4nkpml62pph/$all ||yuweis.com$all ||yuxigon.com$all ||yuxuanknit.com$all diff --git a/urlhaus-filter-agh-online.txt b/urlhaus-filter-agh-online.txt index 4da010e7..e2cf7c54 100644 --- a/urlhaus-filter-agh-online.txt +++ b/urlhaus-filter-agh-online.txt @@ -1,5 +1,5 @@ ! Title: Online Malicious URL Blocklist (AdGuard Home) -! Updated: Mon, 12 Apr 2021 00:12:54 UTC +! Updated: Mon, 12 Apr 2021 12:13:00 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -38,7 +38,6 @@ ||1.246.222.94^ ||1.246.222.98^ ||1.246.223.105^ -||1.246.223.109^ ||1.246.223.10^ ||1.246.223.126^ ||1.246.223.127^ @@ -70,7 +69,8 @@ ||1008691.com^ ||101.108.129.251^ ||101.108.130.121^ -||101.108.131.47^ +||101.108.131.99^ +||101.108.138.150^ ||101.16.183.179^ ||101.229.85.127^ ||101.255.36.154^ @@ -78,6 +78,8 @@ ||101.28.218.245^ ||101.28.76.34^ ||101.75.157.99^ +||101.99.91.200^ +||101.99.94.15^ ||102.130.115.14^ ||102.141.240.139^ ||103.113.99.79^ @@ -92,25 +94,18 @@ ||103.237.21.36^ ||103.238.228.3^ ||103.240.249.121^ -||103.4.117.26^ -||103.47.104.246^ ||103.79.112.254^ -||103.82.98.170^ +||103.82.81.37^ ||103.84.240.130^ ||103.84.241.94^ ||103.91.245.12^ -||103.91.245.13^ ||103.91.245.14^ -||103.91.245.16^ -||103.91.245.17^ -||103.91.245.27^ +||103.91.245.19^ ||103.91.245.36^ -||103.91.245.3^ -||103.91.245.46^ -||103.91.245.47^ +||103.91.245.48^ ||103.92.25.90^ ||103.92.25.95^ -||104.168.44.57^ +||103.97.184.180^ ||104.184.75.123^ ||104.206.93.94^ ||104.33.52.85^ @@ -121,6 +116,7 @@ ||106.105.33.43^ ||107.172.104.105^ ||107.172.141.115^ +||107.172.156.3^ ||107.172.249.148^ ||107.173.219.80^ ||107.173.23.240^ @@ -137,10 +133,10 @@ ||108.190.250.48^ ||108.239.155.26^ ||108.249.194.121^ -||109.104.151.108^ ||109.124.90.229^ ||109.233.196.232^ ||109.235.7.228^ +||109.248.58.238^ ||109.86.85.253^ ||109.95.200.102^ ||109.95.200.230^ @@ -156,13 +152,13 @@ ||110.248.251.194^ ||110.251.10.18^ ||110.253.213.198^ +||110.35.145.127^ ||110.35.208.21^ -||110.35.209.175^ -||110.35.223.92^ -||110.35.225.24^ +||110.35.221.77^ ||110.35.235.57^ +||110.35.249.21^ ||110.35.4.2^ -||111.118.88.128^ +||110.89.10.147^ ||111.118.88.61^ ||111.119.245.114^ ||111.125.67.125^ @@ -177,12 +173,9 @@ ||111.185.49.223^ ||111.38.103.114^ ||111.38.103.122^ -||111.38.104.141^ ||111.38.121.222^ -||111.38.121.223^ ||111.38.121.226^ ||111.38.123.136^ -||111.38.123.15^ ||111.38.123.200^ ||111.38.26.243^ ||111.38.8.81^ @@ -203,12 +196,8 @@ ||112.230.168.103^ ||112.232.0.112^ ||112.237.141.241^ -||112.237.144.226^ -||112.237.75.157^ -||112.237.99.207^ ||112.238.143.135^ ||112.238.190.207^ -||112.238.227.228^ ||112.238.39.2^ ||112.239.101.146^ ||112.240.216.17^ @@ -222,6 +211,7 @@ ||112.247.214.146^ ||112.247.240.226^ ||112.247.82.122^ +||112.248.109.156^ ||112.248.148.90^ ||112.248.63.212^ ||112.249.109.217^ @@ -241,6 +231,7 @@ ||112.27.124.143^ ||112.27.124.147^ ||112.27.124.149^ +||112.27.124.150^ ||112.27.124.158^ ||112.27.124.165^ ||112.27.124.175^ @@ -273,34 +264,34 @@ ||112.30.1.60^ ||112.30.1.90^ ||112.30.1.91^ +||112.30.110.30^ ||112.30.110.38^ ||112.30.110.45^ ||112.30.110.60^ ||112.30.35.237^ -||112.30.4.103^ ||112.30.4.118^ ||112.30.4.124^ ||112.30.4.53^ ||112.30.4.61^ ||112.30.4.68^ -||112.30.4.70^ ||112.30.4.73^ ||112.30.4.90^ ||112.31.0.113^ ||112.31.177.39^ -||112.31.211.135^ ||112.31.216.207^ -||112.31.240.239^ ||112.53.224.79^ ||112.53.227.66^ ||112.65.53.175^ +||112.72.162.159^ ||112.72.162.49^ ||112.72.175.147^ ||112.72.176.112^ +||112.72.176.84^ ||112.72.226.202^ ||112.80.215.101^ ||112.82.146.253^ ||112.82.224.139^ +||112.9.155.122^ ||112.93.29.211^ ||113.11.95.254^ ||113.118.249.97^ @@ -308,65 +299,77 @@ ||113.13.241.32^ ||113.161.58.249^ ||113.161.78.185^ +||113.194.131.72^ +||113.194.135.223^ +||113.226.42.250^ ||113.230.86.107^ ||113.231.184.245^ ||113.231.211.131^ ||113.254.169.251^ ||113.59.128.133^ +||113.59.136.39^ +||113.59.144.42^ ||113.59.149.125^ -||113.59.154.21^ -||113.59.180.40^ ||113.59.191.47^ ||113.61.204.205^ ||113.65.10.139^ -||113.88.153.5^ -||113.88.192.87^ +||113.88.123.22^ +||113.88.228.152^ ||113.89.43.165^ -||114.199.204.37^ ||114.199.253.235^ ||114.201.201.68^ ||114.224.203.128^ ||114.30.54.64^ -||114.35.254.7^ ||114.79.172.42^ ||115.165.216.112^ ||115.171.204.161^ ||115.42.47.36^ -||115.48.140.22^ -||115.49.77.222^ +||115.49.232.197^ +||115.50.172.22^ +||115.50.2.148^ ||115.51.106.238^ +||115.51.91.81^ ||115.53.203.161^ -||115.54.241.214^ +||115.54.212.175^ ||115.55.156.203^ +||115.55.7.9^ ||115.56.131.242^ ||115.56.133.96^ ||115.56.155.202^ -||115.56.178.168^ -||115.56.182.146^ -||115.56.182.151^ -||115.58.111.76^ -||115.58.132.140^ -||115.59.203.197^ ||115.59.214.205^ ||115.59.233.160^ ||115.59.252.120^ ||115.61.110.120^ +||115.61.167.21^ +||115.62.172.140^ +||115.62.26.113^ ||115.73.3.11^ ||115.75.217.79^ ||115.88.133.148^ ||115.92.174.231^ -||115.97.139.110^ +||116.108.92.154^ ||116.124.219.2^ ||116.206.164.46^ ||116.211.100.26^ +||117.194.162.12^ ||117.20.204.138^ ||117.20.204.5^ ||117.20.210.52^ +||117.20.220.126^ ||117.20.243.40^ ||117.201.205.232^ -||117.251.59.124^ +||117.202.64.149^ +||117.213.12.177^ +||117.213.47.94^ +||117.213.9.42^ +||117.215.249.250^ +||117.222.173.91^ +||117.222.175.134^ +||117.242.208.197^ +||117.247.201.45^ ||117.26.124.173^ ||117.63.113.146^ +||117.63.133.251^ ||117.63.53.15^ ||117.86.105.110^ ||118.101.7.28^ @@ -390,10 +393,9 @@ ||118.233.65.93^ ||118.42.125.246^ ||118.43.180.33^ +||118.79.113.239^ ||118.79.218.213^ ||118.79.50.203^ -||118.79.74.77^ -||118.91.41.135^ ||118.99.179.164^ ||118.99.183.235^ ||118.99.239.217^ @@ -412,6 +414,7 @@ ||119.179.43.1^ ||119.179.58.163^ ||119.18.38.144^ +||119.18.88.78^ ||119.180.106.217^ ||119.181.119.21^ ||119.182.97.232^ @@ -427,14 +430,14 @@ ||119.191.255.236^ ||119.204.30.144^ ||119.250.129.231^ -||119.251.105.221^ ||119.56.131.155^ ||119.56.143.46^ ||119.56.143.71^ ||119.56.148.115^ ||119.56.155.57^ -||119.56.166.36^ +||119.56.206.43^ ||119.96.38.150^ +||119.99.52.69^ ||12.132.113.2^ ||12.15.69.83^ ||12.178.187.6^ @@ -457,23 +460,20 @@ ||120.193.91.201^ ||120.193.91.202^ ||120.193.91.204^ -||120.193.91.208^ ||120.193.91.215^ ||120.193.91.233^ +||120.209.126.206^ ||120.209.126.235^ ||120.209.126.239^ ||120.209.126.250^ -||120.209.126.25^ ||120.209.126.60^ ||120.209.126.74^ ||120.209.99.127^ ||120.50.66.60^ ||120.50.93.115^ -||120.57.123.202^ ||120.6.8.11^ ||120.7.75.99^ ||120.83.79.42^ -||120.85.172.111^ ||121.100.114.164^ ||121.100.96.8^ ||121.121.44.222^ @@ -494,6 +494,7 @@ ||121.254.76.17^ ||121.61.96.158^ ||121.61.97.64^ +||121.8.107.214^ ||121.88.99.236^ ||122.100.150.204^ ||122.137.53.134^ @@ -505,7 +506,7 @@ ||122.232.227.128^ ||122.254.33.214^ ||123.0.240.58^ -||123.10.137.193^ +||123.10.32.252^ ||123.11.202.178^ ||123.110.124.244^ ||123.110.170.237^ @@ -513,7 +514,6 @@ ||123.110.19.248^ ||123.110.200.98^ ||123.110.238.188^ -||123.12.164.165^ ||123.129.2.28^ ||123.129.84.36^ ||123.130.208.52^ @@ -527,6 +527,7 @@ ||123.134.14.130^ ||123.135.20.164^ ||123.135.246.180^ +||123.14.95.26^ ||123.154.236.114^ ||123.159.8.100^ ||123.183.16.71^ @@ -552,11 +553,11 @@ ||123.241.148.58^ ||123.241.184.124^ ||123.28.217.23^ -||123.4.204.223^ -||123.4.251.81^ -||123.8.250.132^ -||123.9.193.253^ -||123.9.85.25^ +||123.4.242.19^ +||123.4.47.57^ +||123.5.148.182^ +||123.5.189.15^ +||123.9.36.120^ ||124.129.221.150^ ||124.129.76.230^ ||124.130.40.31^ @@ -592,24 +593,20 @@ ||125.40.1.235^ ||125.40.146.46^ ||125.40.3.71^ +||125.41.14.228^ ||125.43.82.59^ -||125.44.8.154^ ||125.45.186.88^ ||125.45.66.253^ -||125.47.244.8^ +||125.47.244.126^ ||125.47.74.230^ -||125.47.93.160^ ||126.39.155.210^ ||128.116.133.92^ -||13.114.247.134^ ||130.255.159.133^ -||134.119.186.214^ ||135.148.36.127^ ||138.99.204.224^ ||139.159.226.180^ ||139.170.173.198^ ||139.216.102.151^ -||14.102.17.222^ ||14.136.80.242^ ||14.138.8.215^ ||14.138.8.51^ @@ -623,10 +620,15 @@ ||14.50.129.248^ ||14.55.29.2^ ||140.237.12.32^ +||141.105.65.94^ ||142.11.216.5^ ||142.177.56.127^ +||143.198.120.58^ ||148.69.108.177^ ||149.255.15.134^ +||149.255.15.170^ +||149.255.15.29^ +||149.255.15.44^ ||149.255.15.99^ ||149.3.124.194^ ||14karatvisions.com^ @@ -646,9 +648,8 @@ ||162.191.165.238^ ||162.194.28.60^ ||162.209.98.174^ -||163.125.200.234^ +||162.245.221.121^ ||163.125.206.193^ -||163.53.206.228^ ||167.114.172.177^ ||170.81.238.178^ ||171.121.255.12^ @@ -686,17 +687,18 @@ ||175.201.104.192^ ||175.208.230.8^ ||175.213.25.192^ -||175.42.46.118^ ||176.111.174.35^ ||176.111.174.66^ ||176.111.174.67^ ||176.113.161.104^ ||176.113.161.121^ ||176.113.161.59^ +||176.113.161.65^ ||176.113.161.66^ ||176.113.161.71^ ||176.113.161.76^ ||176.113.161.84^ +||176.113.161.91^ ||176.113.161.95^ ||176.12.117.70^ ||176.123.7.115^ @@ -704,7 +706,6 @@ ||176.124.7.225^ ||176.221.188.251^ ||176.240.84.106^ -||177.11.92.78^ ||177.131.226.235^ ||177.54.82.154^ ||178.124.182.187^ @@ -712,7 +713,6 @@ ||178.150.174.65^ ||178.151.143.2^ ||178.165.122.141^ -||178.17.171.144^ ||178.175.0.145^ ||178.175.0.24^ ||178.175.1.179^ @@ -721,128 +721,130 @@ ||178.175.10.124^ ||178.175.10.182^ ||178.175.10.221^ +||178.175.10.247^ ||178.175.10.96^ +||178.175.100.104^ ||178.175.100.151^ +||178.175.101.212^ ||178.175.101.252^ ||178.175.102.207^ ||178.175.102.217^ ||178.175.102.25^ -||178.175.103.52^ +||178.175.103.14^ ||178.175.103.58^ ||178.175.104.112^ +||178.175.104.115^ ||178.175.105.67^ -||178.175.105.89^ ||178.175.106.160^ ||178.175.106.179^ -||178.175.106.199^ +||178.175.107.135^ ||178.175.107.142^ -||178.175.107.156^ ||178.175.107.224^ ||178.175.108.127^ ||178.175.108.173^ -||178.175.108.87^ ||178.175.109.165^ ||178.175.109.181^ +||178.175.11.100^ ||178.175.11.101^ ||178.175.11.139^ ||178.175.11.6^ ||178.175.110.191^ ||178.175.110.195^ -||178.175.111.190^ ||178.175.112.111^ ||178.175.112.183^ -||178.175.112.254^ ||178.175.112.85^ +||178.175.112.87^ ||178.175.113.174^ +||178.175.114.117^ ||178.175.114.151^ ||178.175.114.51^ ||178.175.115.106^ ||178.175.115.208^ ||178.175.116.254^ -||178.175.116.56^ -||178.175.117.110^ -||178.175.118.112^ -||178.175.118.129^ ||178.175.118.174^ ||178.175.118.41^ ||178.175.119.161^ ||178.175.119.43^ -||178.175.12.222^ ||178.175.12.68^ +||178.175.12.91^ ||178.175.120.12^ +||178.175.121.125^ +||178.175.121.130^ ||178.175.121.151^ ||178.175.121.169^ +||178.175.121.243^ +||178.175.121.77^ ||178.175.122.172^ -||178.175.122.28^ +||178.175.122.197^ ||178.175.122.47^ -||178.175.123.202^ ||178.175.123.53^ +||178.175.124.113^ ||178.175.124.38^ -||178.175.125.149^ ||178.175.125.218^ -||178.175.125.52^ ||178.175.126.129^ ||178.175.126.18^ ||178.175.126.234^ -||178.175.126.46^ +||178.175.126.43^ ||178.175.126.80^ ||178.175.127.202^ ||178.175.127.90^ -||178.175.14.222^ -||178.175.14.248^ -||178.175.14.34^ +||178.175.13.219^ +||178.175.15.196^ ||178.175.15.19^ ||178.175.15.232^ ||178.175.15.250^ ||178.175.15.72^ +||178.175.16.224^ ||178.175.16.26^ ||178.175.16.86^ ||178.175.17.135^ -||178.175.17.13^ ||178.175.17.14^ ||178.175.17.50^ -||178.175.17.54^ ||178.175.17.9^ -||178.175.19.163^ -||178.175.2.183^ +||178.175.18.177^ +||178.175.18.31^ ||178.175.2.189^ ||178.175.2.217^ +||178.175.2.23^ ||178.175.2.46^ ||178.175.2.71^ ||178.175.20.117^ ||178.175.20.126^ ||178.175.20.231^ ||178.175.21.194^ -||178.175.21.34^ +||178.175.21.53^ ||178.175.21.71^ ||178.175.22.120^ +||178.175.22.198^ ||178.175.22.206^ ||178.175.22.51^ +||178.175.22.74^ ||178.175.22.93^ ||178.175.22.94^ ||178.175.24.107^ ||178.175.24.176^ ||178.175.24.183^ -||178.175.24.232^ -||178.175.25.114^ -||178.175.25.56^ +||178.175.24.52^ +||178.175.25.162^ ||178.175.26.215^ ||178.175.27.151^ +||178.175.27.203^ ||178.175.27.32^ -||178.175.28.48^ +||178.175.27.43^ ||178.175.28.5^ ||178.175.29.135^ ||178.175.29.233^ -||178.175.29.35^ ||178.175.3.109^ ||178.175.30.187^ -||178.175.30.254^ ||178.175.30.71^ +||178.175.30.90^ ||178.175.31.128^ +||178.175.31.216^ ||178.175.31.55^ ||178.175.31.92^ ||178.175.32.34^ ||178.175.33.190^ +||178.175.33.233^ ||178.175.34.180^ ||178.175.34.222^ ||178.175.35.83^ @@ -853,18 +855,18 @@ ||178.175.36.250^ ||178.175.36.98^ ||178.175.37.10^ -||178.175.37.122^ ||178.175.37.149^ ||178.175.37.215^ ||178.175.37.234^ ||178.175.38.12^ ||178.175.38.74^ ||178.175.38.88^ -||178.175.39.157^ +||178.175.39.110^ ||178.175.39.158^ ||178.175.39.203^ ||178.175.39.210^ ||178.175.4.120^ +||178.175.4.14^ ||178.175.4.180^ ||178.175.4.225^ ||178.175.40.108^ @@ -873,87 +875,91 @@ ||178.175.41.139^ ||178.175.41.182^ ||178.175.41.217^ +||178.175.41.230^ ||178.175.41.68^ ||178.175.42.221^ ||178.175.42.28^ ||178.175.42.46^ ||178.175.43.114^ ||178.175.43.217^ -||178.175.43.238^ +||178.175.43.90^ ||178.175.44.186^ ||178.175.44.38^ ||178.175.44.56^ ||178.175.44.78^ -||178.175.45.125^ ||178.175.45.234^ +||178.175.46.110^ ||178.175.46.113^ -||178.175.46.196^ -||178.175.46.208^ ||178.175.47.11^ ||178.175.47.122^ +||178.175.47.127^ ||178.175.47.222^ ||178.175.47.2^ ||178.175.47.75^ ||178.175.47.80^ ||178.175.47.99^ +||178.175.48.164^ ||178.175.48.185^ ||178.175.48.194^ ||178.175.48.223^ +||178.175.49.104^ +||178.175.49.253^ ||178.175.49.30^ ||178.175.49.51^ ||178.175.49.54^ ||178.175.49.82^ -||178.175.5.254^ +||178.175.5.223^ ||178.175.5.44^ ||178.175.50.217^ ||178.175.50.3^ ||178.175.50.42^ ||178.175.50.54^ ||178.175.50.68^ -||178.175.51.177^ +||178.175.51.117^ ||178.175.51.2^ +||178.175.52.114^ +||178.175.52.139^ ||178.175.52.15^ ||178.175.52.176^ ||178.175.52.181^ ||178.175.52.24^ +||178.175.52.255^ ||178.175.53.214^ ||178.175.53.231^ ||178.175.53.62^ ||178.175.53.79^ +||178.175.53.87^ ||178.175.54.100^ -||178.175.54.196^ +||178.175.54.119^ +||178.175.54.78^ +||178.175.55.118^ ||178.175.55.170^ ||178.175.55.60^ ||178.175.55.99^ ||178.175.56.30^ ||178.175.56.64^ ||178.175.56.74^ -||178.175.57.112^ +||178.175.57.121^ ||178.175.57.145^ ||178.175.58.12^ -||178.175.58.235^ +||178.175.58.130^ +||178.175.58.18^ ||178.175.59.103^ -||178.175.59.106^ ||178.175.59.12^ -||178.175.59.158^ -||178.175.6.144^ -||178.175.6.180^ -||178.175.60.158^ -||178.175.60.49^ -||178.175.60.7^ -||178.175.61.250^ +||178.175.59.173^ +||178.175.59.8^ +||178.175.6.201^ +||178.175.6.203^ +||178.175.61.212^ ||178.175.61.28^ -||178.175.62.137^ +||178.175.62.130^ ||178.175.62.151^ ||178.175.62.206^ -||178.175.63.223^ ||178.175.63.53^ ||178.175.64.116^ ||178.175.65.234^ ||178.175.65.237^ -||178.175.66.140^ ||178.175.66.186^ -||178.175.66.214^ ||178.175.67.28^ ||178.175.67.65^ ||178.175.68.140^ @@ -964,10 +970,8 @@ ||178.175.68.35^ ||178.175.68.4^ ||178.175.68.5^ -||178.175.69.18^ ||178.175.7.113^ ||178.175.7.198^ -||178.175.7.19^ ||178.175.70.108^ ||178.175.70.177^ ||178.175.70.178^ @@ -977,40 +981,37 @@ ||178.175.71.69^ ||178.175.72.208^ ||178.175.72.220^ +||178.175.72.58^ ||178.175.74.223^ ||178.175.75.94^ ||178.175.76.146^ ||178.175.76.221^ ||178.175.76.33^ +||178.175.76.34^ ||178.175.76.8^ -||178.175.77.47^ ||178.175.78.118^ -||178.175.78.125^ ||178.175.78.250^ ||178.175.79.128^ ||178.175.79.146^ ||178.175.79.198^ +||178.175.79.27^ ||178.175.8.119^ -||178.175.8.130^ -||178.175.8.13^ ||178.175.8.40^ -||178.175.81.114^ ||178.175.81.144^ ||178.175.81.189^ ||178.175.82.110^ ||178.175.82.73^ ||178.175.83.125^ +||178.175.83.17^ +||178.175.84.146^ ||178.175.84.154^ ||178.175.84.201^ ||178.175.84.237^ ||178.175.85.190^ -||178.175.86.117^ ||178.175.86.49^ -||178.175.86.59^ ||178.175.87.151^ ||178.175.87.161^ ||178.175.87.202^ -||178.175.87.207^ ||178.175.87.227^ ||178.175.88.102^ ||178.175.88.130^ @@ -1018,34 +1019,31 @@ ||178.175.88.204^ ||178.175.88.85^ ||178.175.89.152^ -||178.175.89.69^ +||178.175.89.195^ +||178.175.9.217^ ||178.175.9.223^ -||178.175.9.24^ ||178.175.90.137^ ||178.175.90.236^ ||178.175.90.3^ ||178.175.90.79^ +||178.175.91.243^ ||178.175.91.3^ ||178.175.91.97^ ||178.175.92.170^ -||178.175.93.115^ +||178.175.92.213^ ||178.175.93.120^ +||178.175.93.204^ ||178.175.93.234^ ||178.175.93.42^ -||178.175.93.98^ -||178.175.94.248^ -||178.175.94.27^ ||178.175.95.105^ ||178.175.95.54^ +||178.175.95.83^ ||178.175.96.136^ ||178.175.96.177^ -||178.175.96.198^ ||178.175.96.225^ ||178.175.97.248^ -||178.175.97.70^ ||178.175.98.63^ ||178.175.99.45^ -||178.175.99.90^ ||178.19.183.14^ ||178.205.101.33^ ||178.21.164.68^ @@ -1073,7 +1071,9 @@ ||180.177.104.65^ ||180.177.180.6^ ||180.177.242.73^ +||180.177.5.36^ ||180.218.5.171^ +||180.248.80.38^ ||180.66.111.36^ ||180.66.53.93^ ||180.94.170.166^ @@ -1090,40 +1090,45 @@ ||181.49.236.4^ ||181.49.59.162^ ||182.112.177.134^ -||182.114.88.240^ -||182.114.88.247^ -||182.115.176.253^ +||182.113.4.247^ +||182.114.194.183^ ||182.116.102.190^ -||182.116.35.52^ +||182.117.29.27^ ||182.119.200.55^ +||182.119.23.75^ +||182.119.48.230^ ||182.120.16.22^ ||182.120.192.88^ ||182.120.34.180^ -||182.121.73.158^ +||182.121.200.137^ +||182.121.205.246^ ||182.122.254.7^ +||182.126.109.194^ +||182.126.126.162^ ||182.126.87.210^ ||182.126.87.246^ -||182.127.213.136^ +||182.127.207.187^ +||182.127.80.240^ ||182.160.98.250^ ||182.233.0.252^ ||182.235.252.31^ ||182.53.197.62^ -||182.59.170.157^ ||182.88.27.89^ ||183.105.104.83^ ||183.109.169.45^ +||183.141.61.174^ ||183.17.145.112^ ||183.188.144.204^ -||183.188.146.216^ -||183.83.109.216^ +||183.49.86.54^ ||183.83.14.20^ ||183.97.40.9^ ||184.164.185.41^ ||184.175.115.10^ ||184.74.149.230^ ||185.106.209.68^ -||185.107.3.8^ ||185.117.2.107^ +||185.117.21.212^ +||185.132.53.182^ ||185.172.110.209^ ||185.172.110.235^ ||185.174.101.41^ @@ -1140,14 +1145,13 @@ ||185.245.96.94^ ||185.26.113.95^ ||185.34.16.231^ +||185.38.142.194^ ||185.55.1.182^ ||185.68.230.207^ ||185.81.154.208^ ||185.81.157.186^ ||185.82.217.185^ ||185.82.217.213^ -||185.82.219.160^ -||185.82.219.161^ ||185.82.219.219^ ||185.82.219.80^ ||186.151.144.85^ @@ -1161,7 +1165,6 @@ ||186.28.60.184^ ||186.34.4.40^ ||186.73.188.132^ -||186.73.188.134^ ||187.12.10.98^ ||187.135.141.192^ ||187.188.124.229^ @@ -1173,12 +1176,15 @@ ||188.152.41.141^ ||188.169.178.50^ ||188.169.179.127^ +||188.169.199.59^ ||188.169.30.30^ ||188.169.36.163^ +||188.169.45.140^ ||188.242.242.144^ ||188.69.251.12^ ||188.83.202.25^ -||189.201.250.184^ +||189.171.22.132^ +||189.175.214.112^ ||189.252.184.115^ ||190.0.42.106^ ||190.109.178.139^ @@ -1193,7 +1199,6 @@ ||190.122.112.42^ ||190.122.112.76^ ||190.130.20.14^ -||190.141.117.41^ ||190.147.16.184^ ||190.159.240.9^ ||190.210.214.130^ @@ -1209,19 +1214,20 @@ ||190.98.37.200^ ||190.98.41.33^ ||191.255.248.220^ -||192.153.57.94^ ||192.210.175.130^ +||192.227.185.106^ ||192.227.220.55^ ||192.227.228.67^ +||192.99.221.230^ ||192.99.240.77^ ||194.113.107.243^ ||194.147.142.230^ -||194.15.36.167^ ||194.152.35.139^ ||194.38.20.199^ ||195.139.126.51^ ||195.228.231.218^ ||195.24.94.187^ +||195.5.3.162^ ||196.202.26.182^ ||196.218.48.82^ ||196.221.148.90^ @@ -1229,15 +1235,12 @@ ||197.159.2.106^ ||197.50.27.115^ ||198.23.133.218^ -||198.23.174.104^ -||198.23.207.121^ +||198.23.213.61^ ||198.23.251.105^ -||198.46.132.132^ ||1am.co.nz^ ||2.239.22.188^ ||2.36.231.201^ ||2.37.149.230^ -||2.37.203.65^ ||2.45.111.158^ ||2.45.4.24^ ||2.55.125.182^ @@ -1250,7 +1253,6 @@ ||200.105.167.98^ ||200.111.189.70^ ||200.194.4.24^ -||200.2.161.171^ ||200.29.105.207^ ||200.30.132.50^ ||201.170.46.2^ @@ -1261,14 +1263,13 @@ ||202.107.233.41^ ||202.111.131.236^ ||202.166.217.54^ -||202.182.125.175^ ||202.29.95.12^ ||202.4.124.58^ -||202.44.228.125^ ||202.51.176.114^ ||202.51.191.174^ ||202.74.236.9^ ||203.109.201.243^ +||203.130.69.205^ ||203.159.80.128^ ||203.159.80.129^ ||203.159.80.164^ @@ -1295,12 +1296,12 @@ ||210.180.237.212^ ||210.216.152.122^ ||210.216.153.142^ -||210.57.237.70^ ||210.57.245.109^ ||210.68.242.114^ ||211.187.132.204^ ||211.187.75.220^ ||211.200.160.239^ +||211.203.111.207^ ||211.204.215.157^ ||211.210.66.179^ ||211.210.93.93^ @@ -1309,7 +1310,6 @@ ||211.237.120.13^ ||211.237.246.137^ ||211.238.83.238^ -||211.247.5.96^ ||212.122.86.105^ ||212.156.215.178^ ||212.46.197.114^ @@ -1319,7 +1319,7 @@ ||213.14.173.117^ ||213.149.190.193^ ||213.163.104.160^ -||213.163.104.99^ +||213.163.104.20^ ||213.163.113.225^ ||213.163.113.51^ ||213.163.114.202^ @@ -1336,7 +1336,7 @@ ||213.163.118.227^ ||213.163.126.176^ ||213.163.126.201^ -||213.163.126.7^ +||213.163.127.204^ ||213.163.127.250^ ||213.163.127.46^ ||213.189.178.163^ @@ -1356,7 +1356,6 @@ ||218.2.40.34^ ||218.234.165.18^ ||218.238.246.3^ -||218.32.118.1^ ||218.35.207.119^ ||218.35.227.133^ ||218.35.68.35^ @@ -1366,11 +1365,12 @@ ||218.79.103.159^ ||218.93.102.63^ ||218.93.102.75^ +||219.154.113.171^ ||219.154.127.194^ -||219.154.137.93^ -||219.156.73.171^ +||219.155.226.205^ ||219.157.136.212^ -||219.157.139.165^ +||219.157.14.239^ +||219.157.178.196^ ||219.157.37.210^ ||219.241.6.180^ ||219.68.1.148^ @@ -1385,7 +1385,6 @@ ||219.85.145.194^ ||21robo.com^ ||220.126.237.74^ -||220.132.106.247^ ||220.173.160.185^ ||220.200.22.163^ ||220.81.134.72^ @@ -1393,7 +1392,9 @@ ||221.124.78.15^ ||221.13.150.74^ ||221.14.162.20^ +||221.14.47.204^ ||221.15.127.60^ +||221.15.182.72^ ||221.15.3.50^ ||221.157.191.178^ ||221.160.136.213^ @@ -1411,18 +1412,17 @@ ||221.232.183.167^ ||221.235.137.36^ ||221.3.68.16^ +||222.107.145.56^ ||222.108.17.64^ ||222.118.248.149^ ||222.119.65.145^ -||222.132.125.138^ ||222.135.9.5^ ||222.137.122.105^ ||222.137.139.86^ -||222.137.170.17^ ||222.137.72.66^ ||222.138.133.186^ -||222.138.17.203^ ||222.139.21.190^ +||222.140.163.181^ ||222.140.17.245^ ||222.187.9.178^ ||222.211.72.66^ @@ -1445,9 +1445,9 @@ ||23.24.213.121^ ||23.243.149.13^ ||23.243.21.167^ -||23.92.213.108^ ||23.94.190.101^ ||23.95.122.24^ +||23.95.122.25^ ||24.103.74.180^ ||24.11.141.134^ ||24.119.158.74^ @@ -1518,9 +1518,7 @@ ||27.213.255.202^ ||27.213.66.112^ ||27.213.84.74^ -||27.214.37.129^ ||27.215.139.242^ -||27.215.190.172^ ||27.215.212.209^ ||27.215.253.149^ ||27.215.71.243^ @@ -1532,7 +1530,6 @@ ||27.217.191.58^ ||27.218.135.3^ ||27.219.132.71^ -||27.219.151.83^ ||27.219.160.112^ ||27.219.176.72^ ||27.219.83.244^ @@ -1548,16 +1545,14 @@ ||27.35.154.13^ ||27.35.212.124^ ||27.35.58.5^ -||27.40.120.108^ -||27.40.73.175^ +||27.40.79.170^ ||27.41.36.97^ -||27.45.90.246^ -||27.5.44.190^ ||31.0.98.131^ ||31.11.51.57^ ||31.13.23.180^ ||31.168.124.130^ ||31.168.146.199^ +||31.168.16.68^ ||31.168.179.83^ ||31.168.184.59^ ||31.168.191.243^ @@ -1607,7 +1602,6 @@ ||39.113.245.254^ ||39.113.98.136^ ||39.114.137.102^ -||39.115.0.100^ ||39.117.31.162^ ||39.162.104.119^ ||39.162.98.216^ @@ -1668,27 +1662,34 @@ ||40.88.2.151^ ||41.139.209.46^ ||41.165.130.43^ -||41.190.63.174^ ||41.193.192.100^ ||41.219.185.171^ ||41.226.60.115^ +||41.72.203.82^ +||41.76.157.2^ ||41.86.18.147^ ||41.86.18.152^ -||41.86.18.204^ -||41.86.19.146^ -||41.86.19.206^ -||41.86.21.28^ -||41.86.21.60^ -||41.86.5.198^ +||41.86.21.38^ +||41.86.21.59^ +||41.86.5.103^ +||41.86.5.197^ +||41.86.5.48^ ||42.202.101.181^ ||42.202.101.199^ +||42.224.171.165^ ||42.224.176.27^ +||42.224.254.220^ +||42.224.4.110^ +||42.227.222.189^ +||42.227.225.253^ ||42.228.40.143^ -||42.228.60.114^ +||42.230.143.162^ +||42.233.97.141^ +||42.235.84.85^ ||42.236.161.72^ ||42.236.212.157^ +||42.237.114.80^ ||42.238.141.250^ -||42.56.15.227^ ||42.61.99.155^ ||42.82.217.241^ ||43.230.207.204^ @@ -1707,6 +1708,7 @@ ||45.144.225.27^ ||45.148.10.47^ ||45.148.10.94^ +||45.15.143.191^ ||45.176.108.248^ ||45.176.109.205^ ||45.176.110.146^ @@ -1715,6 +1717,7 @@ ||45.229.53.148^ ||45.27.253.137^ ||45.51.104.59^ +||45.77.9.151^ ||45.85.90.131^ ||45.9.148.37^ ||45.92.108.35^ @@ -1735,8 +1738,8 @@ ||46.42.118.86^ ||46.42.86.128^ ||46.97.76.242^ +||47.136.96.53^ ||47.145.152.26^ -||47.151.23.172^ ||47.157.97.71^ ||47.16.131.51^ ||47.21.202.98^ @@ -1756,6 +1759,7 @@ ||5.14.122.233^ ||5.188.62.111^ ||5.95.226.154^ +||50.115.174.103^ ||50.115.174.106^ ||50.121.91.255^ ||50.247.83.66^ @@ -1780,32 +1784,39 @@ ||58.240.147.97^ ||58.241.78.55^ ||58.242.91.219^ -||58.249.73.208^ +||58.249.22.24^ ||58.249.75.128^ +||58.249.75.146^ +||58.249.77.141^ ||58.249.80.36^ -||58.252.176.140^ ||58.253.15.184^ ||58.51.219.200^ ||58.72.165.153^ ||58.72.165.39^ ||59.0.211.161^ ||59.102.168.189^ -||59.126.26.220^ ||59.151.202.3^ ||59.151.214.4^ -||59.151.237.51^ -||59.151.246.125^ ||59.173.135.51^ ||59.175.63.177^ ||59.23.114.97^ ||59.26.181.228^ ||59.30.12.254^ -||59.60.117.163^ +||59.50.23.23^ +||59.89.242.116^ +||59.92.217.215^ +||59.92.218.82^ +||59.93.21.140^ +||59.93.21.172^ +||59.94.182.212^ +||59.95.175.49^ +||59.97.170.146^ ||60.13.61.12^ ||60.209.122.57^ ||60.209.216.23^ ||60.209.233.94^ ||60.211.6.112^ +||60.211.80.216^ ||60.212.100.83^ ||60.212.111.39^ ||60.212.206.246^ @@ -1813,31 +1824,30 @@ ||60.212.220.167^ ||60.212.254.178^ ||60.213.83.55^ +||60.214.53.159^ ||60.214.85.149^ ||60.217.177.196^ ||60.217.86.208^ -||60.220.159.240^ -||60.253.15.104^ -||60.253.39.88^ ||60.253.4.72^ ||60.253.51.127^ ||60.253.60.174^ ||60.253.8.81^ -||60.254.36.135^ ||60.7.10.121^ ||60.7.8.43^ ||61.146.108.150^ +||61.163.131.67^ ||61.179.91.194^ ||61.247.224.66^ +||61.3.150.101^ ||61.52.101.143^ +||61.52.186.186^ ||61.52.241.252^ ||61.52.57.40^ ||61.52.9.166^ +||61.52.97.68^ ||61.52.98.43^ ||61.52.99.161^ ||61.53.117.152^ -||61.53.249.58^ -||61.53.74.236^ ||61.54.103.56^ ||61.56.180.67^ ||61.56.181.7^ @@ -1869,7 +1879,6 @@ ||66.108.199.144^ ||66.57.55.210^ ||66.74.7.197^ -||66.91.21.31^ ||66.97.181.196^ ||67.245.151.203^ ||67.8.138.101^ @@ -1931,6 +1940,7 @@ ||74.64.139.223^ ||74.75.165.81^ ||75.127.141.52^ +||75.83.102.27^ ||75.99.213.61^ ||76.170.11.82^ ||76.178.22.145^ @@ -1940,14 +1950,12 @@ ||76.84.134.33^ ||76.89.107.69^ ||76.95.12.137^ -||77.111.182.31^ ||77.237.25.210^ ||77.71.50.153^ ||77.89.203.238^ ||77st.net^ ||78.138.98.134^ ||78.145.224.45^ -||78.187.141.144^ ||78.187.41.200^ ||78.188.106.235^ ||78.188.168.64^ @@ -1968,7 +1976,6 @@ ||80.107.89.207^ ||80.19.101.218^ ||80.211.181.77^ -||80.217.12.7^ ||80.99.128.61^ ||81.136.146.213^ ||81.165.44.109^ @@ -1985,7 +1992,6 @@ ||81.92.36.96^ ||82.103.108.72^ ||82.135.196.130^ -||82.166.212.178^ ||82.166.85.112^ ||82.207.61.194^ ||82.209.250.155^ @@ -2036,14 +2042,17 @@ ||85.105.208.25^ ||85.105.224.141^ ||85.105.241.2^ -||85.108.133.19^ ||85.214.149.236^ ||85.241.39.182^ +||85.250.147.134^ ||85.64.181.50^ ||85.74.215.180^ ||85.97.130.227^ ||86.35.43.220^ +||86.98.23.78^ +||87.117.11.46^ ||87.172.19.130^ +||87.251.71.78^ ||87du.vip^ ||88.119.171.253^ ||88.129.208.43^ @@ -2070,7 +2079,6 @@ ||8poieq.bn.files.1drv.com^ ||90.152.144.139^ ||91.132.197.39^ -||91.138.215.5^ ||91.177.139.132^ ||91.187.103.32^ ||91.212.150.241^ @@ -2085,6 +2093,7 @@ ||92.54.237.237^ ||92.83.62.139^ ||92.85.18.138^ +||93.157.63.221^ ||93.159.169.190^ ||93.173.235.110^ ||93.21.224.154^ @@ -2098,13 +2107,13 @@ ||94.136.69.199^ ||94.143.53.34^ ||94.154.17.170^ +||94.154.82.190^ ||94.200.16.22^ ||94.224.83.208^ ||94.53.120.109^ ||94.85.0.3^ ||95.132.129.250^ ||95.133.158.20^ -||95.154.20.231^ ||95.158.19.130^ ||95.170.113.227^ ||95.170.201.34^ @@ -2140,7 +2149,6 @@ ||adithimedia.com^ ||adithimedia.memengers.com^ ||admin.erapor.smk-alasror.net^ -||admin.gentbcn.org^ ||admin.grandoceanvilla.com^ ||admission.kmctartskuttippuram.org^ ||adventureexplorer.in^ @@ -2156,6 +2164,7 @@ ||aiqtest.com^ ||ajpharmaholding.com^ ||akdvidyalaya.com^ +||al-wahd.com^ ||alasdemariposas.org^ ||alberts.diamondrelationscrm.us^ ||alemelektronik.com^ @@ -2194,7 +2203,6 @@ ||artedibujoyarquitectura.com^ ||arwenyapi.com^ ||ask-regard.call-save.biz^ -||asucssa.live^ ||atfile.com^ ||athenacapsg.com^ ||atlasconcreteworks.com^ @@ -2206,15 +2214,17 @@ ||automaticrefreshments.com^ ||avadhanagames.com^ ||aventuramotorhome.com^ +||awumad01.top^ +||awuqze02.top^ ||ayahuascasp.com.br^ ||ayamallah.com^ -||aycconsultoriaempresarial.com^ ||azmeasurement.com^ ||azraktours.com^ ||b.r.uce.lee.b.es.t@zytrox.tk^ ||b2b.toptanakaryakit.com.tr^ ||backgrounds.pk^ ||badeggdesign.com^ +||bakamla.go.id^ ||balealgodon.mx^ ||bangkok-orchids.com^ ||bangladeshunbound.com^ @@ -2235,7 +2245,6 @@ ||bespokeweddings.ie^ ||bestcarenepal.com^ ||betone.co.kr^ -||betycopaints.com^ ||beveragesmiami.solucioneslink.com^ ||bhavaniengineering.com^ ||bigmikesupplies.co.za^ @@ -2291,12 +2300,12 @@ ||capitalgroup-kw.com^ ||capoeiraventrelivre.com^ ||cashyinvestment.org^ +||casiomaneflirt.cf^ ||catchpoolshetlands.co.uk^ ||cazyacustomfurniture.com^ ||cbn.hypervoizd.com^ ||ccauthority.net^ ||cdaonline.com.ar^ -||cdn-10049480.file.myqcloud.com^ ||cec.asso.ac-amiens.fr^ ||cellas.sk^ ||cendekiabinaaksara.com^ @@ -2310,17 +2319,17 @@ ||chinhdropfile80.myvnc.com^ ||cible-energy.com^ ||cifeer.net^ +||citiconstructioncorp.com^ ||citihits.lk^ ||citssolutions.co.za^ -||citycapproperty.ru^ ||cityglobalgospel.com^ ||civi.istmejia.com^ ||cleanbydesignllc.com^ ||cloud.fc.co.mz^ ||cnc.tacobelllover.tk^ ||codsambal.com^ -||colinde.pricesne.com^ ||colorpak.pl^ +||columbia.aula-web.net^ ||community.reimclub.com^ ||competancy.indigoconsult.net^ ||conceptimagine.ro^ @@ -2330,9 +2339,11 @@ ||consulateins.solucioneslink.com^ ||contributeindustry.com^ ||copelandscapes.com^ +||corwin-tommie06f.ru.com^ ||coulsongraphics.com^ ||count.mail.163.com.impactmedfoundation.com^ ||covid19.cyberschool.or.id^ +||covid19vaccinations.hopto.org^ ||cr-sq.com^ ||craftech.nxtnet.ga^ ||crearechile.cl^ @@ -2395,6 +2406,7 @@ ||dl.198424.com^ ||dl.installcdn-aws.com^ ||dl.packetstormsecurity.net^ +||dl.pandasecur.com^ ||dl.rina-roleplay.com^ ||dnn.alibuf.com^ ||dns.alibuf.com^ @@ -2451,11 +2463,11 @@ ||ennovate.elin.co.za^ ||equimination.ee^ ||erp.nanotechproautocare.com^ +||esaja09.top^ ||escola.probommar.org.br^ ||eservices.immigration.gov.lk^ ||esnconsultants.com^ ||essentia.org.br^ -||ethereality.info^ ||eubanks7.com^ ||europeanzonexxi.com^ ||exilum.com^ @@ -2473,7 +2485,7 @@ ||fisconline.bar^ ||fisconline.casa^ ||fix-america-now.org^ -||fixauto.illumetechnology.com^ +||fkd.derpcity.ru^ ||flexypay.dsquaregroup.com^ ||flintspin.com^ ||flyingbuddhadesign.com^ @@ -2494,7 +2506,6 @@ ||futbolpr.com^ ||futuregraphics.com.ar^ ||g.pinmonkey.xyz^ -||gaditastour.com^ ||gametwogame.com^ ||garciadogshow.com^ ||garenanow.myvnc.com^ @@ -2524,7 +2535,6 @@ ||goldmen.in^ ||gpotecnosystems.com^ ||gracejukes.com^ -||greataccesstoserver.com^ ||grupoinmare.com^ ||gruposelt.000webhostapp.com^ ||gs.monerorx.com^ @@ -2555,17 +2565,13 @@ ||hmpmall.co.kr^ ||hoagietesting10.com^ ||hoayeuthuong-my.sharepoint.com^ -||holmesservices.mobiledevsite.co^ ||homefindersolutions.com^ ||hometownchick.com^ -||hongluosi.com^ ||hookedupboatclub.com^ ||hostingparacolombia.com^ ||hostzaa.com^ -||houstonshutters.site^ ||hr2019.vrcom7.com^ ||hseda.com^ -||hsmwebapp.com^ ||htownbars.com^ ||hubtech.co.za^ ||huellacero.cl^ @@ -2613,6 +2619,8 @@ ||it123.ru^ ||italiandirezione.casa^ ||itc-demo.softgig.co.ke^ +||itsrlytry.000webhostapp.com^ +||jaishomo.info^ ||jamiekaylive.com^ ||jamshed.pk^ ||jansen-heesch.nl^ @@ -2640,11 +2648,11 @@ ||kaptaanchapal.com^ ||karer.by^ ||katanvetov.co.il^ +||katelynn9506a.ru.com^ ||kensingtondriving.com^ ||ketofitnessexpert.com^ ||kevinjewelry.com.co^ ||keywatch.yourpageserver.com^ -||kihn-delaney30gn.ru.com^ ||kingssa.co.za^ ||kjcpromo.com^ ||kleinendeli.co.za^ @@ -2652,7 +2660,6 @@ ||krisbadminton.com^ ||ktb.sch.id^ ||kubatoglubaklava.com.tr^ -||kullumanalitours.com^ ||kumaralok.in^ ||kwanfromhongkong.com^ ||kz.sldov.ru^ @@ -2709,7 +2716,6 @@ ||maksi.feb.unib.ac.id^ ||malaya.tv^ ||malwarecoding.github.io^ -||managed.oss-cn-beijing.aliyuncs.com^ ||managemysalon.in^ ||manantialesdelnorte.uy^ ||manhtien.net^ @@ -2752,6 +2758,7 @@ ||microblading.mirliandias.com.br^ ||microcomm-group.com^ ||mikhailmotoringschool.com^ +||mills-skyla30ec.com^ ||mingguanwms.com^ ||minuevavida.org^ ||mirror.mypage.sk^ @@ -2768,6 +2775,7 @@ ||moninediy.com^ ||moreirawag.ac.ug^ ||motorcomunicacion.com^ +||moumitas.com^ ||msacontabil.com.br^ ||mumgee.co.za^ ||muzimbiti.xigubo.co.mz^ @@ -2817,6 +2825,7 @@ ||nyeh2o.com.au^ ||obseques-conseils.com^ ||oecteam.com^ +||ohe.ie^ ||ohsewgorgeous.co.uk^ ||oleholeh.memangbeda.website^ ||omaia.org^ @@ -2827,7 +2836,6 @@ ||onedigitalcard.granvizionnecorp.com^ ||onedrive.listifyapp.co^ ||online.creedglobal.in^ -||open.rawntech.com^ ||open.warehousesaas.co.uk^ ||opolis.io^ ||optimus.com.sg^ @@ -2902,6 +2910,7 @@ ||pujashoppe.in^ ||punchdialogues.com^ ||punjabdevelopersassociation.com.pk^ +||pvcprinting.co.uk^ ||qadir.tickfa.ir^ ||qatarglobalconsulting.com^ ||qmsled.com^ @@ -2928,16 +2937,15 @@ ||readymmade.com^ ||recyclethesurplus.com^ ||redbats.co.in^ +||redboxmultimedia.com^ ||redchillicrackers.com^ ||reifenquick.de^ -||relaxindulge.co.nz^ ||renehavis.com.ua^ ||repatriacioncolombia.com^ ||res.uf1.cn^ ||reseller.digimitra.in^ ||reseller.itechbrasil.com^ ||resuco.net^ -||revolet-sa.com^ ||rezkabum.ru^ ||rhema.com.sg^ ||richmondminerals.co.zm^ @@ -2952,6 +2960,7 @@ ||ronnietucker.co.uk^ ||roomsvc.servegate.kr^ ||roshnijewellery.com^ +||rotronics.com.ph^ ||rsgym.net^ ||rubazar.pro^ ||rubycityvietnam.com^ @@ -2981,6 +2990,7 @@ ||schoolbustracker.softgig.co.ke^ ||sculetus.nl^ ||secure-doc-reader.com^ +||secure.activedirect.xyz^ ||segalsmetals.elin.co.za^ ||sellmyphonela.com^ ||selltechtoday.com^ @@ -2990,7 +3000,9 @@ ||sericaasia.com^ ||servicemhkd.myvnc.com^ ||servicemhkd80.myvnc.com^ +||serviciovirtual.com.ar^ ||sexologistpakistan.net^ +||sgb.ac.ke^ ||sgessy.com.br^ ||shaheentbfoundation.com^ ||shahikhana.cstdevs.com^ @@ -3028,7 +3040,6 @@ ||sobethuacademy.com^ ||soft.110route.com^ ||soft.officelabo.net^ -||sogecoenergy.com^ ||sohs.conceptechs.info^ ||solar.amazingtribe.lk^ ||somcorbera.cat^ @@ -3042,7 +3053,6 @@ ||spetsesyachtcharter.gr^ ||spititourism.com^ ||spittinfire.com^ -||springbedspetroleum.com^ ||src1.minibai.com^ ||sreenivasapaintingworks.com^ ||sriglobalit.com^ @@ -3053,16 +3063,23 @@ ||staging.apparelpunch.com^ ||starcountry.net^ ||static.3001.net^ +||stdynbnbnewagedevixz.dns.army^ +||stdynmxwllminoragest.dns.army^ +||stdyunitedkesokokgst.dns.army^ +||stdyworkfinetraingst.dns.army^ +||stdyzgchgcloudgostxs.dns.army^ ||stiau.iuc.ac^ ||sticker.jewsjuice.com^ ||stiepancasetia.ac.id^ ||stlukesohag.com^ ||store.ericalgarin.com^ ||stott-thompson.co.uk^ +||stratexec.co.za^ ||streetdemo.yourpageserver.com^ ||suboldesign.com^ ||sumerians.org^ ||sunaryem.com.tr^ +||sunbrero.com.au^ ||sunmarkholidays.com^ ||support-4-free.com^ ||support.clz.kr^ @@ -3141,7 +3158,6 @@ ||toplevel.com.br^ ||topmask.co.za^ ||torresquinterocorp.com^ -||towme.services^ ||toyotacollege.ac.th^ ||tpke.hu^ ||translaterjemah.com^ @@ -3168,7 +3184,6 @@ ||unyazitelecom.com^ ||up.llw0.com^ ||upcbpta.com^ -||used-jeans.fr^ ||useformoney.000webhostapp.com^ ||uss.ac.th^ ||uzzepay.com.br^ @@ -3177,7 +3192,6 @@ ||vcah.co.uk^ ||vectarts.com^ ||vegadelcasero.cl^ -||velma-harber30ku.com^ ||vendas.lidiacarmeli.com.br^ ||veterinariadrpopui.com^ ||vfocus.net^ @@ -3193,7 +3207,6 @@ ||viveirodoiscorregos.com.br^ ||vksales.com^ ||vocalterra.com^ -||vokasi.ub.ac.id^ ||vologroup.com.br^ ||voteyouramerica.dekitout.com^ ||vpts.co.za^ @@ -3214,6 +3227,7 @@ ||weinsteincounseling.com^ ||wfinance.com.br^ ||whcms.yourpageserver.com^ +||whiteglovetailgate.com^ ||whiteresponse.com^ ||wi522012.ferozo.com^ ||wikalen.co.za^ @@ -3243,6 +3257,7 @@ ||yeq.i.u.j.ia.n.3@zytrox.tk^ ||ylfpremium.com^ ||yoast.yourpageserver.com^ +||yp.hnggzyjy.cn^ ||yummyyogaudaipur.com^ ||yzkzixun.com^ ||ziyker4gaming@zytrox.tk^ diff --git a/urlhaus-filter-agh.txt b/urlhaus-filter-agh.txt index 847c5c34..46698074 100644 --- a/urlhaus-filter-agh.txt +++ b/urlhaus-filter-agh.txt @@ -1,5 +1,5 @@ ! Title: Malicious URL Blocklist (AdGuard Home) -! Updated: Mon, 12 Apr 2021 00:12:54 UTC +! Updated: Mon, 12 Apr 2021 12:13:00 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -1391,6 +1391,7 @@ ||101.0.34.225^ ||101.0.34.229^ ||101.0.34.230^ +||101.0.34.236^ ||101.0.34.244^ ||101.0.34.247^ ||101.0.34.253^ @@ -1657,6 +1658,7 @@ ||101.108.131.81^ ||101.108.131.89^ ||101.108.131.92^ +||101.108.131.99^ ||101.108.132.0^ ||101.108.132.109^ ||101.108.132.110^ @@ -1808,6 +1810,7 @@ ||101.108.137.77^ ||101.108.138.108^ ||101.108.138.109^ +||101.108.138.150^ ||101.108.138.155^ ||101.108.138.160^ ||101.108.138.174^ @@ -6073,6 +6076,7 @@ ||103.91.245.45^ ||103.91.245.46^ ||103.91.245.47^ +||103.91.245.48^ ||103.91.245.49^ ||103.91.245.54^ ||103.91.245.55^ @@ -8785,6 +8789,7 @@ ||107.172.153.90^ ||107.172.156.122^ ||107.172.156.153^ +||107.172.156.3^ ||107.172.157.125^ ||107.172.157.131^ ||107.172.157.176^ @@ -12195,6 +12200,7 @@ ||111.92.81.107^ ||111.92.81.109^ ||111.92.81.111^ +||111.92.81.112^ ||111.92.81.113^ ||111.92.81.116^ ||111.92.81.118^ @@ -17651,6 +17657,7 @@ ||112.248.108.109^ ||112.248.108.182^ ||112.248.108.18^ +||112.248.109.156^ ||112.248.109.95^ ||112.248.11.123^ ||112.248.110.120^ @@ -20361,6 +20368,7 @@ ||112.9.149.240^ ||112.9.153.32^ ||112.9.154.61^ +||112.9.155.122^ ||112.9.157.102^ ||112.9.158.247^ ||112.9.160.95^ @@ -23894,6 +23902,7 @@ ||113.194.131.162^ ||113.194.131.197^ ||113.194.131.210^ +||113.194.131.72^ ||113.194.132.207^ ||113.194.132.253^ ||113.194.132.44^ @@ -23908,6 +23917,7 @@ ||113.194.133.9^ ||113.194.134.64^ ||113.194.135.154^ +||113.194.135.223^ ||113.194.135.230^ ||113.194.135.238^ ||113.194.135.63^ @@ -26565,6 +26575,7 @@ ||113.88.122.63^ ||113.88.122.78^ ||113.88.123.145^ +||113.88.123.22^ ||113.88.123.235^ ||113.88.124.109^ ||113.88.124.119^ @@ -26936,6 +26947,7 @@ ||113.88.211.95^ ||113.88.224.159^ ||113.88.228.13^ +||113.88.228.152^ ||113.88.228.16^ ||113.88.228.211^ ||113.88.228.73^ @@ -27190,6 +27202,7 @@ ||113.88.65.37^ ||113.88.65.38^ ||113.88.65.48^ +||113.88.65.49^ ||113.88.65.54^ ||113.88.65.80^ ||113.88.66.213^ @@ -27396,6 +27409,7 @@ ||113.89.247.90^ ||113.89.248.112^ ||113.89.248.181^ +||113.89.4.189^ ||113.89.4.201^ ||113.89.4.74^ ||113.89.4.7^ @@ -27663,6 +27677,7 @@ ||113.9.241.101^ ||113.9.29.128^ ||113.9.94.126^ +||113.90.133.38^ ||113.90.135.225^ ||113.90.135.231^ ||113.90.160.138^ @@ -28334,6 +28349,7 @@ ||114.223.238.75^ ||114.223.244.108^ ||114.223.28.254^ +||114.223.43.7^ ||114.223.48.158^ ||114.223.61.204^ ||114.223.63.197^ @@ -29092,6 +29108,7 @@ ||114.235.211.48^ ||114.235.211.60^ ||114.235.211.88^ +||114.235.213.31^ ||114.235.22.32^ ||114.235.222.230^ ||114.235.222.245^ @@ -30061,6 +30078,7 @@ ||114.97.224.73^ ||114.97.225.120^ ||114tv.cc^ +||115.110.193.166^ ||115.120.136.248^ ||115.120.204.211^ ||115.127.96.194^ @@ -34705,6 +34723,7 @@ ||115.49.232.129^ ||115.49.232.177^ ||115.49.232.185^ +||115.49.232.197^ ||115.49.232.204^ ||115.49.232.20^ ||115.49.232.210^ @@ -37077,6 +37096,7 @@ ||115.50.172.21^ ||115.50.172.223^ ||115.50.172.225^ +||115.50.172.22^ ||115.50.172.236^ ||115.50.172.33^ ||115.50.172.43^ @@ -37428,6 +37448,7 @@ ||115.50.2.128^ ||115.50.2.132^ ||115.50.2.141^ +||115.50.2.148^ ||115.50.2.149^ ||115.50.2.159^ ||115.50.2.179^ @@ -42351,6 +42372,7 @@ ||115.51.91.62^ ||115.51.91.66^ ||115.51.91.70^ +||115.51.91.81^ ||115.51.91.98^ ||115.51.92.114^ ||115.51.92.115^ @@ -45314,6 +45336,7 @@ ||115.54.212.149^ ||115.54.212.163^ ||115.54.212.173^ +||115.54.212.175^ ||115.54.212.17^ ||115.54.212.180^ ||115.54.212.183^ @@ -49425,6 +49448,7 @@ ||115.55.7.55^ ||115.55.7.60^ ||115.55.7.92^ +||115.55.7.9^ ||115.55.70.113^ ||115.55.71.231^ ||115.55.72.105^ @@ -57123,6 +57147,7 @@ ||115.59.248.228^ ||115.59.25.113^ ||115.59.25.169^ +||115.59.250.37^ ||115.59.250.52^ ||115.59.252.114^ ||115.59.252.120^ @@ -59306,6 +59331,7 @@ ||115.61.167.185^ ||115.61.167.196^ ||115.61.167.207^ +||115.61.167.21^ ||115.61.167.225^ ||115.61.167.227^ ||115.61.167.230^ @@ -59814,6 +59840,7 @@ ||115.61.186.106^ ||115.61.186.114^ ||115.61.186.11^ +||115.61.186.139^ ||115.61.186.144^ ||115.61.186.153^ ||115.61.186.158^ @@ -60695,6 +60722,7 @@ ||115.62.171.71^ ||115.62.171.81^ ||115.62.172.135^ +||115.62.172.140^ ||115.62.172.145^ ||115.62.172.173^ ||115.62.172.200^ @@ -60753,6 +60781,7 @@ ||115.62.25.100^ ||115.62.26.100^ ||115.62.26.102^ +||115.62.26.113^ ||115.62.26.114^ ||115.62.26.120^ ||115.62.26.123^ @@ -66692,6 +66721,7 @@ ||115.96.199.129^ ||115.96.199.132^ ||115.96.199.138^ +||115.96.199.146^ ||115.96.199.160^ ||115.96.199.163^ ||115.96.199.165^ @@ -91491,6 +91521,7 @@ ||116.106.77.111^ ||116.108.32.244^ ||116.108.71.196^ +||116.108.92.154^ ||116.109.108.32^ ||116.109.132.2^ ||116.109.156.14^ @@ -93311,6 +93342,7 @@ ||116.68.96.97^ ||116.68.96.98^ ||116.68.96.99^ +||116.68.97.100^ ||116.68.97.102^ ||116.68.97.104^ ||116.68.97.117^ @@ -93430,6 +93462,7 @@ ||116.68.99.129^ ||116.68.99.132^ ||116.68.99.139^ +||116.68.99.152^ ||116.68.99.155^ ||116.68.99.158^ ||116.68.99.159^ @@ -114175,6 +114208,7 @@ ||117.194.162.126^ ||117.194.162.128^ ||117.194.162.129^ +||117.194.162.12^ ||117.194.162.132^ ||117.194.162.134^ ||117.194.162.135^ @@ -116157,6 +116191,7 @@ ||117.201.197.124^ ||117.201.199.181^ ||117.201.199.230^ +||117.201.200.106^ ||117.201.200.236^ ||117.201.201.33^ ||117.201.202.154^ @@ -119705,6 +119740,7 @@ ||117.213.12.130^ ||117.213.12.148^ ||117.213.12.158^ +||117.213.12.177^ ||117.213.12.208^ ||117.213.12.218^ ||117.213.12.219^ @@ -121202,6 +121238,7 @@ ||117.213.9.177^ ||117.213.9.1^ ||117.213.9.203^ +||117.213.9.42^ ||117.213.9.58^ ||117.213.9.71^ ||117.213.9.77^ @@ -121558,6 +121595,7 @@ ||117.215.249.174^ ||117.215.249.175^ ||117.215.249.181^ +||117.215.249.196^ ||117.215.249.197^ ||117.215.249.199^ ||117.215.249.20^ @@ -121570,6 +121608,7 @@ ||117.215.249.241^ ||117.215.249.242^ ||117.215.249.245^ +||117.215.249.250^ ||117.215.249.251^ ||117.215.249.255^ ||117.215.249.27^ @@ -124070,6 +124109,7 @@ ||117.222.175.122^ ||117.222.175.12^ ||117.222.175.130^ +||117.222.175.134^ ||117.222.175.135^ ||117.222.175.136^ ||117.222.175.138^ @@ -126038,6 +126078,7 @@ ||117.247.201.42^ ||117.247.201.43^ ||117.247.201.44^ +||117.247.201.45^ ||117.247.201.47^ ||117.247.201.49^ ||117.247.201.4^ @@ -128763,6 +128804,7 @@ ||117.63.124.134^ ||117.63.127.23^ ||117.63.130.19^ +||117.63.133.251^ ||117.63.151.77^ ||117.63.156.234^ ||117.63.157.34^ @@ -130763,6 +130805,7 @@ ||118.79.112.110^ ||118.79.112.230^ ||118.79.112.54^ +||118.79.113.239^ ||118.79.113.7^ ||118.79.114.198^ ||118.79.114.78^ @@ -137071,6 +137114,7 @@ ||119.99.251.129^ ||119.99.30.19^ ||119.99.50.91^ +||119.99.52.69^ ||119.99.63.42^ ||11bybbsny.com^ ||11degrees.org^ @@ -145675,6 +145719,7 @@ ||123.10.32.196^ ||123.10.32.200^ ||123.10.32.239^ +||123.10.32.252^ ||123.10.32.87^ ||123.10.32.95^ ||123.10.33.112^ @@ -153465,6 +153510,7 @@ ||123.14.95.219^ ||123.14.95.248^ ||123.14.95.24^ +||123.14.95.26^ ||123.14.96.154^ ||123.14.96.157^ ||123.14.96.209^ @@ -155847,6 +155893,7 @@ ||123.4.242.152^ ||123.4.242.163^ ||123.4.242.199^ +||123.4.242.19^ ||123.4.242.204^ ||123.4.242.210^ ||123.4.242.218^ @@ -156235,6 +156282,7 @@ ||123.4.47.248^ ||123.4.47.25^ ||123.4.47.32^ +||123.4.47.57^ ||123.4.48.128^ ||123.4.48.40^ ||123.4.48.70^ @@ -159049,6 +159097,7 @@ ||123.5.188.8^ ||123.5.188.93^ ||123.5.188.97^ +||123.5.188.9^ ||123.5.189.101^ ||123.5.189.107^ ||123.5.189.113^ @@ -159064,6 +159113,7 @@ ||123.5.189.151^ ||123.5.189.154^ ||123.5.189.155^ +||123.5.189.15^ ||123.5.189.161^ ||123.5.189.164^ ||123.5.189.184^ @@ -161243,6 +161293,7 @@ ||123.9.117.236^ ||123.9.117.245^ ||123.9.118.130^ +||123.9.118.183^ ||123.9.118.79^ ||123.9.119.209^ ||123.9.119.47^ @@ -162411,6 +162462,7 @@ ||123.9.35.198^ ||123.9.35.6^ ||123.9.35.88^ +||123.9.36.120^ ||123.9.36.188^ ||123.9.36.222^ ||123.9.36.6^ @@ -168258,6 +168310,7 @@ ||125.41.14.213^ ||125.41.14.219^ ||125.41.14.220^ +||125.41.14.228^ ||125.41.14.22^ ||125.41.14.232^ ||125.41.14.235^ @@ -188676,6 +188729,7 @@ ||143.198.220.102^ ||143.198.48.37^ ||143.198.54.180^ +||143.198.54.233^ ||143.198.63.143^ ||143.198.65.195^ ||143.198.65.229^ @@ -188942,6 +188996,7 @@ ||149.255.15.134^ ||149.255.15.138^ ||149.255.15.143^ +||149.255.15.170^ ||149.255.15.172^ ||149.255.15.180^ ||149.255.15.182^ @@ -188950,8 +189005,10 @@ ||149.255.15.213^ ||149.255.15.235^ ||149.255.15.27^ +||149.255.15.29^ ||149.255.15.38^ ||149.255.15.43^ +||149.255.15.44^ ||149.255.15.87^ ||149.255.15.99^ ||149.255.36.133^ @@ -190154,6 +190211,7 @@ ||157.90.24.103^ ||157.90.244.110^ ||157.90.244.177^ +||157.90.8.28^ ||157.97.133.128^ ||157.97.17.46^ ||157.97.2.215^ @@ -191386,6 +191444,7 @@ ||162.244.81.158^ ||162.244.81.204^ ||162.244.81.55^ +||162.245.221.121^ ||162.246.15.229^ ||162.246.20.117^ ||162.246.20.236^ @@ -203053,6 +203112,7 @@ ||178.175.10.224^ ||178.175.10.240^ ||178.175.10.244^ +||178.175.10.247^ ||178.175.10.248^ ||178.175.10.251^ ||178.175.10.254^ @@ -203084,6 +203144,7 @@ ||178.175.10.98^ ||178.175.10.99^ ||178.175.100.101^ +||178.175.100.104^ ||178.175.100.106^ ||178.175.100.109^ ||178.175.100.110^ @@ -203232,6 +203293,7 @@ ||178.175.101.209^ ||178.175.101.210^ ||178.175.101.211^ +||178.175.101.212^ ||178.175.101.213^ ||178.175.101.217^ ||178.175.101.219^ @@ -203335,6 +203397,7 @@ ||178.175.102.17^ ||178.175.102.183^ ||178.175.102.184^ +||178.175.102.186^ ||178.175.102.188^ ||178.175.102.189^ ||178.175.102.190^ @@ -203510,6 +203573,7 @@ ||178.175.104.110^ ||178.175.104.112^ ||178.175.104.114^ +||178.175.104.115^ ||178.175.104.116^ ||178.175.104.11^ ||178.175.104.120^ @@ -203857,6 +203921,7 @@ ||178.175.107.124^ ||178.175.107.127^ ||178.175.107.133^ +||178.175.107.135^ ||178.175.107.136^ ||178.175.107.138^ ||178.175.107.13^ @@ -204182,6 +204247,7 @@ ||178.175.109.98^ ||178.175.109.9^ ||178.175.11.0^ +||178.175.11.100^ ||178.175.11.101^ ||178.175.11.104^ ||178.175.11.105^ @@ -204608,6 +204674,7 @@ ||178.175.112.81^ ||178.175.112.85^ ||178.175.112.86^ +||178.175.112.87^ ||178.175.112.89^ ||178.175.112.8^ ||178.175.112.90^ @@ -205640,6 +205707,7 @@ ||178.175.121.117^ ||178.175.121.122^ ||178.175.121.123^ +||178.175.121.125^ ||178.175.121.129^ ||178.175.121.12^ ||178.175.121.130^ @@ -206298,6 +206366,7 @@ ||178.175.126.38^ ||178.175.126.3^ ||178.175.126.41^ +||178.175.126.43^ ||178.175.126.44^ ||178.175.126.46^ ||178.175.126.48^ @@ -206492,6 +206561,7 @@ ||178.175.13.212^ ||178.175.13.213^ ||178.175.13.216^ +||178.175.13.219^ ||178.175.13.21^ ||178.175.13.220^ ||178.175.13.221^ @@ -206596,6 +206666,7 @@ ||178.175.14.25^ ||178.175.14.27^ ||178.175.14.28^ +||178.175.14.29^ ||178.175.14.2^ ||178.175.14.32^ ||178.175.14.33^ @@ -206664,6 +206735,7 @@ ||178.175.15.190^ ||178.175.15.194^ ||178.175.15.195^ +||178.175.15.196^ ||178.175.15.197^ ||178.175.15.198^ ||178.175.15.199^ @@ -206982,6 +207054,7 @@ ||178.175.18.253^ ||178.175.18.27^ ||178.175.18.2^ +||178.175.18.31^ ||178.175.18.32^ ||178.175.18.36^ ||178.175.18.37^ @@ -207169,6 +207242,7 @@ ||178.175.2.236^ ||178.175.2.237^ ||178.175.2.238^ +||178.175.2.23^ ||178.175.2.242^ ||178.175.2.243^ ||178.175.2.244^ @@ -207442,6 +207516,7 @@ ||178.175.22.187^ ||178.175.22.188^ ||178.175.22.194^ +||178.175.22.198^ ||178.175.22.1^ ||178.175.22.203^ ||178.175.22.206^ @@ -207485,6 +207560,7 @@ ||178.175.22.69^ ||178.175.22.6^ ||178.175.22.72^ +||178.175.22.74^ ||178.175.22.75^ ||178.175.22.78^ ||178.175.22.83^ @@ -207720,6 +207796,7 @@ ||178.175.25.155^ ||178.175.25.156^ ||178.175.25.159^ +||178.175.25.162^ ||178.175.25.163^ ||178.175.25.164^ ||178.175.25.166^ @@ -207984,6 +208061,7 @@ ||178.175.27.252^ ||178.175.27.253^ ||178.175.27.25^ +||178.175.27.26^ ||178.175.27.30^ ||178.175.27.32^ ||178.175.27.34^ @@ -207992,6 +208070,7 @@ ||178.175.27.38^ ||178.175.27.39^ ||178.175.27.41^ +||178.175.27.43^ ||178.175.27.46^ ||178.175.27.47^ ||178.175.27.48^ @@ -208406,6 +208485,7 @@ ||178.175.30.81^ ||178.175.30.86^ ||178.175.30.8^ +||178.175.30.90^ ||178.175.30.91^ ||178.175.30.93^ ||178.175.30.96^ @@ -208682,6 +208762,7 @@ ||178.175.33.228^ ||178.175.33.22^ ||178.175.33.231^ +||178.175.33.233^ ||178.175.33.234^ ||178.175.33.236^ ||178.175.33.239^ @@ -209636,6 +209717,7 @@ ||178.175.41.224^ ||178.175.41.225^ ||178.175.41.229^ +||178.175.41.230^ ||178.175.41.231^ ||178.175.41.235^ ||178.175.41.237^ @@ -209993,6 +210075,7 @@ ||178.175.44.89^ ||178.175.44.8^ ||178.175.44.90^ +||178.175.44.93^ ||178.175.44.95^ ||178.175.44.96^ ||178.175.44.9^ @@ -210209,6 +210292,7 @@ ||178.175.46.55^ ||178.175.46.59^ ||178.175.46.5^ +||178.175.46.60^ ||178.175.46.61^ ||178.175.46.63^ ||178.175.46.65^ @@ -210238,6 +210322,7 @@ ||178.175.47.11^ ||178.175.47.122^ ||178.175.47.126^ +||178.175.47.127^ ||178.175.47.128^ ||178.175.47.12^ ||178.175.47.132^ @@ -210368,6 +210453,7 @@ ||178.175.48.161^ ||178.175.48.162^ ||178.175.48.163^ +||178.175.48.164^ ||178.175.48.168^ ||178.175.48.16^ ||178.175.48.172^ @@ -210581,6 +210667,7 @@ ||178.175.5.21^ ||178.175.5.221^ ||178.175.5.222^ +||178.175.5.223^ ||178.175.5.226^ ||178.175.5.227^ ||178.175.5.229^ @@ -210838,6 +210925,7 @@ ||178.175.52.109^ ||178.175.52.111^ ||178.175.52.112^ +||178.175.52.114^ ||178.175.52.115^ ||178.175.52.118^ ||178.175.52.119^ @@ -210897,6 +210985,7 @@ ||178.175.52.24^ ||178.175.52.250^ ||178.175.52.252^ +||178.175.52.255^ ||178.175.52.2^ ||178.175.52.31^ ||178.175.52.33^ @@ -211030,6 +211119,7 @@ ||178.175.53.83^ ||178.175.53.85^ ||178.175.53.86^ +||178.175.53.87^ ||178.175.53.8^ ||178.175.53.90^ ||178.175.53.94^ @@ -211133,6 +211223,7 @@ ||178.175.54.71^ ||178.175.54.72^ ||178.175.54.74^ +||178.175.54.78^ ||178.175.54.7^ ||178.175.54.80^ ||178.175.54.81^ @@ -211153,6 +211244,7 @@ ||178.175.55.113^ ||178.175.55.114^ ||178.175.55.117^ +||178.175.55.118^ ||178.175.55.119^ ||178.175.55.121^ ||178.175.55.125^ @@ -211362,6 +211454,7 @@ ||178.175.57.102^ ||178.175.57.103^ ||178.175.57.104^ +||178.175.57.105^ ||178.175.57.108^ ||178.175.57.10^ ||178.175.57.112^ @@ -211477,6 +211570,7 @@ ||178.175.58.126^ ||178.175.58.127^ ||178.175.58.12^ +||178.175.58.130^ ||178.175.58.133^ ||178.175.58.139^ ||178.175.58.141^ @@ -211503,6 +211597,7 @@ ||178.175.58.185^ ||178.175.58.188^ ||178.175.58.189^ +||178.175.58.18^ ||178.175.58.191^ ||178.175.58.192^ ||178.175.58.198^ @@ -211717,6 +211812,8 @@ ||178.175.6.195^ ||178.175.6.196^ ||178.175.6.198^ +||178.175.6.201^ +||178.175.6.203^ ||178.175.6.204^ ||178.175.6.205^ ||178.175.6.207^ @@ -211904,6 +212001,7 @@ ||178.175.61.209^ ||178.175.61.20^ ||178.175.61.210^ +||178.175.61.212^ ||178.175.61.214^ ||178.175.61.217^ ||178.175.61.219^ @@ -211970,6 +212068,7 @@ ||178.175.62.122^ ||178.175.62.123^ ||178.175.62.128^ +||178.175.62.130^ ||178.175.62.134^ ||178.175.62.137^ ||178.175.62.141^ @@ -212632,6 +212731,7 @@ ||178.175.68.161^ ||178.175.68.162^ ||178.175.68.164^ +||178.175.68.165^ ||178.175.68.166^ ||178.175.68.167^ ||178.175.68.170^ @@ -213265,6 +213365,7 @@ ||178.175.72.53^ ||178.175.72.54^ ||178.175.72.56^ +||178.175.72.58^ ||178.175.72.61^ ||178.175.72.65^ ||178.175.72.69^ @@ -213661,6 +213762,7 @@ ||178.175.76.27^ ||178.175.76.29^ ||178.175.76.33^ +||178.175.76.34^ ||178.175.76.36^ ||178.175.76.37^ ||178.175.76.43^ @@ -213945,6 +214047,7 @@ ||178.175.79.247^ ||178.175.79.24^ ||178.175.79.253^ +||178.175.79.27^ ||178.175.79.30^ ||178.175.79.31^ ||178.175.79.38^ @@ -214420,6 +214523,7 @@ ||178.175.83.15^ ||178.175.83.167^ ||178.175.83.176^ +||178.175.83.17^ ||178.175.83.180^ ||178.175.83.184^ ||178.175.83.185^ @@ -214686,6 +214790,7 @@ ||178.175.85.230^ ||178.175.85.231^ ||178.175.85.234^ +||178.175.85.235^ ||178.175.85.23^ ||178.175.85.242^ ||178.175.85.243^ @@ -215519,6 +215624,7 @@ ||178.175.92.20^ ||178.175.92.210^ ||178.175.92.211^ +||178.175.92.213^ ||178.175.92.214^ ||178.175.92.215^ ||178.175.92.218^ @@ -215629,6 +215735,7 @@ ||178.175.93.200^ ||178.175.93.202^ ||178.175.93.203^ +||178.175.93.204^ ||178.175.93.205^ ||178.175.93.207^ ||178.175.93.210^ @@ -215915,6 +216022,7 @@ ||178.175.95.7^ ||178.175.95.80^ ||178.175.95.82^ +||178.175.95.83^ ||178.175.95.85^ ||178.175.95.86^ ||178.175.95.88^ @@ -218514,6 +218622,7 @@ ||180.177.104.65^ ||180.177.180.6^ ||180.177.242.73^ +||180.177.5.36^ ||180.177.76.161^ ||180.177.80.11^ ||180.178.104.86^ @@ -218621,7 +218730,9 @@ ||180.188.241.91^ ||180.188.241.99^ ||180.188.247.140^ +||180.188.247.172^ ||180.188.247.181^ +||180.188.247.218^ ||180.188.247.26^ ||180.188.252.185^ ||180.188.252.37^ @@ -222738,6 +222849,7 @@ ||182.113.4.209^ ||182.113.4.223^ ||182.113.4.226^ +||182.113.4.247^ ||182.113.4.64^ ||182.113.4.68^ ||182.113.4.88^ @@ -223708,6 +223820,7 @@ ||182.114.193.2^ ||182.114.193.70^ ||182.114.194.116^ +||182.114.194.183^ ||182.114.194.184^ ||182.114.194.206^ ||182.114.194.210^ @@ -235184,6 +235297,7 @@ ||182.119.23.6^ ||182.119.23.70^ ||182.119.23.74^ +||182.119.23.75^ ||182.119.23.90^ ||182.119.23.91^ ||182.119.23.9^ @@ -235629,6 +235743,7 @@ ||182.119.48.200^ ||182.119.48.205^ ||182.119.48.217^ +||182.119.48.230^ ||182.119.48.242^ ||182.119.48.250^ ||182.119.48.255^ @@ -238499,6 +238614,7 @@ ||182.121.123.0^ ||182.121.123.122^ ||182.121.123.124^ +||182.121.123.134^ ||182.121.123.141^ ||182.121.123.142^ ||182.121.123.16^ @@ -239952,6 +240068,7 @@ ||182.121.200.115^ ||182.121.200.119^ ||182.121.200.127^ +||182.121.200.137^ ||182.121.200.143^ ||182.121.200.151^ ||182.121.200.161^ @@ -240144,6 +240261,7 @@ ||182.121.205.223^ ||182.121.205.228^ ||182.121.205.237^ +||182.121.205.246^ ||182.121.205.251^ ||182.121.205.39^ ||182.121.205.47^ @@ -246639,6 +246757,7 @@ ||182.126.109.133^ ||182.126.109.146^ ||182.126.109.150^ +||182.126.109.194^ ||182.126.109.20^ ||182.126.109.255^ ||182.126.109.25^ @@ -247403,6 +247522,7 @@ ||182.126.126.14^ ||182.126.126.150^ ||182.126.126.161^ +||182.126.126.162^ ||182.126.126.16^ ||182.126.126.170^ ||182.126.126.176^ @@ -251634,6 +251754,7 @@ ||182.127.207.156^ ||182.127.207.158^ ||182.127.207.162^ +||182.127.207.187^ ||182.127.207.218^ ||182.127.207.226^ ||182.127.207.247^ @@ -252690,6 +252811,7 @@ ||182.127.80.184^ ||182.127.80.192^ ||182.127.80.229^ +||182.127.80.240^ ||182.127.80.85^ ||182.127.80.89^ ||182.127.81.114^ @@ -253354,6 +253476,7 @@ ||182.235.29.89^ ||182.236.124.160^ ||182.239.129.154^ +||182.240.132.164^ ||182.240.132.203^ ||182.240.213.4^ ||182.240.214.81^ @@ -255106,6 +255229,7 @@ ||182.57.105.110^ ||182.57.105.161^ ||182.57.105.167^ +||182.57.105.175^ ||182.57.106.118^ ||182.57.106.190^ ||182.57.106.237^ @@ -260593,6 +260717,7 @@ ||183.141.54.112^ ||183.141.55.239^ ||183.141.60.120^ +||183.141.61.174^ ||183.141.61.39^ ||183.142.11.225^ ||183.142.115.155^ @@ -261257,6 +261382,7 @@ ||183.17.227.102^ ||183.17.227.109^ ||183.17.227.113^ +||183.17.227.148^ ||183.17.227.162^ ||183.17.227.172^ ||183.17.227.187^ @@ -261816,6 +261942,7 @@ ||183.49.47.56^ ||183.49.85.243^ ||183.49.85.247^ +||183.49.86.54^ ||183.49.87.144^ ||183.49.87.220^ ||183.49.87.27^ @@ -261904,6 +262031,7 @@ ||183.83.103.117^ ||183.83.104.165^ ||183.83.104.44^ +||183.83.104.55^ ||183.83.104.68^ ||183.83.105.181^ ||183.83.105.21^ @@ -262495,6 +262623,7 @@ ||185.117.119.71^ ||185.117.155.20^ ||185.117.2.107^ +||185.117.21.212^ ||185.117.75.111^ ||185.117.75.201^ ||185.117.75.248^ @@ -262583,6 +262712,7 @@ ||185.132.53.161^ ||185.132.53.166^ ||185.132.53.167^ +||185.132.53.182^ ||185.132.53.185^ ||185.132.53.186^ ||185.132.53.191^ @@ -263778,6 +263908,7 @@ ||185.36.59.11^ ||185.36.59.76^ ||185.36.81.43^ +||185.38.142.194^ ||185.38.142.236^ ||185.39.11.105^ ||185.39.183.48^ @@ -265136,6 +265267,7 @@ ||186.33.105.7^ ||186.33.105.8^ ||186.33.105.9^ +||186.33.107.74^ ||186.33.112.100^ ||186.33.112.101^ ||186.33.112.102^ @@ -267386,9 +267518,11 @@ ||189.170.12.149^ ||189.170.178.180^ ||189.170.40.102^ +||189.171.22.132^ ||189.171.31.166^ ||189.172.151.237^ ||189.174.35.248^ +||189.175.214.112^ ||189.176.68.26^ ||189.176.93.82^ ||189.177.144.215^ @@ -270021,6 +270155,7 @@ ||192.99.169.15^ ||192.99.208.196^ ||192.99.214.32^ +||192.99.221.230^ ||192.99.240.77^ ||192.99.242.13^ ||192.99.246.11^ @@ -273489,6 +273624,7 @@ ||202.164.138.156^ ||202.164.138.157^ ||202.164.138.158^ +||202.164.138.159^ ||202.164.138.15^ ||202.164.138.160^ ||202.164.138.161^ @@ -273745,6 +273881,7 @@ ||202.164.139.25^ ||202.164.139.26^ ||202.164.139.28^ +||202.164.139.29^ ||202.164.139.2^ ||202.164.139.30^ ||202.164.139.31^ @@ -273764,6 +273901,7 @@ ||202.164.139.52^ ||202.164.139.55^ ||202.164.139.56^ +||202.164.139.57^ ||202.164.139.58^ ||202.164.139.60^ ||202.164.139.61^ @@ -277750,6 +277888,7 @@ ||206.189.129.96^ ||206.189.131.31^ ||206.189.132.42^ +||206.189.135.162^ ||206.189.135.253^ ||206.189.138.82^ ||206.189.140.181^ @@ -282396,6 +282535,7 @@ ||219.154.113.157^ ||219.154.113.161^ ||219.154.113.163^ +||219.154.113.171^ ||219.154.113.172^ ||219.154.113.177^ ||219.154.113.181^ @@ -284758,6 +284898,7 @@ ||219.155.226.188^ ||219.155.226.194^ ||219.155.226.198^ +||219.155.226.205^ ||219.155.226.225^ ||219.155.226.43^ ||219.155.226.50^ @@ -288010,6 +288151,7 @@ ||219.157.138.38^ ||219.157.138.63^ ||219.157.139.165^ +||219.157.14.239^ ||219.157.14.85^ ||219.157.140.190^ ||219.157.140.255^ @@ -288472,6 +288614,7 @@ ||219.157.178.171^ ||219.157.178.179^ ||219.157.178.192^ +||219.157.178.196^ ||219.157.178.201^ ||219.157.178.205^ ||219.157.178.210^ @@ -290645,6 +290788,7 @@ ||219.157.48.51^ ||219.157.48.58^ ||219.157.48.59^ +||219.157.48.5^ ||219.157.48.6^ ||219.157.48.70^ ||219.157.48.72^ @@ -293802,6 +293946,7 @@ ||221.14.47.162^ ||221.14.47.182^ ||221.14.47.189^ +||221.14.47.204^ ||221.14.47.225^ ||221.14.47.46^ ||221.14.47.77^ @@ -295218,6 +295363,7 @@ ||221.15.182.29^ ||221.15.182.40^ ||221.15.182.48^ +||221.15.182.72^ ||221.15.182.94^ ||221.15.182.9^ ||221.15.183.104^ @@ -296761,6 +296907,7 @@ ||221.15.53.25^ ||221.15.53.42^ ||221.15.53.46^ +||221.15.53.55^ ||221.15.53.57^ ||221.15.53.62^ ||221.15.53.74^ @@ -307383,6 +307530,7 @@ ||222.140.163.159^ ||222.140.163.15^ ||222.140.163.179^ +||222.140.163.181^ ||222.140.163.184^ ||222.140.163.188^ ||222.140.163.208^ @@ -312527,6 +312675,7 @@ ||23.95.116.135^ ||23.95.116.144^ ||23.95.122.24^ +||23.95.122.25^ ||23.95.122.47^ ||23.95.13.131^ ||23.95.13.158^ @@ -322752,6 +322901,7 @@ ||27.40.71.3^ ||27.40.72.200^ ||27.40.73.175^ +||27.40.79.170^ ||27.40.79.70^ ||27.40.82.129^ ||27.40.82.201^ @@ -347111,6 +347261,7 @@ ||31.168.126.45^ ||31.168.146.199^ ||31.168.153.60^ +||31.168.16.68^ ||31.168.177.37^ ||31.168.178.71^ ||31.168.179.83^ @@ -356073,6 +356224,7 @@ ||41.143.247.190^ ||41.143.31.149^ ||41.143.57.149^ +||41.143.69.12^ ||41.144.143.214^ ||41.144.159.85^ ||41.146.243.74^ @@ -358334,6 +358486,7 @@ ||42.224.171.138^ ||42.224.171.162^ ||42.224.171.163^ +||42.224.171.165^ ||42.224.171.168^ ||42.224.171.193^ ||42.224.171.196^ @@ -360119,6 +360272,7 @@ ||42.224.254.199^ ||42.224.254.205^ ||42.224.254.207^ +||42.224.254.220^ ||42.224.254.224^ ||42.224.254.226^ ||42.224.254.228^ @@ -360644,6 +360798,7 @@ ||42.224.39.88^ ||42.224.4.0^ ||42.224.4.100^ +||42.224.4.110^ ||42.224.4.112^ ||42.224.4.120^ ||42.224.4.12^ @@ -364813,6 +364968,7 @@ ||42.227.222.143^ ||42.227.222.158^ ||42.227.222.174^ +||42.227.222.189^ ||42.227.222.229^ ||42.227.222.244^ ||42.227.222.43^ @@ -364848,6 +365004,7 @@ ||42.227.225.154^ ||42.227.225.181^ ||42.227.225.209^ +||42.227.225.253^ ||42.227.225.45^ ||42.227.225.49^ ||42.227.225.81^ @@ -368718,6 +368875,7 @@ ||42.230.142.79^ ||42.230.142.82^ ||42.230.143.130^ +||42.230.143.162^ ||42.230.143.174^ ||42.230.143.176^ ||42.230.143.17^ @@ -373090,6 +373248,7 @@ ||42.232.169.202^ ||42.232.169.203^ ||42.232.169.209^ +||42.232.169.211^ ||42.232.169.219^ ||42.232.169.223^ ||42.232.169.226^ @@ -374796,6 +374955,7 @@ ||42.233.96.52^ ||42.233.96.71^ ||42.233.97.10^ +||42.233.97.141^ ||42.233.97.149^ ||42.233.97.157^ ||42.233.97.160^ @@ -379435,6 +379595,7 @@ ||42.235.84.52^ ||42.235.84.54^ ||42.235.84.73^ +||42.235.84.85^ ||42.235.84.87^ ||42.235.84.88^ ||42.235.84.97^ @@ -380646,6 +380807,7 @@ ||42.237.114.252^ ||42.237.114.48^ ||42.237.114.50^ +||42.237.114.80^ ||42.237.114.87^ ||42.237.115.169^ ||42.237.115.175^ @@ -384530,6 +384692,7 @@ ||45.15.143.158^ ||45.15.143.170^ ||45.15.143.175^ +||45.15.143.191^ ||45.15.143.253^ ||45.15.25.65^ ||45.15.253.88^ @@ -385724,6 +385887,7 @@ ||45.229.54.19^ ||45.229.54.1^ ||45.229.54.200^ +||45.229.54.201^ ||45.229.54.202^ ||45.229.54.203^ ||45.229.54.204^ @@ -385825,6 +385989,7 @@ ||45.229.55.71^ ||45.229.55.75^ ||45.229.55.79^ +||45.229.55.80^ ||45.229.55.83^ ||45.229.55.85^ ||45.229.55.98^ @@ -386508,6 +386673,7 @@ ||45.77.78.41^ ||45.77.79.163^ ||45.77.88.79^ +||45.77.9.151^ ||45.77.97.236^ ||45.77.98.62^ ||45.78.21.150^ @@ -393066,6 +393232,7 @@ ||58.249.75.126^ ||58.249.75.128^ ||58.249.75.13^ +||58.249.75.146^ ||58.249.75.14^ ||58.249.75.158^ ||58.249.75.159^ @@ -393128,6 +393295,7 @@ ||58.249.77.105^ ||58.249.77.119^ ||58.249.77.12^ +||58.249.77.141^ ||58.249.77.142^ ||58.249.77.144^ ||58.249.77.147^ @@ -393464,6 +393632,7 @@ ||58.249.86.202^ ||58.249.86.203^ ||58.249.86.20^ +||58.249.86.214^ ||58.249.86.227^ ||58.249.86.242^ ||58.249.86.2^ @@ -394512,6 +394681,7 @@ ||59.126.128.229^ ||59.126.128.92^ ||59.126.13.182^ +||59.126.132.42^ ||59.126.132.4^ ||59.126.136.62^ ||59.126.139.144^ @@ -398537,6 +398707,7 @@ ||59.5.192.126^ ||59.5.204.218^ ||59.5.230.140^ +||59.50.23.23^ ||59.50.28.100^ ||59.51.10.111^ ||59.51.10.55^ @@ -400833,6 +401004,7 @@ ||59.92.217.210^ ||59.92.217.211^ ||59.92.217.214^ +||59.92.217.215^ ||59.92.217.217^ ||59.92.217.218^ ||59.92.217.219^ @@ -402002,6 +402174,7 @@ ||59.93.21.133^ ||59.93.21.137^ ||59.93.21.138^ +||59.93.21.140^ ||59.93.21.141^ ||59.93.21.146^ ||59.93.21.147^ @@ -403284,6 +403457,7 @@ ||59.94.182.208^ ||59.94.182.20^ ||59.94.182.210^ +||59.94.182.212^ ||59.94.182.216^ ||59.94.182.217^ ||59.94.182.21^ @@ -404175,6 +404349,7 @@ ||59.95.175.46^ ||59.95.175.47^ ||59.95.175.48^ +||59.95.175.49^ ||59.95.175.4^ ||59.95.175.50^ ||59.95.175.51^ @@ -412039,6 +412214,7 @@ ||60.211.80.189^ ||60.211.80.208^ ||60.211.80.213^ +||60.211.80.216^ ||60.211.80.5^ ||60.211.80.9^ ||60.211.81.125^ @@ -412694,6 +412870,7 @@ ||60.214.52.40^ ||60.214.52.50^ ||60.214.52.96^ +||60.214.53.159^ ||60.214.53.170^ ||60.214.53.183^ ||60.214.53.242^ @@ -422202,6 +422379,7 @@ ||60.254.88.6^ ||60.254.88.91^ ||60.254.89.110^ +||60.254.89.158^ ||60.254.89.160^ ||60.254.89.191^ ||60.254.89.195^ @@ -425280,6 +425458,7 @@ ||61.3.149.196^ ||61.3.149.197^ ||61.3.149.216^ +||61.3.149.244^ ||61.3.149.253^ ||61.3.149.26^ ||61.3.149.31^ @@ -425294,6 +425473,7 @@ ||61.3.149.86^ ||61.3.149.89^ ||61.3.150.0^ +||61.3.150.101^ ||61.3.150.104^ ||61.3.150.121^ ||61.3.150.140^ @@ -425335,9 +425515,11 @@ ||61.3.151.90^ ||61.3.152.205^ ||61.3.152.26^ +||61.3.153.224^ ||61.3.154.201^ ||61.3.154.21^ ||61.3.156.130^ +||61.3.156.17^ ||61.3.18.216^ ||61.3.18.2^ ||61.3.23.66^ @@ -426301,6 +426483,7 @@ ||61.52.186.181^ ||61.52.186.184^ ||61.52.186.185^ +||61.52.186.186^ ||61.52.186.192^ ||61.52.186.195^ ||61.52.186.207^ @@ -429240,6 +429423,7 @@ ||61.52.97.5^ ||61.52.97.61^ ||61.52.97.64^ +||61.52.97.68^ ||61.52.97.69^ ||61.52.97.72^ ||61.52.97.74^ @@ -434191,7 +434375,6 @@ ||65.99.158.218^ ||65.99.176.17^ ||650x.com^ -||654tyfcdr4654fytfy.top^ ||65k2.com^ ||66-gifts.com^ ||66.103.9.249^ @@ -434952,7 +435135,6 @@ ||6gue98ddw4220152.freebackup.site^ ||6hffgq.dm.files.1drv.com^ ||6hu.xyz^ -||6ip.us^ ||6iptv.com^ ||6itokam.com^ ||6kd743o1w.com^ @@ -437362,6 +437544,7 @@ ||80.92.189.5^ ||80.92.189.70^ ||80.92.204.14^ +||80.92.204.57^ ||80.93.182.219^ ||80.99.128.61^ ||80001.me^ @@ -438568,6 +438751,7 @@ ||85.245.162.144^ ||85.247.247.175^ ||85.25.213.151^ +||85.250.147.134^ ||85.250.36.135^ ||85.255.1.93^ ||85.26.250.86^ @@ -438745,6 +438929,7 @@ ||86.7.86.4^ ||86.82.137.79^ ||86.91.10.91^ +||86.98.23.78^ ||860259.com^ ||8650hwvaapy.realbrjuridico.email^ ||866appliance.com^ @@ -438862,6 +439047,7 @@ ||87.248.61.60^ ||87.249.204.194^ ||87.251.235.167^ +||87.251.71.78^ ||87.251.82.211^ ||87.253.0.196^ ||87.253.1.206^ @@ -439437,6 +439623,7 @@ ||89.148.233.85^ ||89.148.234.101^ ||89.148.234.165^ +||89.148.234.217^ ||89.148.234.37^ ||89.148.235.94^ ||89.148.237.100^ @@ -440867,6 +441054,7 @@ ||93.157.62.102^ ||93.157.62.171^ ||93.157.62.58^ +||93.157.63.221^ ||93.157.63.244^ ||93.159.141.165^ ||93.159.141.166^ @@ -442475,7 +442663,6 @@ ||a.doko.moe^ ||a.gg.fm^ ||a.heritageandterre.com^ -||a.pomf.cat^ ||a.pomf.se^ ||a.pomf.space^ ||a.pomf.su^ @@ -447190,7 +447377,6 @@ ||anmocnhien.vn^ ||anmolanwar.com^ ||ann141.net^ -||anna.websaiting.ru^ ||annaaluminium.annagroup.net^ ||annabelle-hamande.be^ ||annabphotography.co.uk^ @@ -447705,6 +447891,7 @@ ||app.boxrcdn.com^ ||app.bridgeimpex.org^ ||app.calag.at^ +||app.casetabs.com^ ||app.catholicchurch.co.in^ ||app.choiphui.com^ ||app.cloudindustry.net^ @@ -449611,6 +449798,7 @@ ||atphitech.com^ ||atpn.ir^ ||atprofessional.org^ +||atpscan.global.hornetsecurity.com^ ||atr.it^ ||atradex.com^ ||atragon.co.uk^ @@ -450371,6 +450559,8 @@ ||awsxb.xyz^ ||awsyscloud.com^ ||awtinfostore.co.business^ +||awumad01.top^ +||awuqze02.top^ ||ax-yogado.com^ ||axalize.vn^ ||axalta.grupojenrab.mx^ @@ -451768,6 +451958,7 @@ ||bbfr.cba.pl^ ||bbgiardinodoriente.it^ ||bbgk.de^ +||bbgroup.com.vn^ ||bbh-design.de^ ||bbhdata.com^ ||bbhs.org.ng^ @@ -452207,7 +452398,6 @@ ||bel-med-tour.ru^ ||belabargelro.com^ ||belair.btwstudio.ch^ -||belairinternet.com^ ||belamater.com.br^ ||belangel.by^ ||belanja-berkah.xyz^ @@ -452326,7 +452516,6 @@ ||belz-development.de^ ||belznerdesign.de^ ||bem.fkep.unpad.ac.id^ -||bem.hukum.ub.ac.id^ ||bem.unimal.ac.id^ ||bemagazine.club^ ||bemakeup.ru^ @@ -453099,6 +453288,7 @@ ||bierne-les-villages.fr^ ||biese.eu^ ||bietthubien.org^ +||bietthudep902.com^ ||bietthulambach.com^ ||bietthulienkegamuda.net^ ||bietthumau.com^ @@ -456994,7 +457184,6 @@ ||callpetercatering.com^ ||callrealtyaz.com^ ||callshaal.com^ -||callsmaster.com^ ||calltoprimus.ru^ ||callumstokes.com^ ||calm-tech.africa^ @@ -458254,7 +458443,6 @@ ||cdndownloadlp.club^ ||cdnmultimedia.com^ ||cdnpic.mgyun.com^ -||cdnrep.reimageplus.com^ ||cdnxh.net^ ||cdoconsult.com.br^ ||cdolechon.com^ @@ -459046,7 +459234,6 @@ ||cheematransxpressinc.com^ ||cheerchile.cl^ ||cheerfulgiversneverlack.com^ -||cheerfullydo.com^ ||cheesecakery.com.br^ ||cheetahridge.mediadevstaging.com^ ||chef-solutions.dreamscape.co.in^ @@ -459977,6 +460164,7 @@ ||clarte-thailand.com^ ||clashofclansgems.nl^ ||clasificados.diaadianews.com^ +||clasificadosmaule.com^ ||class.britishonline.co^ ||class.snph.ir^ ||classbrain.net^ @@ -460274,6 +460462,7 @@ ||cloakingtds.xyz^ ||clock.noixun.com^ ||clodflarechk.com^ +||clodura.ai^ ||clone.affordable.cm^ ||clone.system-standex.dk^ ||cloned.in^ @@ -460459,7 +460648,6 @@ ||cmecobrancas.com^ ||cmelik.com^ ||cmessagers.com^ -||cmg.asia^ ||cmg.ma^ ||cmgroup.com.ua^ ||cmhighschool.edu.bd^ @@ -462998,7 +463186,6 @@ ||cuadros.pe^ ||cuahangphongthuy.net^ ||cuahangstore.com^ -||cuahangvattu.com^ ||cualtis.com^ ||cuanhomxingfanhapkhau.com^ ||cuasotinhoc.net^ @@ -463427,6 +463614,7 @@ ||d.qiluwl.com^ ||d.teamworx.ph^ ||d.techmartbd.com^ +||d.top4top.io^ ||d.top4top.net^ ||d.ttr3p.com^ ||d04.data39.helldata.com^ @@ -465408,6 +465596,7 @@ ||deposayim.ml^ ||depositoclara.com.br^ ||depot7.com^ +||depozituldegeneratoare.ro^ ||depraetere.net^ ||deprealty.ru^ ||depressionted.com^ @@ -467134,7 +467323,6 @@ ||dl-675423.store-downloads.com^ ||dl-80076342.md-downloads.com^ ||dl-97674424.md-downloads.com^ -||dl-gameplayer.dmm.com^ ||dl-link.link^ ||dl-link.live^ ||dl-link.network^ @@ -467157,9 +467345,9 @@ ||dl.imht.ir^ ||dl.installcdn-aws.com^ ||dl.mqego.com^ -||dl.mydown.com^ ||dl.ossdown.fun^ ||dl.packetstormsecurity.net^ +||dl.pandasecur.com^ ||dl.popupgrade.com^ ||dl.repairlabshost.com^ ||dl.rina-roleplay.com^ @@ -467336,6 +467524,9 @@ ||dobroviz.com.ua^ ||dobrovorot.su^ ||dobsoncentral.com^ +||doc-0s-7c-docs.googleusercontent.com^ +||doc-10-0c-docs.googleusercontent.com^ +||doc-10-8s-docs.googleusercontent.com^ ||doc-hub.healthycheapfast.com^ ||doc-japan.com^ ||doc.albaspizzaastoria.com^ @@ -469610,6 +469801,7 @@ ||ec2-54-207-92-161.sa-east-1.compute.amazonaws.com^ ||ec2-54-212-231-68.us-west-2.compute.amazonaws.com^ ||ec2-54-94-215-87.sa-east-1.compute.amazonaws.com^ +||ec2euc1.boxcloud.com^ ||ec2test.ga^ ||ec3-design.com^ ||ecadigital.com^ @@ -471910,6 +472102,7 @@ ||esaarc.com^ ||esacbd.com^ ||esagarautomobiles.com^ +||esaja09.top^ ||esanjobs.org^ ||esar.weenets.com^ ||esascom.com^ @@ -477704,7 +477897,6 @@ ||genrjw.dm.files.1drv.com^ ||genstaff.gov.kg^ ||gentcreativa.com^ -||gentecoyol.com^ ||gentesanluis.com^ ||gentiane-salers.com^ ||gentlechirocenter.com^ @@ -480453,6 +480645,7 @@ ||gvpcdpgc.edu.in^ ||gvpmacademy.co.za^ ||gvsme.com^ +||gw.daelimcloud.com^ ||gw.hitlin.com^ ||gwangjuhotels.kr^ ||gwavellc.com^ @@ -483264,7 +483457,6 @@ ||hotelwaldblick.com^ ||hotexpress.co^ ||hotfacts.org^ -||hotgifts.online^ ||hotilife.com^ ||hotissue.xyz^ ||hotkine.com^ @@ -483642,7 +483834,6 @@ ||hukuen-motokare.xyz^ ||hukuki.site^ ||hukukportal.com^ -||hukum.ub.ac.id^ ||hukum.unwiku.ac.id^ ||hulianwang114.com^ ||huliot.in^ @@ -483964,6 +484155,7 @@ ||i-supportcharity.com^ ||i-vnsweyu.pl^ ||i-voda.com^ +||i.fiery.me^ ||i.fluffy.cc^ ||i.funtourspt.eu^ ||i.n.t.e.rloca.l.qs.j.y@jfas.top^ @@ -487244,6 +487436,7 @@ ||itspsc.com.ua^ ||itspueh.nl^ ||itsquare.yrcreations.com^ +||itsrlytry.000webhostapp.com^ ||itssprout.com^ ||itstelecom.com.br^ ||itsweezle.com^ @@ -487443,6 +487636,7 @@ ||j-stage.jp^ ||j-toputvoutfitters.com^ ||j.kyryl.ru^ +||j.top4top.io^ ||j11g9xecuxe43xu.xyz^ ||j12z7407gwtzk.xyz^ ||j13.biz^ @@ -487575,6 +487769,7 @@ ||jaipurweddingphotography.com^ ||jairathsnatural.ca^ ||jairozapata.000webhostapp.com^ +||jaishomo.info^ ||jaishritours.com^ ||jaiswalsupplement.com^ ||jajadomains.com^ @@ -491603,7 +491798,6 @@ ||kodim0112sabang.com^ ||kodingeko.com^ ||kodip.nfile.net^ -||kodjdsjsdjf.tk^ ||kodlacan.site^ ||kodmuje.com^ ||kodolios.000webhostapp.com^ @@ -494243,6 +494437,7 @@ ||library.cifor.org^ ||library.dhl-xom.com^ ||library.iainbengkulu.ac.id^ +||library.mju.ac.th^ ||library.phibi.my.id^ ||library.piet.co.in^ ||library.strophicmusic.com^ @@ -494929,7 +495124,6 @@ ||livecigarevent.com^ ||livecricketscorecard.info^ ||livedaynews.com^ -||livedemo00.template-help.com^ ||livedownload.in^ ||livedrumtracks.com^ ||livefarma.com^ @@ -494962,7 +495156,6 @@ ||livestreams.vn^ ||livesuitesapartdaire.com^ ||livesurgerycourse.ir^ -||liveswinburneeduau-my.sharepoint.com^ ||liveswindow.casa^ ||liveswindow.cyou^ ||liveswindows.bar^ @@ -496137,7 +496330,6 @@ ||luzconsulting.com.br^ ||luzevida.com.br^ ||luzfloral.com^ -||luzy.vn^ ||luzzeri.com^ ||lvajnczdy.cf^ ||lvcfund.org.vn^ @@ -499175,7 +499367,6 @@ ||mecgwl.ac.in^ ||mechanicaltools.club^ ||mechanicsthatcometoyou.com^ -||mecharnise.ir^ ||mechathrones.com^ ||mechauto.co.za^ ||mechdesign.com^ @@ -499761,7 +499952,6 @@ ||menziesadvisory-my.sharepoint.com^ ||menzway.com^ ||meogiambeo.com^ -||meohaybotui.com^ ||meolamdephay.com^ ||mepsgen.com^ ||mera.ddns.net^ @@ -500079,6 +500269,7 @@ ||mfomjr.com^ ||mfotovideo.ro^ ||mfpburundi.bi^ +||mfpc.org.my^ ||mfppanel.xyz^ ||mfpvision.com^ ||mfronza.com.br^ @@ -505111,7 +505302,6 @@ ||nhadatquan2.xyz^ ||nhadatthienthoi.com^ ||nhadephungyen.com^ -||nhadepkientruc.net^ ||nhahangdaihung.com^ ||nhahanghaivuong.vn^ ||nhahanglegiang.vn^ @@ -505325,7 +505515,6 @@ ||nikanpolimer.ir^ ||nikastroi.ru^ ||nikavkuchyni.sk^ -||nikayu.com^ ||nikbox.ru^ ||nikeshyadav.com^ ||nikhil.webscript.co.in^ @@ -507841,7 +508030,6 @@ ||option47.us^ ||optioncapitalgroup.ru^ ||optionrp.com^ -||optionscity.com^ ||optisaving.com^ ||optitechsa.co.za^ ||optocen.ru^ @@ -508136,7 +508324,6 @@ ||osezrayonner.ma^ ||osgbforum.com^ ||oshattorney.com^ -||oshi.at^ ||oshodrycleaning.com^ ||oshonafitness.com^ ||oshop.es^ @@ -511836,7 +512023,6 @@ ||posmicrosystems.com^ ||posnxqmp.ru^ ||pospeeps.com^ -||posqit.net^ ||possessionnow.com^ ||possible.re^ ||possopagar.com.br^ @@ -512472,7 +512658,6 @@ ||prisidmart.com^ ||priskat.net^ ||prism-photo.com^ -||prisma.fp.ub.ac.id^ ||prismaxis.com^ ||prismfox.com^ ||prismware.ml^ @@ -513064,6 +513249,7 @@ ||protech.mn^ ||protechcarpetcare.com^ ||protechgroup1.com^ +||protect.mimecast-offshore.com^ ||protectiadatelor.biz^ ||protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org^ ||protection.pecol.eu^ @@ -513145,6 +513331,7 @@ ||proxy-ipv4.com^ ||proxy.2u0apcm6ylhdy7s.com^ ||proxy.hueaudio.com^ +||proxy.qualtrics.com^ ||proxygrnd.xyz^ ||proxyholding.com^ ||proxyresume.com^ @@ -515658,6 +515845,7 @@ ||redlogisticsmaroc.com^ ||redloop.io^ ||redlotusevents.com^ +||redm1az1.000webhostapp.com^ ||redmag.by^ ||redmarcial.ossmarcial.com^ ||redmediasigns.com^ @@ -516829,6 +517017,7 @@ ||rkcable.co.in^ ||rkfplumbing.co.uk^ ||rkinstitute.org^ +||rkkrstdygorgiousejbg.dns.army^ ||rkkrstdygorgiousejds.dns.army^ ||rkkrstdygorgiousejtw.dns.army^ ||rklkpgcollege.com^ @@ -517385,6 +517574,7 @@ ||rotoblast.org^ ||rotor.olsztyn.pl^ ||rotoscoop.com^ +||rotronics.com.ph^ ||rott-mtr.de^ ||rotterdammeetings.nl^ ||rotulosalarcon.com^ @@ -517798,7 +517988,6 @@ ||runmureed.com^ ||runmyweb.com^ ||runnected.kaiman.fr^ -||runnerbd.com^ ||runnerschool.com^ ||running-bike.com^ ||runningcrewteam.com^ @@ -519321,6 +519510,7 @@ ||savemyfile.3utilities.com^ ||savemyseatnow.com^ ||saveraahealthcare.com^ +||saveserpnow.com^ ||saveserpresults.com^ ||savestudio.com^ ||savetax.idfcmf.com^ @@ -519998,6 +520188,7 @@ ||secure-risk.namaskara.me^ ||secure-snupa.com^ ||secure.accounts.resourses.com^ +||secure.activedirect.xyz^ ||secure.anchorssb.co^ ||secure.app-amazon.com.recovery-account.amazon.com.alphatravelmongolia.com^ ||secure.bodybuilderabs.net^ @@ -520675,7 +520866,6 @@ ||service.dawat.fr^ ||service.drnjithendran.com^ ||service.eftformotherissues.com^ -||service.ezsoftwareupdater.com^ ||service.heritageimagingcenter.com^ ||service.hybridhomesteam.com^ ||service.idealfurnitureoutlet.com^ @@ -521180,6 +521370,7 @@ ||sharebook.tk^ ||sharechautari.com^ ||shared-cnd.com^ +||shared.outlook.inky.com^ ||shareddocuments.ml^ ||shareddynamics.com^ ||sharedeconomy.eu^ @@ -525546,9 +525737,11 @@ ||stdymjventsluzcafsrp.dns.army^ ||stdymorcmmylntwincdq.dns.army^ ||stdymorcmmylntwinstr.dns.army^ +||stdynbnbnewagedevixz.dns.army^ ||stdynbnbnewagedevsmn.dns.army^ ||stdynbnbnewagedevxaz.dns.army^ ||stdyneverwalkachinese2loneinlifekstgqm.ydns.eu^ +||stdynmxwllminoragest.dns.army^ ||stdyperezluzcafeyzst.dns.navy^ ||stdypmrimelimtwstogy.dns.army^ ||stdypycsslwinnerscot.dns.army^ @@ -525579,6 +525772,7 @@ ||stdytopreoneenversrw.dns.army^ ||stdytopreoneenvervaj.dns.army^ ||stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu^ +||stdyunitedkesokokgst.dns.army^ ||stdyunitedkesokostdr.dns.army^ ||stdyunitedkesokostri.dns.navy^ ||stdyunitedkesokostxc.dns.army^ @@ -525588,7 +525782,9 @@ ||stdyworkfineanotherrainbowlomoyentwkgls.duckdns.org^ ||stdyworkfinesanotherrainbowlomoyentstfcp.ydns.eu^ ||stdyworkfinesanotherrainbowlomoyentstgot.ydns.eu^ +||stdyworkfinetraingst.dns.army^ ||stdyzgchgcloudgostgt.dns.army^ +||stdyzgchgcloudgostxs.dns.army^ ||steadyrestmanufacturers.com^ ||steak.wpress.dk^ ||steakhouse.com.ua^ @@ -526148,6 +526344,7 @@ ||strengthandvigour.com^ ||strengthrer.com^ ||strenover.ga^ +||stressing.pw^ ||stressnada.com^ ||stretchpilates.fit^ ||strewn.org^ @@ -526839,6 +527036,7 @@ ||supercutscissors.com^ ||superdad.id^ ||superdigitalguy.xyz^ +||superdomain1709.info^ ||superdot.rs^ ||superecruiters.com^ ||superfacil.center^ @@ -526942,7 +527140,6 @@ ||support.mdsol.com^ ||support.nordenrecycling.com^ ||support.nuvemit.com^ -||support.pubg.com^ ||support.redbook.aero^ ||support.revolus.xyz^ ||support.servu.co.uk^ @@ -527287,7 +527484,6 @@ ||swicoservers.co.uk^ ||swieradowbiega.pl^ ||swifck.xmr.ac^ -||swift-cloud.com^ ||swiftbusinesspay.com^ ||swiftee.co.uk^ ||swiftender.com^ @@ -528132,7 +528328,6 @@ ||targas.de^ ||targat-china.com^ ||target-events.com^ -||target-support.online^ ||target2cloud.com^ ||targetbizbd.com^ ||targetcm.net^ @@ -529713,7 +529908,6 @@ ||thachastew.com^ ||thachvietstone.com^ ||thadathilfarmresort.com^ -||thaddeusarmstrong.com^ ||thadinnoo.co^ ||thagreymatter.com^ ||thai-chana.asia^ @@ -531435,7 +531629,6 @@ ||tlcid.org^ ||tlckids-or.ga^ ||tlcmoto.com^ -||tldrbox.top^ ||tldrnet.top^ ||tlextreme.com^ ||tlfthelifefactory.com.au^ @@ -533032,6 +533225,7 @@ ||ts.7rb.xyz^ ||ts0ev73.com^ ||tsal.com^ +||tsapparel.com.my^ ||tsareva-garden.ru^ ||tsatsi.co.za^ ||tsauctions.com^ @@ -533259,6 +533453,7 @@ ||tunnelview.co.uk^ ||tunuvo.com^ ||tuobrasocial.com.ar^ +||tuoitrethainguyen.vn^ ||tupibaje.com^ ||tupperware.michaelroberge.ca^ ||tur.000webhostapp.com^ @@ -534405,7 +534600,6 @@ ||unlimited.nu^ ||unlimitedbags.club^ ||unlimitedfreightco.com^ -||unlimitedimportandexport.com^ ||unlock-king.com^ ||unlock2.neagoeandrei.com^ ||unlockall.neagoeandrei.com^ @@ -534731,6 +534925,7 @@ ||url-validation-clients.com^ ||url.246546.com^ ||url.57569.fr.snd52.ch^ +||url2.mailanyone.net^ ||url3.mailanyone.net^ ||url5459.41southbar.com^ ||url675.textilmallorca.com^ @@ -534934,7 +535129,6 @@ ||utting.org^ ||utv.sakeronline.se^ ||utv1.enliden.net^ -||uujian.cn^ ||uumove.com^ ||uurty87e8rt7rt.com^ ||uutiset.helppokoti.fi^ @@ -536908,7 +537102,6 @@ ||voingani.it^ ||voip96.ru^ ||voipminic.com^ -||vokasi.ub.ac.id^ ||vokzalrf.ru^ ||vol.agency^ ||vol2.pw^ @@ -537536,7 +537729,6 @@ ||washuis.nl^ ||wasidora.com^ ||wasilewski-online.de^ -||wasimjee.com^ ||wasino.co.th^ ||wasobd.net^ ||waspha.com^ @@ -539076,7 +539268,6 @@ ||woatinkwoo.com^ ||woclawoffers.fun^ ||wocomm.marketingmindz.com^ -||wodfitapparel.fr^ ||wodmetaldom.pl^ ||wodsuit.com^ ||woelf.in^ @@ -541705,7 +541896,9 @@ ||yoyoso.nz^ ||yoyoteacher.cn^ ||yp.dcyazilim.com^ +||yp.hnggzyjy.cn^ ||ypbb.or.id^ +||ypddf.org^ ||ypicsdy.cf^ ||ypko-55.gq^ ||ypom.com.br^ @@ -541864,7 +542057,6 @@ ||yuti.kr^ ||yuvann.com^ ||yuvikadvertisments.com^ -||yuwaraja.vokasi.ub.ac.id^ ||yuweis.com^ ||yuxigon.com^ ||yuxuanknit.com^ diff --git a/urlhaus-filter-bind-online.conf b/urlhaus-filter-bind-online.conf index 922b9c58..b0905165 100644 --- a/urlhaus-filter-bind-online.conf +++ b/urlhaus-filter-bind-online.conf @@ -1,5 +1,5 @@ # Title: Online Malicious Domains BIND Blocklist -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -33,7 +33,6 @@ zone "addahealingmusic.com" { type master; notify no; file "null.zone.file"; }; zone "adithimedia.com" { type master; notify no; file "null.zone.file"; }; zone "adithimedia.memengers.com" { type master; notify no; file "null.zone.file"; }; zone "admin.erapor.smk-alasror.net" { type master; notify no; file "null.zone.file"; }; -zone "admin.gentbcn.org" { type master; notify no; file "null.zone.file"; }; zone "admin.grandoceanvilla.com" { type master; notify no; file "null.zone.file"; }; zone "admission.kmctartskuttippuram.org" { type master; notify no; file "null.zone.file"; }; zone "adventureexplorer.in" { type master; notify no; file "null.zone.file"; }; @@ -49,6 +48,7 @@ zone "aiecons.com" { type master; notify no; file "null.zone.file"; }; zone "aiqtest.com" { type master; notify no; file "null.zone.file"; }; zone "ajpharmaholding.com" { type master; notify no; file "null.zone.file"; }; zone "akdvidyalaya.com" { type master; notify no; file "null.zone.file"; }; +zone "al-wahd.com" { type master; notify no; file "null.zone.file"; }; zone "alasdemariposas.org" { type master; notify no; file "null.zone.file"; }; zone "alberts.diamondrelationscrm.us" { type master; notify no; file "null.zone.file"; }; zone "alemelektronik.com" { type master; notify no; file "null.zone.file"; }; @@ -86,7 +86,6 @@ zone "aps-sv.com" { type master; notify no; file "null.zone.file"; }; zone "artedibujoyarquitectura.com" { type master; notify no; file "null.zone.file"; }; zone "arwenyapi.com" { type master; notify no; file "null.zone.file"; }; zone "ask-regard.call-save.biz" { type master; notify no; file "null.zone.file"; }; -zone "asucssa.live" { type master; notify no; file "null.zone.file"; }; zone "atfile.com" { type master; notify no; file "null.zone.file"; }; zone "athenacapsg.com" { type master; notify no; file "null.zone.file"; }; zone "atlasconcreteworks.com" { type master; notify no; file "null.zone.file"; }; @@ -98,15 +97,17 @@ zone "australianpga.com.au" { type master; notify no; file "null.zone.file"; }; zone "automaticrefreshments.com" { type master; notify no; file "null.zone.file"; }; zone "avadhanagames.com" { type master; notify no; file "null.zone.file"; }; zone "aventuramotorhome.com" { type master; notify no; file "null.zone.file"; }; +zone "awumad01.top" { type master; notify no; file "null.zone.file"; }; +zone "awuqze02.top" { type master; notify no; file "null.zone.file"; }; zone "ayahuascasp.com.br" { type master; notify no; file "null.zone.file"; }; zone "ayamallah.com" { type master; notify no; file "null.zone.file"; }; -zone "aycconsultoriaempresarial.com" { type master; notify no; file "null.zone.file"; }; zone "azmeasurement.com" { type master; notify no; file "null.zone.file"; }; zone "azraktours.com" { type master; notify no; file "null.zone.file"; }; zone "b.r.uce.lee.b.es.t@zytrox.tk" { type master; notify no; file "null.zone.file"; }; zone "b2b.toptanakaryakit.com.tr" { type master; notify no; file "null.zone.file"; }; zone "backgrounds.pk" { type master; notify no; file "null.zone.file"; }; zone "badeggdesign.com" { type master; notify no; file "null.zone.file"; }; +zone "bakamla.go.id" { type master; notify no; file "null.zone.file"; }; zone "balealgodon.mx" { type master; notify no; file "null.zone.file"; }; zone "bangkok-orchids.com" { type master; notify no; file "null.zone.file"; }; zone "bangladeshunbound.com" { type master; notify no; file "null.zone.file"; }; @@ -127,7 +128,6 @@ zone "beor360.com" { type master; notify no; file "null.zone.file"; }; zone "bespokeweddings.ie" { type master; notify no; file "null.zone.file"; }; zone "bestcarenepal.com" { type master; notify no; file "null.zone.file"; }; zone "betone.co.kr" { type master; notify no; file "null.zone.file"; }; -zone "betycopaints.com" { type master; notify no; file "null.zone.file"; }; zone "beveragesmiami.solucioneslink.com" { type master; notify no; file "null.zone.file"; }; zone "bhavaniengineering.com" { type master; notify no; file "null.zone.file"; }; zone "bigmikesupplies.co.za" { type master; notify no; file "null.zone.file"; }; @@ -183,12 +183,12 @@ zone "canadianwork.cc" { type master; notify no; file "null.zone.file"; }; zone "capitalgroup-kw.com" { type master; notify no; file "null.zone.file"; }; zone "capoeiraventrelivre.com" { type master; notify no; file "null.zone.file"; }; zone "cashyinvestment.org" { type master; notify no; file "null.zone.file"; }; +zone "casiomaneflirt.cf" { type master; notify no; file "null.zone.file"; }; zone "catchpoolshetlands.co.uk" { type master; notify no; file "null.zone.file"; }; zone "cazyacustomfurniture.com" { type master; notify no; file "null.zone.file"; }; zone "cbn.hypervoizd.com" { type master; notify no; file "null.zone.file"; }; zone "ccauthority.net" { type master; notify no; file "null.zone.file"; }; zone "cdaonline.com.ar" { type master; notify no; file "null.zone.file"; }; -zone "cdn-10049480.file.myqcloud.com" { type master; notify no; file "null.zone.file"; }; zone "cec.asso.ac-amiens.fr" { type master; notify no; file "null.zone.file"; }; zone "cellas.sk" { type master; notify no; file "null.zone.file"; }; zone "cendekiabinaaksara.com" { type master; notify no; file "null.zone.file"; }; @@ -202,17 +202,17 @@ zone "chinhdropfile.myvnc.com" { type master; notify no; file "null.zone.file"; zone "chinhdropfile80.myvnc.com" { type master; notify no; file "null.zone.file"; }; zone "cible-energy.com" { type master; notify no; file "null.zone.file"; }; zone "cifeer.net" { type master; notify no; file "null.zone.file"; }; +zone "citiconstructioncorp.com" { type master; notify no; file "null.zone.file"; }; zone "citihits.lk" { type master; notify no; file "null.zone.file"; }; zone "citssolutions.co.za" { type master; notify no; file "null.zone.file"; }; -zone "citycapproperty.ru" { type master; notify no; file "null.zone.file"; }; zone "cityglobalgospel.com" { type master; notify no; file "null.zone.file"; }; zone "civi.istmejia.com" { type master; notify no; file "null.zone.file"; }; zone "cleanbydesignllc.com" { type master; notify no; file "null.zone.file"; }; zone "cloud.fc.co.mz" { type master; notify no; file "null.zone.file"; }; zone "cnc.tacobelllover.tk" { type master; notify no; file "null.zone.file"; }; zone "codsambal.com" { type master; notify no; file "null.zone.file"; }; -zone "colinde.pricesne.com" { type master; notify no; file "null.zone.file"; }; zone "colorpak.pl" { type master; notify no; file "null.zone.file"; }; +zone "columbia.aula-web.net" { type master; notify no; file "null.zone.file"; }; zone "community.reimclub.com" { type master; notify no; file "null.zone.file"; }; zone "competancy.indigoconsult.net" { type master; notify no; file "null.zone.file"; }; zone "conceptimagine.ro" { type master; notify no; file "null.zone.file"; }; @@ -222,9 +222,11 @@ zone "constructoralyon.com" { type master; notify no; file "null.zone.file"; }; zone "consulateins.solucioneslink.com" { type master; notify no; file "null.zone.file"; }; zone "contributeindustry.com" { type master; notify no; file "null.zone.file"; }; zone "copelandscapes.com" { type master; notify no; file "null.zone.file"; }; +zone "corwin-tommie06f.ru.com" { type master; notify no; file "null.zone.file"; }; zone "coulsongraphics.com" { type master; notify no; file "null.zone.file"; }; zone "count.mail.163.com.impactmedfoundation.com" { type master; notify no; file "null.zone.file"; }; zone "covid19.cyberschool.or.id" { type master; notify no; file "null.zone.file"; }; +zone "covid19vaccinations.hopto.org" { type master; notify no; file "null.zone.file"; }; zone "cr-sq.com" { type master; notify no; file "null.zone.file"; }; zone "craftech.nxtnet.ga" { type master; notify no; file "null.zone.file"; }; zone "crearechile.cl" { type master; notify no; file "null.zone.file"; }; @@ -287,6 +289,7 @@ zone "dl.1003b.56a.com" { type master; notify no; file "null.zone.file"; }; zone "dl.198424.com" { type master; notify no; file "null.zone.file"; }; zone "dl.installcdn-aws.com" { type master; notify no; file "null.zone.file"; }; zone "dl.packetstormsecurity.net" { type master; notify no; file "null.zone.file"; }; +zone "dl.pandasecur.com" { type master; notify no; file "null.zone.file"; }; zone "dl.rina-roleplay.com" { type master; notify no; file "null.zone.file"; }; zone "dnn.alibuf.com" { type master; notify no; file "null.zone.file"; }; zone "dns.alibuf.com" { type master; notify no; file "null.zone.file"; }; @@ -343,11 +346,11 @@ zone "endurotanzania.co.tz" { type master; notify no; file "null.zone.file"; }; zone "ennovate.elin.co.za" { type master; notify no; file "null.zone.file"; }; zone "equimination.ee" { type master; notify no; file "null.zone.file"; }; zone "erp.nanotechproautocare.com" { type master; notify no; file "null.zone.file"; }; +zone "esaja09.top" { type master; notify no; file "null.zone.file"; }; zone "escola.probommar.org.br" { type master; notify no; file "null.zone.file"; }; zone "eservices.immigration.gov.lk" { type master; notify no; file "null.zone.file"; }; zone "esnconsultants.com" { type master; notify no; file "null.zone.file"; }; zone "essentia.org.br" { type master; notify no; file "null.zone.file"; }; -zone "ethereality.info" { type master; notify no; file "null.zone.file"; }; zone "eubanks7.com" { type master; notify no; file "null.zone.file"; }; zone "europeanzonexxi.com" { type master; notify no; file "null.zone.file"; }; zone "exilum.com" { type master; notify no; file "null.zone.file"; }; @@ -365,7 +368,7 @@ zone "fineartgallerym.com" { type master; notify no; file "null.zone.file"; }; zone "fisconline.bar" { type master; notify no; file "null.zone.file"; }; zone "fisconline.casa" { type master; notify no; file "null.zone.file"; }; zone "fix-america-now.org" { type master; notify no; file "null.zone.file"; }; -zone "fixauto.illumetechnology.com" { type master; notify no; file "null.zone.file"; }; +zone "fkd.derpcity.ru" { type master; notify no; file "null.zone.file"; }; zone "flexypay.dsquaregroup.com" { type master; notify no; file "null.zone.file"; }; zone "flintspin.com" { type master; notify no; file "null.zone.file"; }; zone "flyingbuddhadesign.com" { type master; notify no; file "null.zone.file"; }; @@ -386,7 +389,6 @@ zone "fusionfiresolutions.com" { type master; notify no; file "null.zone.file"; zone "futbolpr.com" { type master; notify no; file "null.zone.file"; }; zone "futuregraphics.com.ar" { type master; notify no; file "null.zone.file"; }; zone "g.pinmonkey.xyz" { type master; notify no; file "null.zone.file"; }; -zone "gaditastour.com" { type master; notify no; file "null.zone.file"; }; zone "gametwogame.com" { type master; notify no; file "null.zone.file"; }; zone "garciadogshow.com" { type master; notify no; file "null.zone.file"; }; zone "garenanow.myvnc.com" { type master; notify no; file "null.zone.file"; }; @@ -416,7 +418,6 @@ zone "goldenasiacapital.com" { type master; notify no; file "null.zone.file"; }; zone "goldmen.in" { type master; notify no; file "null.zone.file"; }; zone "gpotecnosystems.com" { type master; notify no; file "null.zone.file"; }; zone "gracejukes.com" { type master; notify no; file "null.zone.file"; }; -zone "greataccesstoserver.com" { type master; notify no; file "null.zone.file"; }; zone "grupoinmare.com" { type master; notify no; file "null.zone.file"; }; zone "gruposelt.000webhostapp.com" { type master; notify no; file "null.zone.file"; }; zone "gs.monerorx.com" { type master; notify no; file "null.zone.file"; }; @@ -447,17 +448,13 @@ zone "hitstation.nl" { type master; notify no; file "null.zone.file"; }; zone "hmpmall.co.kr" { type master; notify no; file "null.zone.file"; }; zone "hoagietesting10.com" { type master; notify no; file "null.zone.file"; }; zone "hoayeuthuong-my.sharepoint.com" { type master; notify no; file "null.zone.file"; }; -zone "holmesservices.mobiledevsite.co" { type master; notify no; file "null.zone.file"; }; zone "homefindersolutions.com" { type master; notify no; file "null.zone.file"; }; zone "hometownchick.com" { type master; notify no; file "null.zone.file"; }; -zone "hongluosi.com" { type master; notify no; file "null.zone.file"; }; zone "hookedupboatclub.com" { type master; notify no; file "null.zone.file"; }; zone "hostingparacolombia.com" { type master; notify no; file "null.zone.file"; }; zone "hostzaa.com" { type master; notify no; file "null.zone.file"; }; -zone "houstonshutters.site" { type master; notify no; file "null.zone.file"; }; zone "hr2019.vrcom7.com" { type master; notify no; file "null.zone.file"; }; zone "hseda.com" { type master; notify no; file "null.zone.file"; }; -zone "hsmwebapp.com" { type master; notify no; file "null.zone.file"; }; zone "htownbars.com" { type master; notify no; file "null.zone.file"; }; zone "hubtech.co.za" { type master; notify no; file "null.zone.file"; }; zone "huellacero.cl" { type master; notify no; file "null.zone.file"; }; @@ -505,6 +502,8 @@ zone "isso.ps" { type master; notify no; file "null.zone.file"; }; zone "it123.ru" { type master; notify no; file "null.zone.file"; }; zone "italiandirezione.casa" { type master; notify no; file "null.zone.file"; }; zone "itc-demo.softgig.co.ke" { type master; notify no; file "null.zone.file"; }; +zone "itsrlytry.000webhostapp.com" { type master; notify no; file "null.zone.file"; }; +zone "jaishomo.info" { type master; notify no; file "null.zone.file"; }; zone "jamiekaylive.com" { type master; notify no; file "null.zone.file"; }; zone "jamshed.pk" { type master; notify no; file "null.zone.file"; }; zone "jansen-heesch.nl" { type master; notify no; file "null.zone.file"; }; @@ -532,11 +531,11 @@ zone "kalogirosfinance.com" { type master; notify no; file "null.zone.file"; }; zone "kaptaanchapal.com" { type master; notify no; file "null.zone.file"; }; zone "karer.by" { type master; notify no; file "null.zone.file"; }; zone "katanvetov.co.il" { type master; notify no; file "null.zone.file"; }; +zone "katelynn9506a.ru.com" { type master; notify no; file "null.zone.file"; }; zone "kensingtondriving.com" { type master; notify no; file "null.zone.file"; }; zone "ketofitnessexpert.com" { type master; notify no; file "null.zone.file"; }; zone "kevinjewelry.com.co" { type master; notify no; file "null.zone.file"; }; zone "keywatch.yourpageserver.com" { type master; notify no; file "null.zone.file"; }; -zone "kihn-delaney30gn.ru.com" { type master; notify no; file "null.zone.file"; }; zone "kingssa.co.za" { type master; notify no; file "null.zone.file"; }; zone "kjcpromo.com" { type master; notify no; file "null.zone.file"; }; zone "kleinendeli.co.za" { type master; notify no; file "null.zone.file"; }; @@ -544,7 +543,6 @@ zone "korrectconceptservices.com" { type master; notify no; file "null.zone.file zone "krisbadminton.com" { type master; notify no; file "null.zone.file"; }; zone "ktb.sch.id" { type master; notify no; file "null.zone.file"; }; zone "kubatoglubaklava.com.tr" { type master; notify no; file "null.zone.file"; }; -zone "kullumanalitours.com" { type master; notify no; file "null.zone.file"; }; zone "kumaralok.in" { type master; notify no; file "null.zone.file"; }; zone "kwanfromhongkong.com" { type master; notify no; file "null.zone.file"; }; zone "kz.sldov.ru" { type master; notify no; file "null.zone.file"; }; @@ -601,7 +599,6 @@ zone "mail.jeffsono.org" { type master; notify no; file "null.zone.file"; }; zone "maksi.feb.unib.ac.id" { type master; notify no; file "null.zone.file"; }; zone "malaya.tv" { type master; notify no; file "null.zone.file"; }; zone "malwarecoding.github.io" { type master; notify no; file "null.zone.file"; }; -zone "managed.oss-cn-beijing.aliyuncs.com" { type master; notify no; file "null.zone.file"; }; zone "managemysalon.in" { type master; notify no; file "null.zone.file"; }; zone "manantialesdelnorte.uy" { type master; notify no; file "null.zone.file"; }; zone "manhtien.net" { type master; notify no; file "null.zone.file"; }; @@ -644,6 +641,7 @@ zone "michimal2.000webhostapp.com" { type master; notify no; file "null.zone.fil zone "microblading.mirliandias.com.br" { type master; notify no; file "null.zone.file"; }; zone "microcomm-group.com" { type master; notify no; file "null.zone.file"; }; zone "mikhailmotoringschool.com" { type master; notify no; file "null.zone.file"; }; +zone "mills-skyla30ec.com" { type master; notify no; file "null.zone.file"; }; zone "mingguanwms.com" { type master; notify no; file "null.zone.file"; }; zone "minuevavida.org" { type master; notify no; file "null.zone.file"; }; zone "mirror.mypage.sk" { type master; notify no; file "null.zone.file"; }; @@ -660,6 +658,7 @@ zone "monetization.business" { type master; notify no; file "null.zone.file"; }; zone "moninediy.com" { type master; notify no; file "null.zone.file"; }; zone "moreirawag.ac.ug" { type master; notify no; file "null.zone.file"; }; zone "motorcomunicacion.com" { type master; notify no; file "null.zone.file"; }; +zone "moumitas.com" { type master; notify no; file "null.zone.file"; }; zone "msacontabil.com.br" { type master; notify no; file "null.zone.file"; }; zone "mumgee.co.za" { type master; notify no; file "null.zone.file"; }; zone "muzimbiti.xigubo.co.mz" { type master; notify no; file "null.zone.file"; }; @@ -709,6 +708,7 @@ zone "nyasabigbullets.com" { type master; notify no; file "null.zone.file"; }; zone "nyeh2o.com.au" { type master; notify no; file "null.zone.file"; }; zone "obseques-conseils.com" { type master; notify no; file "null.zone.file"; }; zone "oecteam.com" { type master; notify no; file "null.zone.file"; }; +zone "ohe.ie" { type master; notify no; file "null.zone.file"; }; zone "ohsewgorgeous.co.uk" { type master; notify no; file "null.zone.file"; }; zone "oleholeh.memangbeda.website" { type master; notify no; file "null.zone.file"; }; zone "omaia.org" { type master; notify no; file "null.zone.file"; }; @@ -719,7 +719,6 @@ zone "omscoc.pappai.com" { type master; notify no; file "null.zone.file"; }; zone "onedigitalcard.granvizionnecorp.com" { type master; notify no; file "null.zone.file"; }; zone "onedrive.listifyapp.co" { type master; notify no; file "null.zone.file"; }; zone "online.creedglobal.in" { type master; notify no; file "null.zone.file"; }; -zone "open.rawntech.com" { type master; notify no; file "null.zone.file"; }; zone "open.warehousesaas.co.uk" { type master; notify no; file "null.zone.file"; }; zone "opolis.io" { type master; notify no; file "null.zone.file"; }; zone "optimus.com.sg" { type master; notify no; file "null.zone.file"; }; @@ -794,6 +793,7 @@ zone "prox.realunix.cc" { type master; notify no; file "null.zone.file"; }; zone "pujashoppe.in" { type master; notify no; file "null.zone.file"; }; zone "punchdialogues.com" { type master; notify no; file "null.zone.file"; }; zone "punjabdevelopersassociation.com.pk" { type master; notify no; file "null.zone.file"; }; +zone "pvcprinting.co.uk" { type master; notify no; file "null.zone.file"; }; zone "qadir.tickfa.ir" { type master; notify no; file "null.zone.file"; }; zone "qatarglobalconsulting.com" { type master; notify no; file "null.zone.file"; }; zone "qmsled.com" { type master; notify no; file "null.zone.file"; }; @@ -820,16 +820,15 @@ zone "readwrite26.nl" { type master; notify no; file "null.zone.file"; }; zone "readymmade.com" { type master; notify no; file "null.zone.file"; }; zone "recyclethesurplus.com" { type master; notify no; file "null.zone.file"; }; zone "redbats.co.in" { type master; notify no; file "null.zone.file"; }; +zone "redboxmultimedia.com" { type master; notify no; file "null.zone.file"; }; zone "redchillicrackers.com" { type master; notify no; file "null.zone.file"; }; zone "reifenquick.de" { type master; notify no; file "null.zone.file"; }; -zone "relaxindulge.co.nz" { type master; notify no; file "null.zone.file"; }; zone "renehavis.com.ua" { type master; notify no; file "null.zone.file"; }; zone "repatriacioncolombia.com" { type master; notify no; file "null.zone.file"; }; zone "res.uf1.cn" { type master; notify no; file "null.zone.file"; }; zone "reseller.digimitra.in" { type master; notify no; file "null.zone.file"; }; zone "reseller.itechbrasil.com" { type master; notify no; file "null.zone.file"; }; zone "resuco.net" { type master; notify no; file "null.zone.file"; }; -zone "revolet-sa.com" { type master; notify no; file "null.zone.file"; }; zone "rezkabum.ru" { type master; notify no; file "null.zone.file"; }; zone "rhema.com.sg" { type master; notify no; file "null.zone.file"; }; zone "richmondminerals.co.zm" { type master; notify no; file "null.zone.file"; }; @@ -844,6 +843,7 @@ zone "romanianpoints.com" { type master; notify no; file "null.zone.file"; }; zone "ronnietucker.co.uk" { type master; notify no; file "null.zone.file"; }; zone "roomsvc.servegate.kr" { type master; notify no; file "null.zone.file"; }; zone "roshnijewellery.com" { type master; notify no; file "null.zone.file"; }; +zone "rotronics.com.ph" { type master; notify no; file "null.zone.file"; }; zone "rsgym.net" { type master; notify no; file "null.zone.file"; }; zone "rubazar.pro" { type master; notify no; file "null.zone.file"; }; zone "rubycityvietnam.com" { type master; notify no; file "null.zone.file"; }; @@ -872,6 +872,7 @@ zone "scheff.com" { type master; notify no; file "null.zone.file"; }; zone "schoolbustracker.softgig.co.ke" { type master; notify no; file "null.zone.file"; }; zone "sculetus.nl" { type master; notify no; file "null.zone.file"; }; zone "secure-doc-reader.com" { type master; notify no; file "null.zone.file"; }; +zone "secure.activedirect.xyz" { type master; notify no; file "null.zone.file"; }; zone "segalsmetals.elin.co.za" { type master; notify no; file "null.zone.file"; }; zone "sellmyphonela.com" { type master; notify no; file "null.zone.file"; }; zone "selltechtoday.com" { type master; notify no; file "null.zone.file"; }; @@ -881,7 +882,9 @@ zone "serendibsourcing.com" { type master; notify no; file "null.zone.file"; }; zone "sericaasia.com" { type master; notify no; file "null.zone.file"; }; zone "servicemhkd.myvnc.com" { type master; notify no; file "null.zone.file"; }; zone "servicemhkd80.myvnc.com" { type master; notify no; file "null.zone.file"; }; +zone "serviciovirtual.com.ar" { type master; notify no; file "null.zone.file"; }; zone "sexologistpakistan.net" { type master; notify no; file "null.zone.file"; }; +zone "sgb.ac.ke" { type master; notify no; file "null.zone.file"; }; zone "sgessy.com.br" { type master; notify no; file "null.zone.file"; }; zone "shaheentbfoundation.com" { type master; notify no; file "null.zone.file"; }; zone "shahikhana.cstdevs.com" { type master; notify no; file "null.zone.file"; }; @@ -919,7 +922,6 @@ zone "sobariko.com" { type master; notify no; file "null.zone.file"; }; zone "sobethuacademy.com" { type master; notify no; file "null.zone.file"; }; zone "soft.110route.com" { type master; notify no; file "null.zone.file"; }; zone "soft.officelabo.net" { type master; notify no; file "null.zone.file"; }; -zone "sogecoenergy.com" { type master; notify no; file "null.zone.file"; }; zone "sohs.conceptechs.info" { type master; notify no; file "null.zone.file"; }; zone "solar.amazingtribe.lk" { type master; notify no; file "null.zone.file"; }; zone "somcorbera.cat" { type master; notify no; file "null.zone.file"; }; @@ -933,7 +935,6 @@ zone "spent.com.pl" { type master; notify no; file "null.zone.file"; }; zone "spetsesyachtcharter.gr" { type master; notify no; file "null.zone.file"; }; zone "spititourism.com" { type master; notify no; file "null.zone.file"; }; zone "spittinfire.com" { type master; notify no; file "null.zone.file"; }; -zone "springbedspetroleum.com" { type master; notify no; file "null.zone.file"; }; zone "src1.minibai.com" { type master; notify no; file "null.zone.file"; }; zone "sreenivasapaintingworks.com" { type master; notify no; file "null.zone.file"; }; zone "sriglobalit.com" { type master; notify no; file "null.zone.file"; }; @@ -944,16 +945,23 @@ zone "st.devcodin.com" { type master; notify no; file "null.zone.file"; }; zone "staging.apparelpunch.com" { type master; notify no; file "null.zone.file"; }; zone "starcountry.net" { type master; notify no; file "null.zone.file"; }; zone "static.3001.net" { type master; notify no; file "null.zone.file"; }; +zone "stdynbnbnewagedevixz.dns.army" { type master; notify no; file "null.zone.file"; }; +zone "stdynmxwllminoragest.dns.army" { type master; notify no; file "null.zone.file"; }; +zone "stdyunitedkesokokgst.dns.army" { type master; notify no; file "null.zone.file"; }; +zone "stdyworkfinetraingst.dns.army" { type master; notify no; file "null.zone.file"; }; +zone "stdyzgchgcloudgostxs.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stiau.iuc.ac" { type master; notify no; file "null.zone.file"; }; zone "sticker.jewsjuice.com" { type master; notify no; file "null.zone.file"; }; zone "stiepancasetia.ac.id" { type master; notify no; file "null.zone.file"; }; zone "stlukesohag.com" { type master; notify no; file "null.zone.file"; }; zone "store.ericalgarin.com" { type master; notify no; file "null.zone.file"; }; zone "stott-thompson.co.uk" { type master; notify no; file "null.zone.file"; }; +zone "stratexec.co.za" { type master; notify no; file "null.zone.file"; }; zone "streetdemo.yourpageserver.com" { type master; notify no; file "null.zone.file"; }; zone "suboldesign.com" { type master; notify no; file "null.zone.file"; }; zone "sumerians.org" { type master; notify no; file "null.zone.file"; }; zone "sunaryem.com.tr" { type master; notify no; file "null.zone.file"; }; +zone "sunbrero.com.au" { type master; notify no; file "null.zone.file"; }; zone "sunmarkholidays.com" { type master; notify no; file "null.zone.file"; }; zone "support-4-free.com" { type master; notify no; file "null.zone.file"; }; zone "support.clz.kr" { type master; notify no; file "null.zone.file"; }; @@ -1032,7 +1040,6 @@ zone "topcell9.com" { type master; notify no; file "null.zone.file"; }; zone "toplevel.com.br" { type master; notify no; file "null.zone.file"; }; zone "topmask.co.za" { type master; notify no; file "null.zone.file"; }; zone "torresquinterocorp.com" { type master; notify no; file "null.zone.file"; }; -zone "towme.services" { type master; notify no; file "null.zone.file"; }; zone "toyotacollege.ac.th" { type master; notify no; file "null.zone.file"; }; zone "tpke.hu" { type master; notify no; file "null.zone.file"; }; zone "translaterjemah.com" { type master; notify no; file "null.zone.file"; }; @@ -1059,7 +1066,6 @@ zone "union.jctrip.cn" { type master; notify no; file "null.zone.file"; }; zone "unyazitelecom.com" { type master; notify no; file "null.zone.file"; }; zone "up.llw0.com" { type master; notify no; file "null.zone.file"; }; zone "upcbpta.com" { type master; notify no; file "null.zone.file"; }; -zone "used-jeans.fr" { type master; notify no; file "null.zone.file"; }; zone "useformoney.000webhostapp.com" { type master; notify no; file "null.zone.file"; }; zone "uss.ac.th" { type master; notify no; file "null.zone.file"; }; zone "uzzepay.com.br" { type master; notify no; file "null.zone.file"; }; @@ -1068,7 +1074,6 @@ zone "vbcargo.hu" { type master; notify no; file "null.zone.file"; }; zone "vcah.co.uk" { type master; notify no; file "null.zone.file"; }; zone "vectarts.com" { type master; notify no; file "null.zone.file"; }; zone "vegadelcasero.cl" { type master; notify no; file "null.zone.file"; }; -zone "velma-harber30ku.com" { type master; notify no; file "null.zone.file"; }; zone "vendas.lidiacarmeli.com.br" { type master; notify no; file "null.zone.file"; }; zone "veterinariadrpopui.com" { type master; notify no; file "null.zone.file"; }; zone "vfocus.net" { type master; notify no; file "null.zone.file"; }; @@ -1084,7 +1089,6 @@ zone "vivationdesign.com" { type master; notify no; file "null.zone.file"; }; zone "viveirodoiscorregos.com.br" { type master; notify no; file "null.zone.file"; }; zone "vksales.com" { type master; notify no; file "null.zone.file"; }; zone "vocalterra.com" { type master; notify no; file "null.zone.file"; }; -zone "vokasi.ub.ac.id" { type master; notify no; file "null.zone.file"; }; zone "vologroup.com.br" { type master; notify no; file "null.zone.file"; }; zone "voteyouramerica.dekitout.com" { type master; notify no; file "null.zone.file"; }; zone "vpts.co.za" { type master; notify no; file "null.zone.file"; }; @@ -1105,6 +1109,7 @@ zone "webpresario.com" { type master; notify no; file "null.zone.file"; }; zone "weinsteincounseling.com" { type master; notify no; file "null.zone.file"; }; zone "wfinance.com.br" { type master; notify no; file "null.zone.file"; }; zone "whcms.yourpageserver.com" { type master; notify no; file "null.zone.file"; }; +zone "whiteglovetailgate.com" { type master; notify no; file "null.zone.file"; }; zone "whiteresponse.com" { type master; notify no; file "null.zone.file"; }; zone "wi522012.ferozo.com" { type master; notify no; file "null.zone.file"; }; zone "wikalen.co.za" { type master; notify no; file "null.zone.file"; }; @@ -1134,6 +1139,7 @@ zone "yeichner.com" { type master; notify no; file "null.zone.file"; }; zone "yeq.i.u.j.ia.n.3@zytrox.tk" { type master; notify no; file "null.zone.file"; }; zone "ylfpremium.com" { type master; notify no; file "null.zone.file"; }; zone "yoast.yourpageserver.com" { type master; notify no; file "null.zone.file"; }; +zone "yp.hnggzyjy.cn" { type master; notify no; file "null.zone.file"; }; zone "yummyyogaudaipur.com" { type master; notify no; file "null.zone.file"; }; zone "yzkzixun.com" { type master; notify no; file "null.zone.file"; }; zone "ziyker4gaming@zytrox.tk" { type master; notify no; file "null.zone.file"; }; diff --git a/urlhaus-filter-bind.conf b/urlhaus-filter-bind.conf index fc6c2636..c756e80a 100644 --- a/urlhaus-filter-bind.conf +++ b/urlhaus-filter-bind.conf @@ -1,5 +1,5 @@ # Title: Malicious Domains BIND Blocklist -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -1438,7 +1438,6 @@ zone "6481254.ru" { type master; notify no; file "null.zone.file"; }; zone "649924.nchsoftwarecom.com" { type master; notify no; file "null.zone.file"; }; zone "64x9bg.ch.files.1drv.com" { type master; notify no; file "null.zone.file"; }; zone "650x.com" { type master; notify no; file "null.zone.file"; }; -zone "654tyfcdr4654fytfy.top" { type master; notify no; file "null.zone.file"; }; zone "65k2.com" { type master; notify no; file "null.zone.file"; }; zone "66-gifts.com" { type master; notify no; file "null.zone.file"; }; zone "662ekeep6.com" { type master; notify no; file "null.zone.file"; }; @@ -1476,7 +1475,6 @@ zone "6gsdlmpym.com" { type master; notify no; file "null.zone.file"; }; zone "6gue98ddw4220152.freebackup.site" { type master; notify no; file "null.zone.file"; }; zone "6hffgq.dm.files.1drv.com" { type master; notify no; file "null.zone.file"; }; zone "6hu.xyz" { type master; notify no; file "null.zone.file"; }; -zone "6ip.us" { type master; notify no; file "null.zone.file"; }; zone "6iptv.com" { type master; notify no; file "null.zone.file"; }; zone "6itokam.com" { type master; notify no; file "null.zone.file"; }; zone "6kd743o1w.com" { type master; notify no; file "null.zone.file"; }; @@ -1869,7 +1867,6 @@ zone "a.deadnig.ga" { type master; notify no; file "null.zone.file"; }; zone "a.doko.moe" { type master; notify no; file "null.zone.file"; }; zone "a.gg.fm" { type master; notify no; file "null.zone.file"; }; zone "a.heritageandterre.com" { type master; notify no; file "null.zone.file"; }; -zone "a.pomf.cat" { type master; notify no; file "null.zone.file"; }; zone "a.pomf.se" { type master; notify no; file "null.zone.file"; }; zone "a.pomf.space" { type master; notify no; file "null.zone.file"; }; zone "a.pomf.su" { type master; notify no; file "null.zone.file"; }; @@ -6583,7 +6580,6 @@ zone "anmingsi.com" { type master; notify no; file "null.zone.file"; }; zone "anmocnhien.vn" { type master; notify no; file "null.zone.file"; }; zone "anmolanwar.com" { type master; notify no; file "null.zone.file"; }; zone "ann141.net" { type master; notify no; file "null.zone.file"; }; -zone "anna.websaiting.ru" { type master; notify no; file "null.zone.file"; }; zone "annaaluminium.annagroup.net" { type master; notify no; file "null.zone.file"; }; zone "annabelle-hamande.be" { type master; notify no; file "null.zone.file"; }; zone "annabphotography.co.uk" { type master; notify no; file "null.zone.file"; }; @@ -7098,6 +7094,7 @@ zone "app.bigplan-alex.com" { type master; notify no; file "null.zone.file"; }; zone "app.boxrcdn.com" { type master; notify no; file "null.zone.file"; }; zone "app.bridgeimpex.org" { type master; notify no; file "null.zone.file"; }; zone "app.calag.at" { type master; notify no; file "null.zone.file"; }; +zone "app.casetabs.com" { type master; notify no; file "null.zone.file"; }; zone "app.catholicchurch.co.in" { type master; notify no; file "null.zone.file"; }; zone "app.choiphui.com" { type master; notify no; file "null.zone.file"; }; zone "app.cloudindustry.net" { type master; notify no; file "null.zone.file"; }; @@ -9004,6 +9001,7 @@ zone "atpcsm.be" { type master; notify no; file "null.zone.file"; }; zone "atphitech.com" { type master; notify no; file "null.zone.file"; }; zone "atpn.ir" { type master; notify no; file "null.zone.file"; }; zone "atprofessional.org" { type master; notify no; file "null.zone.file"; }; +zone "atpscan.global.hornetsecurity.com" { type master; notify no; file "null.zone.file"; }; zone "atr.it" { type master; notify no; file "null.zone.file"; }; zone "atradex.com" { type master; notify no; file "null.zone.file"; }; zone "atragon.co.uk" { type master; notify no; file "null.zone.file"; }; @@ -9764,6 +9762,8 @@ zone "awswx.xyz" { type master; notify no; file "null.zone.file"; }; zone "awsxb.xyz" { type master; notify no; file "null.zone.file"; }; zone "awsyscloud.com" { type master; notify no; file "null.zone.file"; }; zone "awtinfostore.co.business" { type master; notify no; file "null.zone.file"; }; +zone "awumad01.top" { type master; notify no; file "null.zone.file"; }; +zone "awuqze02.top" { type master; notify no; file "null.zone.file"; }; zone "ax-yogado.com" { type master; notify no; file "null.zone.file"; }; zone "axalize.vn" { type master; notify no; file "null.zone.file"; }; zone "axalta.grupojenrab.mx" { type master; notify no; file "null.zone.file"; }; @@ -11161,6 +11161,7 @@ zone "bbfjjf8.com" { type master; notify no; file "null.zone.file"; }; zone "bbfr.cba.pl" { type master; notify no; file "null.zone.file"; }; zone "bbgiardinodoriente.it" { type master; notify no; file "null.zone.file"; }; zone "bbgk.de" { type master; notify no; file "null.zone.file"; }; +zone "bbgroup.com.vn" { type master; notify no; file "null.zone.file"; }; zone "bbh-design.de" { type master; notify no; file "null.zone.file"; }; zone "bbhdata.com" { type master; notify no; file "null.zone.file"; }; zone "bbhs.org.ng" { type master; notify no; file "null.zone.file"; }; @@ -11600,7 +11601,6 @@ zone "bekurov.org" { type master; notify no; file "null.zone.file"; }; zone "bel-med-tour.ru" { type master; notify no; file "null.zone.file"; }; zone "belabargelro.com" { type master; notify no; file "null.zone.file"; }; zone "belair.btwstudio.ch" { type master; notify no; file "null.zone.file"; }; -zone "belairinternet.com" { type master; notify no; file "null.zone.file"; }; zone "belamater.com.br" { type master; notify no; file "null.zone.file"; }; zone "belangel.by" { type master; notify no; file "null.zone.file"; }; zone "belanja-berkah.xyz" { type master; notify no; file "null.zone.file"; }; @@ -11719,7 +11719,6 @@ zone "belyi.ug" { type master; notify no; file "null.zone.file"; }; zone "belz-development.de" { type master; notify no; file "null.zone.file"; }; zone "belznerdesign.de" { type master; notify no; file "null.zone.file"; }; zone "bem.fkep.unpad.ac.id" { type master; notify no; file "null.zone.file"; }; -zone "bem.hukum.ub.ac.id" { type master; notify no; file "null.zone.file"; }; zone "bem.unimal.ac.id" { type master; notify no; file "null.zone.file"; }; zone "bemagazine.club" { type master; notify no; file "null.zone.file"; }; zone "bemakeup.ru" { type master; notify no; file "null.zone.file"; }; @@ -12492,6 +12491,7 @@ zone "bieres.lavachenoiresud.com" { type master; notify no; file "null.zone.file zone "bierne-les-villages.fr" { type master; notify no; file "null.zone.file"; }; zone "biese.eu" { type master; notify no; file "null.zone.file"; }; zone "bietthubien.org" { type master; notify no; file "null.zone.file"; }; +zone "bietthudep902.com" { type master; notify no; file "null.zone.file"; }; zone "bietthulambach.com" { type master; notify no; file "null.zone.file"; }; zone "bietthulienkegamuda.net" { type master; notify no; file "null.zone.file"; }; zone "bietthumau.com" { type master; notify no; file "null.zone.file"; }; @@ -16387,7 +16387,6 @@ zone "callonenergy.com" { type master; notify no; file "null.zone.file"; }; zone "callpetercatering.com" { type master; notify no; file "null.zone.file"; }; zone "callrealtyaz.com" { type master; notify no; file "null.zone.file"; }; zone "callshaal.com" { type master; notify no; file "null.zone.file"; }; -zone "callsmaster.com" { type master; notify no; file "null.zone.file"; }; zone "calltoprimus.ru" { type master; notify no; file "null.zone.file"; }; zone "callumstokes.com" { type master; notify no; file "null.zone.file"; }; zone "calm-tech.africa" { type master; notify no; file "null.zone.file"; }; @@ -17647,7 +17646,6 @@ zone "cdncomfortgroup.website" { type master; notify no; file "null.zone.file"; zone "cdndownloadlp.club" { type master; notify no; file "null.zone.file"; }; zone "cdnmultimedia.com" { type master; notify no; file "null.zone.file"; }; zone "cdnpic.mgyun.com" { type master; notify no; file "null.zone.file"; }; -zone "cdnrep.reimageplus.com" { type master; notify no; file "null.zone.file"; }; zone "cdnxh.net" { type master; notify no; file "null.zone.file"; }; zone "cdoconsult.com.br" { type master; notify no; file "null.zone.file"; }; zone "cdolechon.com" { type master; notify no; file "null.zone.file"; }; @@ -18439,7 +18437,6 @@ zone "cheekie2.neagoeandrei.com" { type master; notify no; file "null.zone.file" zone "cheematransxpressinc.com" { type master; notify no; file "null.zone.file"; }; zone "cheerchile.cl" { type master; notify no; file "null.zone.file"; }; zone "cheerfulgiversneverlack.com" { type master; notify no; file "null.zone.file"; }; -zone "cheerfullydo.com" { type master; notify no; file "null.zone.file"; }; zone "cheesecakery.com.br" { type master; notify no; file "null.zone.file"; }; zone "cheetahridge.mediadevstaging.com" { type master; notify no; file "null.zone.file"; }; zone "chef-solutions.dreamscape.co.in" { type master; notify no; file "null.zone.file"; }; @@ -19370,6 +19367,7 @@ zone "clarrywillow.top" { type master; notify no; file "null.zone.file"; }; zone "clarte-thailand.com" { type master; notify no; file "null.zone.file"; }; zone "clashofclansgems.nl" { type master; notify no; file "null.zone.file"; }; zone "clasificados.diaadianews.com" { type master; notify no; file "null.zone.file"; }; +zone "clasificadosmaule.com" { type master; notify no; file "null.zone.file"; }; zone "class.britishonline.co" { type master; notify no; file "null.zone.file"; }; zone "class.snph.ir" { type master; notify no; file "null.zone.file"; }; zone "classbrain.net" { type master; notify no; file "null.zone.file"; }; @@ -19667,6 +19665,7 @@ zone "clntnjkstdycloudstcy.dns.army" { type master; notify no; file "null.zone.f zone "cloakingtds.xyz" { type master; notify no; file "null.zone.file"; }; zone "clock.noixun.com" { type master; notify no; file "null.zone.file"; }; zone "clodflarechk.com" { type master; notify no; file "null.zone.file"; }; +zone "clodura.ai" { type master; notify no; file "null.zone.file"; }; zone "clone.affordable.cm" { type master; notify no; file "null.zone.file"; }; zone "clone.system-standex.dk" { type master; notify no; file "null.zone.file"; }; zone "cloned.in" { type master; notify no; file "null.zone.file"; }; @@ -19852,7 +19851,6 @@ zone "cmeaststar.de" { type master; notify no; file "null.zone.file"; }; zone "cmecobrancas.com" { type master; notify no; file "null.zone.file"; }; zone "cmelik.com" { type master; notify no; file "null.zone.file"; }; zone "cmessagers.com" { type master; notify no; file "null.zone.file"; }; -zone "cmg.asia" { type master; notify no; file "null.zone.file"; }; zone "cmg.ma" { type master; notify no; file "null.zone.file"; }; zone "cmgroup.com.ua" { type master; notify no; file "null.zone.file"; }; zone "cmhighschool.edu.bd" { type master; notify no; file "null.zone.file"; }; @@ -22391,7 +22389,6 @@ zone "cuacuonsieure.com" { type master; notify no; file "null.zone.file"; }; zone "cuadros.pe" { type master; notify no; file "null.zone.file"; }; zone "cuahangphongthuy.net" { type master; notify no; file "null.zone.file"; }; zone "cuahangstore.com" { type master; notify no; file "null.zone.file"; }; -zone "cuahangvattu.com" { type master; notify no; file "null.zone.file"; }; zone "cualtis.com" { type master; notify no; file "null.zone.file"; }; zone "cuanhomxingfanhapkhau.com" { type master; notify no; file "null.zone.file"; }; zone "cuasotinhoc.net" { type master; notify no; file "null.zone.file"; }; @@ -22820,6 +22817,7 @@ zone "d.powerofwish.com" { type master; notify no; file "null.zone.file"; }; zone "d.qiluwl.com" { type master; notify no; file "null.zone.file"; }; zone "d.teamworx.ph" { type master; notify no; file "null.zone.file"; }; zone "d.techmartbd.com" { type master; notify no; file "null.zone.file"; }; +zone "d.top4top.io" { type master; notify no; file "null.zone.file"; }; zone "d.top4top.net" { type master; notify no; file "null.zone.file"; }; zone "d.ttr3p.com" { type master; notify no; file "null.zone.file"; }; zone "d04.data39.helldata.com" { type master; notify no; file "null.zone.file"; }; @@ -24801,6 +24799,7 @@ zone "deportetotal.mx" { type master; notify no; file "null.zone.file"; }; zone "deposayim.ml" { type master; notify no; file "null.zone.file"; }; zone "depositoclara.com.br" { type master; notify no; file "null.zone.file"; }; zone "depot7.com" { type master; notify no; file "null.zone.file"; }; +zone "depozituldegeneratoare.ro" { type master; notify no; file "null.zone.file"; }; zone "depraetere.net" { type master; notify no; file "null.zone.file"; }; zone "deprealty.ru" { type master; notify no; file "null.zone.file"; }; zone "depressionted.com" { type master; notify no; file "null.zone.file"; }; @@ -26527,7 +26526,6 @@ zone "dl-45538429.onedrives-en-live.com" { type master; notify no; file "null.zo zone "dl-675423.store-downloads.com" { type master; notify no; file "null.zone.file"; }; zone "dl-80076342.md-downloads.com" { type master; notify no; file "null.zone.file"; }; zone "dl-97674424.md-downloads.com" { type master; notify no; file "null.zone.file"; }; -zone "dl-gameplayer.dmm.com" { type master; notify no; file "null.zone.file"; }; zone "dl-link.link" { type master; notify no; file "null.zone.file"; }; zone "dl-link.live" { type master; notify no; file "null.zone.file"; }; zone "dl-link.network" { type master; notify no; file "null.zone.file"; }; @@ -26550,9 +26548,9 @@ zone "dl.ikiki.cn" { type master; notify no; file "null.zone.file"; }; zone "dl.imht.ir" { type master; notify no; file "null.zone.file"; }; zone "dl.installcdn-aws.com" { type master; notify no; file "null.zone.file"; }; zone "dl.mqego.com" { type master; notify no; file "null.zone.file"; }; -zone "dl.mydown.com" { type master; notify no; file "null.zone.file"; }; zone "dl.ossdown.fun" { type master; notify no; file "null.zone.file"; }; zone "dl.packetstormsecurity.net" { type master; notify no; file "null.zone.file"; }; +zone "dl.pandasecur.com" { type master; notify no; file "null.zone.file"; }; zone "dl.popupgrade.com" { type master; notify no; file "null.zone.file"; }; zone "dl.repairlabshost.com" { type master; notify no; file "null.zone.file"; }; zone "dl.rina-roleplay.com" { type master; notify no; file "null.zone.file"; }; @@ -26729,6 +26727,9 @@ zone "dobrojutrodjevojke.com" { type master; notify no; file "null.zone.file"; } zone "dobroviz.com.ua" { type master; notify no; file "null.zone.file"; }; zone "dobrovorot.su" { type master; notify no; file "null.zone.file"; }; zone "dobsoncentral.com" { type master; notify no; file "null.zone.file"; }; +zone "doc-0s-7c-docs.googleusercontent.com" { type master; notify no; file "null.zone.file"; }; +zone "doc-10-0c-docs.googleusercontent.com" { type master; notify no; file "null.zone.file"; }; +zone "doc-10-8s-docs.googleusercontent.com" { type master; notify no; file "null.zone.file"; }; zone "doc-hub.healthycheapfast.com" { type master; notify no; file "null.zone.file"; }; zone "doc-japan.com" { type master; notify no; file "null.zone.file"; }; zone "doc.albaspizzaastoria.com" { type master; notify no; file "null.zone.file"; }; @@ -29003,6 +29004,7 @@ zone "ec2-52-56-233-157.eu-west-2.compute.amazonaws.com" { type master; notify n zone "ec2-54-207-92-161.sa-east-1.compute.amazonaws.com" { type master; notify no; file "null.zone.file"; }; zone "ec2-54-212-231-68.us-west-2.compute.amazonaws.com" { type master; notify no; file "null.zone.file"; }; zone "ec2-54-94-215-87.sa-east-1.compute.amazonaws.com" { type master; notify no; file "null.zone.file"; }; +zone "ec2euc1.boxcloud.com" { type master; notify no; file "null.zone.file"; }; zone "ec2test.ga" { type master; notify no; file "null.zone.file"; }; zone "ec3-design.com" { type master; notify no; file "null.zone.file"; }; zone "ecadigital.com" { type master; notify no; file "null.zone.file"; }; @@ -31303,6 +31305,7 @@ zone "es.thevoucherstop.com" { type master; notify no; file "null.zone.file"; }; zone "esaarc.com" { type master; notify no; file "null.zone.file"; }; zone "esacbd.com" { type master; notify no; file "null.zone.file"; }; zone "esagarautomobiles.com" { type master; notify no; file "null.zone.file"; }; +zone "esaja09.top" { type master; notify no; file "null.zone.file"; }; zone "esanjobs.org" { type master; notify no; file "null.zone.file"; }; zone "esar.weenets.com" { type master; notify no; file "null.zone.file"; }; zone "esascom.com" { type master; notify no; file "null.zone.file"; }; @@ -37097,7 +37100,6 @@ zone "genregis.com" { type master; notify no; file "null.zone.file"; }; zone "genrjw.dm.files.1drv.com" { type master; notify no; file "null.zone.file"; }; zone "genstaff.gov.kg" { type master; notify no; file "null.zone.file"; }; zone "gentcreativa.com" { type master; notify no; file "null.zone.file"; }; -zone "gentecoyol.com" { type master; notify no; file "null.zone.file"; }; zone "gentesanluis.com" { type master; notify no; file "null.zone.file"; }; zone "gentiane-salers.com" { type master; notify no; file "null.zone.file"; }; zone "gentlechirocenter.com" { type master; notify no; file "null.zone.file"; }; @@ -39846,6 +39848,7 @@ zone "gvou7g.by.files.1drv.com" { type master; notify no; file "null.zone.file"; zone "gvpcdpgc.edu.in" { type master; notify no; file "null.zone.file"; }; zone "gvpmacademy.co.za" { type master; notify no; file "null.zone.file"; }; zone "gvsme.com" { type master; notify no; file "null.zone.file"; }; +zone "gw.daelimcloud.com" { type master; notify no; file "null.zone.file"; }; zone "gw.hitlin.com" { type master; notify no; file "null.zone.file"; }; zone "gwangjuhotels.kr" { type master; notify no; file "null.zone.file"; }; zone "gwavellc.com" { type master; notify no; file "null.zone.file"; }; @@ -42657,7 +42660,6 @@ zone "hotelvip-bron.ru" { type master; notify no; file "null.zone.file"; }; zone "hotelwaldblick.com" { type master; notify no; file "null.zone.file"; }; zone "hotexpress.co" { type master; notify no; file "null.zone.file"; }; zone "hotfacts.org" { type master; notify no; file "null.zone.file"; }; -zone "hotgifts.online" { type master; notify no; file "null.zone.file"; }; zone "hotilife.com" { type master; notify no; file "null.zone.file"; }; zone "hotissue.xyz" { type master; notify no; file "null.zone.file"; }; zone "hotkine.com" { type master; notify no; file "null.zone.file"; }; @@ -43035,7 +43037,6 @@ zone "hukouec-ltd.com" { type master; notify no; file "null.zone.file"; }; zone "hukuen-motokare.xyz" { type master; notify no; file "null.zone.file"; }; zone "hukuki.site" { type master; notify no; file "null.zone.file"; }; zone "hukukportal.com" { type master; notify no; file "null.zone.file"; }; -zone "hukum.ub.ac.id" { type master; notify no; file "null.zone.file"; }; zone "hukum.unwiku.ac.id" { type master; notify no; file "null.zone.file"; }; zone "hulianwang114.com" { type master; notify no; file "null.zone.file"; }; zone "huliot.in" { type master; notify no; file "null.zone.file"; }; @@ -43357,6 +43358,7 @@ zone "i-sharecloud.com" { type master; notify no; file "null.zone.file"; }; zone "i-supportcharity.com" { type master; notify no; file "null.zone.file"; }; zone "i-vnsweyu.pl" { type master; notify no; file "null.zone.file"; }; zone "i-voda.com" { type master; notify no; file "null.zone.file"; }; +zone "i.fiery.me" { type master; notify no; file "null.zone.file"; }; zone "i.fluffy.cc" { type master; notify no; file "null.zone.file"; }; zone "i.funtourspt.eu" { type master; notify no; file "null.zone.file"; }; zone "i.n.t.e.rloca.l.qs.j.y@jfas.top" { type master; notify no; file "null.zone.file"; }; @@ -46637,6 +46639,7 @@ zone "itspread.com" { type master; notify no; file "null.zone.file"; }; zone "itspsc.com.ua" { type master; notify no; file "null.zone.file"; }; zone "itspueh.nl" { type master; notify no; file "null.zone.file"; }; zone "itsquare.yrcreations.com" { type master; notify no; file "null.zone.file"; }; +zone "itsrlytry.000webhostapp.com" { type master; notify no; file "null.zone.file"; }; zone "itssprout.com" { type master; notify no; file "null.zone.file"; }; zone "itstelecom.com.br" { type master; notify no; file "null.zone.file"; }; zone "itsweezle.com" { type master; notify no; file "null.zone.file"; }; @@ -46836,6 +46839,7 @@ zone "j-skill.ru" { type master; notify no; file "null.zone.file"; }; zone "j-stage.jp" { type master; notify no; file "null.zone.file"; }; zone "j-toputvoutfitters.com" { type master; notify no; file "null.zone.file"; }; zone "j.kyryl.ru" { type master; notify no; file "null.zone.file"; }; +zone "j.top4top.io" { type master; notify no; file "null.zone.file"; }; zone "j11g9xecuxe43xu.xyz" { type master; notify no; file "null.zone.file"; }; zone "j12z7407gwtzk.xyz" { type master; notify no; file "null.zone.file"; }; zone "j13.biz" { type master; notify no; file "null.zone.file"; }; @@ -46968,6 +46972,7 @@ zone "jaipurjungle.co.in" { type master; notify no; file "null.zone.file"; }; zone "jaipurweddingphotography.com" { type master; notify no; file "null.zone.file"; }; zone "jairathsnatural.ca" { type master; notify no; file "null.zone.file"; }; zone "jairozapata.000webhostapp.com" { type master; notify no; file "null.zone.file"; }; +zone "jaishomo.info" { type master; notify no; file "null.zone.file"; }; zone "jaishritours.com" { type master; notify no; file "null.zone.file"; }; zone "jaiswalsupplement.com" { type master; notify no; file "null.zone.file"; }; zone "jajadomains.com" { type master; notify no; file "null.zone.file"; }; @@ -50996,7 +51001,6 @@ zone "kodiakpro.ca" { type master; notify no; file "null.zone.file"; }; zone "kodim0112sabang.com" { type master; notify no; file "null.zone.file"; }; zone "kodingeko.com" { type master; notify no; file "null.zone.file"; }; zone "kodip.nfile.net" { type master; notify no; file "null.zone.file"; }; -zone "kodjdsjsdjf.tk" { type master; notify no; file "null.zone.file"; }; zone "kodlacan.site" { type master; notify no; file "null.zone.file"; }; zone "kodmuje.com" { type master; notify no; file "null.zone.file"; }; zone "kodolios.000webhostapp.com" { type master; notify no; file "null.zone.file"; }; @@ -53636,6 +53640,7 @@ zone "library.arihantmbainstitute.ac.in" { type master; notify no; file "null.zo zone "library.cifor.org" { type master; notify no; file "null.zone.file"; }; zone "library.dhl-xom.com" { type master; notify no; file "null.zone.file"; }; zone "library.iainbengkulu.ac.id" { type master; notify no; file "null.zone.file"; }; +zone "library.mju.ac.th" { type master; notify no; file "null.zone.file"; }; zone "library.phibi.my.id" { type master; notify no; file "null.zone.file"; }; zone "library.piet.co.in" { type master; notify no; file "null.zone.file"; }; zone "library.strophicmusic.com" { type master; notify no; file "null.zone.file"; }; @@ -54322,7 +54327,6 @@ zone "livechallenge.fr" { type master; notify no; file "null.zone.file"; }; zone "livecigarevent.com" { type master; notify no; file "null.zone.file"; }; zone "livecricketscorecard.info" { type master; notify no; file "null.zone.file"; }; zone "livedaynews.com" { type master; notify no; file "null.zone.file"; }; -zone "livedemo00.template-help.com" { type master; notify no; file "null.zone.file"; }; zone "livedownload.in" { type master; notify no; file "null.zone.file"; }; zone "livedrumtracks.com" { type master; notify no; file "null.zone.file"; }; zone "livefarma.com" { type master; notify no; file "null.zone.file"; }; @@ -54355,7 +54359,6 @@ zone "livesouvenir.com" { type master; notify no; file "null.zone.file"; }; zone "livestreams.vn" { type master; notify no; file "null.zone.file"; }; zone "livesuitesapartdaire.com" { type master; notify no; file "null.zone.file"; }; zone "livesurgerycourse.ir" { type master; notify no; file "null.zone.file"; }; -zone "liveswinburneeduau-my.sharepoint.com" { type master; notify no; file "null.zone.file"; }; zone "liveswindow.casa" { type master; notify no; file "null.zone.file"; }; zone "liveswindow.cyou" { type master; notify no; file "null.zone.file"; }; zone "liveswindows.bar" { type master; notify no; file "null.zone.file"; }; @@ -55530,7 +55533,6 @@ zone "luzbarbosa.com.br" { type master; notify no; file "null.zone.file"; }; zone "luzconsulting.com.br" { type master; notify no; file "null.zone.file"; }; zone "luzevida.com.br" { type master; notify no; file "null.zone.file"; }; zone "luzfloral.com" { type master; notify no; file "null.zone.file"; }; -zone "luzy.vn" { type master; notify no; file "null.zone.file"; }; zone "luzzeri.com" { type master; notify no; file "null.zone.file"; }; zone "lvajnczdy.cf" { type master; notify no; file "null.zone.file"; }; zone "lvcfund.org.vn" { type master; notify no; file "null.zone.file"; }; @@ -58568,7 +58570,6 @@ zone "mecflui.com.br" { type master; notify no; file "null.zone.file"; }; zone "mecgwl.ac.in" { type master; notify no; file "null.zone.file"; }; zone "mechanicaltools.club" { type master; notify no; file "null.zone.file"; }; zone "mechanicsthatcometoyou.com" { type master; notify no; file "null.zone.file"; }; -zone "mecharnise.ir" { type master; notify no; file "null.zone.file"; }; zone "mechathrones.com" { type master; notify no; file "null.zone.file"; }; zone "mechauto.co.za" { type master; notify no; file "null.zone.file"; }; zone "mechdesign.com" { type master; notify no; file "null.zone.file"; }; @@ -59154,7 +59155,6 @@ zone "menxhiqi.com" { type master; notify no; file "null.zone.file"; }; zone "menziesadvisory-my.sharepoint.com" { type master; notify no; file "null.zone.file"; }; zone "menzway.com" { type master; notify no; file "null.zone.file"; }; zone "meogiambeo.com" { type master; notify no; file "null.zone.file"; }; -zone "meohaybotui.com" { type master; notify no; file "null.zone.file"; }; zone "meolamdephay.com" { type master; notify no; file "null.zone.file"; }; zone "mepsgen.com" { type master; notify no; file "null.zone.file"; }; zone "mera.ddns.net" { type master; notify no; file "null.zone.file"; }; @@ -59472,6 +59472,7 @@ zone "mfmr.gov.sl" { type master; notify no; file "null.zone.file"; }; zone "mfomjr.com" { type master; notify no; file "null.zone.file"; }; zone "mfotovideo.ro" { type master; notify no; file "null.zone.file"; }; zone "mfpburundi.bi" { type master; notify no; file "null.zone.file"; }; +zone "mfpc.org.my" { type master; notify no; file "null.zone.file"; }; zone "mfppanel.xyz" { type master; notify no; file "null.zone.file"; }; zone "mfpvision.com" { type master; notify no; file "null.zone.file"; }; zone "mfronza.com.br" { type master; notify no; file "null.zone.file"; }; @@ -64504,7 +64505,6 @@ zone "nhadatphonglinh.com" { type master; notify no; file "null.zone.file"; }; zone "nhadatquan2.xyz" { type master; notify no; file "null.zone.file"; }; zone "nhadatthienthoi.com" { type master; notify no; file "null.zone.file"; }; zone "nhadephungyen.com" { type master; notify no; file "null.zone.file"; }; -zone "nhadepkientruc.net" { type master; notify no; file "null.zone.file"; }; zone "nhahangdaihung.com" { type master; notify no; file "null.zone.file"; }; zone "nhahanghaivuong.vn" { type master; notify no; file "null.zone.file"; }; zone "nhahanglegiang.vn" { type master; notify no; file "null.zone.file"; }; @@ -64718,7 +64718,6 @@ zone "nikanbearing.com" { type master; notify no; file "null.zone.file"; }; zone "nikanpolimer.ir" { type master; notify no; file "null.zone.file"; }; zone "nikastroi.ru" { type master; notify no; file "null.zone.file"; }; zone "nikavkuchyni.sk" { type master; notify no; file "null.zone.file"; }; -zone "nikayu.com" { type master; notify no; file "null.zone.file"; }; zone "nikbox.ru" { type master; notify no; file "null.zone.file"; }; zone "nikeshyadav.com" { type master; notify no; file "null.zone.file"; }; zone "nikhil.webscript.co.in" { type master; notify no; file "null.zone.file"; }; @@ -67234,7 +67233,6 @@ zone "optimusforce.nl" { type master; notify no; file "null.zone.file"; }; zone "option47.us" { type master; notify no; file "null.zone.file"; }; zone "optioncapitalgroup.ru" { type master; notify no; file "null.zone.file"; }; zone "optionrp.com" { type master; notify no; file "null.zone.file"; }; -zone "optionscity.com" { type master; notify no; file "null.zone.file"; }; zone "optisaving.com" { type master; notify no; file "null.zone.file"; }; zone "optitechsa.co.za" { type master; notify no; file "null.zone.file"; }; zone "optocen.ru" { type master; notify no; file "null.zone.file"; }; @@ -67529,7 +67527,6 @@ zone "osethmaayurveda.com" { type master; notify no; file "null.zone.file"; }; zone "osezrayonner.ma" { type master; notify no; file "null.zone.file"; }; zone "osgbforum.com" { type master; notify no; file "null.zone.file"; }; zone "oshattorney.com" { type master; notify no; file "null.zone.file"; }; -zone "oshi.at" { type master; notify no; file "null.zone.file"; }; zone "oshodrycleaning.com" { type master; notify no; file "null.zone.file"; }; zone "oshonafitness.com" { type master; notify no; file "null.zone.file"; }; zone "oshop.es" { type master; notify no; file "null.zone.file"; }; @@ -71229,7 +71226,6 @@ zone "posmaster.co.kr" { type master; notify no; file "null.zone.file"; }; zone "posmicrosystems.com" { type master; notify no; file "null.zone.file"; }; zone "posnxqmp.ru" { type master; notify no; file "null.zone.file"; }; zone "pospeeps.com" { type master; notify no; file "null.zone.file"; }; -zone "posqit.net" { type master; notify no; file "null.zone.file"; }; zone "possessionnow.com" { type master; notify no; file "null.zone.file"; }; zone "possible.re" { type master; notify no; file "null.zone.file"; }; zone "possopagar.com.br" { type master; notify no; file "null.zone.file"; }; @@ -71865,7 +71861,6 @@ zone "prishaartcreations.com" { type master; notify no; file "null.zone.file"; } zone "prisidmart.com" { type master; notify no; file "null.zone.file"; }; zone "priskat.net" { type master; notify no; file "null.zone.file"; }; zone "prism-photo.com" { type master; notify no; file "null.zone.file"; }; -zone "prisma.fp.ub.ac.id" { type master; notify no; file "null.zone.file"; }; zone "prismaxis.com" { type master; notify no; file "null.zone.file"; }; zone "prismfox.com" { type master; notify no; file "null.zone.file"; }; zone "prismware.ml" { type master; notify no; file "null.zone.file"; }; @@ -72457,6 +72452,7 @@ zone "protech.binarybizz.com" { type master; notify no; file "null.zone.file"; } zone "protech.mn" { type master; notify no; file "null.zone.file"; }; zone "protechcarpetcare.com" { type master; notify no; file "null.zone.file"; }; zone "protechgroup1.com" { type master; notify no; file "null.zone.file"; }; +zone "protect.mimecast-offshore.com" { type master; notify no; file "null.zone.file"; }; zone "protectiadatelor.biz" { type master; notify no; file "null.zone.file"; }; zone "protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org" { type master; notify no; file "null.zone.file"; }; zone "protection.pecol.eu" { type master; notify no; file "null.zone.file"; }; @@ -72538,6 +72534,7 @@ zone "proxima-solution.com" { type master; notify no; file "null.zone.file"; }; zone "proxy-ipv4.com" { type master; notify no; file "null.zone.file"; }; zone "proxy.2u0apcm6ylhdy7s.com" { type master; notify no; file "null.zone.file"; }; zone "proxy.hueaudio.com" { type master; notify no; file "null.zone.file"; }; +zone "proxy.qualtrics.com" { type master; notify no; file "null.zone.file"; }; zone "proxygrnd.xyz" { type master; notify no; file "null.zone.file"; }; zone "proxyholding.com" { type master; notify no; file "null.zone.file"; }; zone "proxyresume.com" { type master; notify no; file "null.zone.file"; }; @@ -75051,6 +75048,7 @@ zone "redlk.com" { type master; notify no; file "null.zone.file"; }; zone "redlogisticsmaroc.com" { type master; notify no; file "null.zone.file"; }; zone "redloop.io" { type master; notify no; file "null.zone.file"; }; zone "redlotusevents.com" { type master; notify no; file "null.zone.file"; }; +zone "redm1az1.000webhostapp.com" { type master; notify no; file "null.zone.file"; }; zone "redmag.by" { type master; notify no; file "null.zone.file"; }; zone "redmarcial.ossmarcial.com" { type master; notify no; file "null.zone.file"; }; zone "redmediasigns.com" { type master; notify no; file "null.zone.file"; }; @@ -76222,6 +76220,7 @@ zone "rkbicycle.com" { type master; notify no; file "null.zone.file"; }; zone "rkcable.co.in" { type master; notify no; file "null.zone.file"; }; zone "rkfplumbing.co.uk" { type master; notify no; file "null.zone.file"; }; zone "rkinstitute.org" { type master; notify no; file "null.zone.file"; }; +zone "rkkrstdygorgiousejbg.dns.army" { type master; notify no; file "null.zone.file"; }; zone "rkkrstdygorgiousejds.dns.army" { type master; notify no; file "null.zone.file"; }; zone "rkkrstdygorgiousejtw.dns.army" { type master; notify no; file "null.zone.file"; }; zone "rklkpgcollege.com" { type master; notify no; file "null.zone.file"; }; @@ -76778,6 +76777,7 @@ zone "rotiyes.co.id" { type master; notify no; file "null.zone.file"; }; zone "rotoblast.org" { type master; notify no; file "null.zone.file"; }; zone "rotor.olsztyn.pl" { type master; notify no; file "null.zone.file"; }; zone "rotoscoop.com" { type master; notify no; file "null.zone.file"; }; +zone "rotronics.com.ph" { type master; notify no; file "null.zone.file"; }; zone "rott-mtr.de" { type master; notify no; file "null.zone.file"; }; zone "rotterdammeetings.nl" { type master; notify no; file "null.zone.file"; }; zone "rotulosalarcon.com" { type master; notify no; file "null.zone.file"; }; @@ -77191,7 +77191,6 @@ zone "runmagazine.es" { type master; notify no; file "null.zone.file"; }; zone "runmureed.com" { type master; notify no; file "null.zone.file"; }; zone "runmyweb.com" { type master; notify no; file "null.zone.file"; }; zone "runnected.kaiman.fr" { type master; notify no; file "null.zone.file"; }; -zone "runnerbd.com" { type master; notify no; file "null.zone.file"; }; zone "runnerschool.com" { type master; notify no; file "null.zone.file"; }; zone "running-bike.com" { type master; notify no; file "null.zone.file"; }; zone "runningcrewteam.com" { type master; notify no; file "null.zone.file"; }; @@ -78713,6 +78712,7 @@ zone "savemodificationgloballyfromthepinaltypo.duckdns.org" { type master; notif zone "savemyfile.3utilities.com" { type master; notify no; file "null.zone.file"; }; zone "savemyseatnow.com" { type master; notify no; file "null.zone.file"; }; zone "saveraahealthcare.com" { type master; notify no; file "null.zone.file"; }; +zone "saveserpnow.com" { type master; notify no; file "null.zone.file"; }; zone "saveserpresults.com" { type master; notify no; file "null.zone.file"; }; zone "savestudio.com" { type master; notify no; file "null.zone.file"; }; zone "savetax.idfcmf.com" { type master; notify no; file "null.zone.file"; }; @@ -79390,6 +79390,7 @@ zone "secure-net.tech" { type master; notify no; file "null.zone.file"; }; zone "secure-risk.namaskara.me" { type master; notify no; file "null.zone.file"; }; zone "secure-snupa.com" { type master; notify no; file "null.zone.file"; }; zone "secure.accounts.resourses.com" { type master; notify no; file "null.zone.file"; }; +zone "secure.activedirect.xyz" { type master; notify no; file "null.zone.file"; }; zone "secure.anchorssb.co" { type master; notify no; file "null.zone.file"; }; zone "secure.app-amazon.com.recovery-account.amazon.com.alphatravelmongolia.com" { type master; notify no; file "null.zone.file"; }; zone "secure.bodybuilderabs.net" { type master; notify no; file "null.zone.file"; }; @@ -80067,7 +80068,6 @@ zone "service.atlink.ir" { type master; notify no; file "null.zone.file"; }; zone "service.dawat.fr" { type master; notify no; file "null.zone.file"; }; zone "service.drnjithendran.com" { type master; notify no; file "null.zone.file"; }; zone "service.eftformotherissues.com" { type master; notify no; file "null.zone.file"; }; -zone "service.ezsoftwareupdater.com" { type master; notify no; file "null.zone.file"; }; zone "service.heritageimagingcenter.com" { type master; notify no; file "null.zone.file"; }; zone "service.hybridhomesteam.com" { type master; notify no; file "null.zone.file"; }; zone "service.idealfurnitureoutlet.com" { type master; notify no; file "null.zone.file"; }; @@ -80572,6 +80572,7 @@ zone "shareallfilesthroughsecureexchangesystem.duckdns.org" { type master; notif zone "sharebook.tk" { type master; notify no; file "null.zone.file"; }; zone "sharechautari.com" { type master; notify no; file "null.zone.file"; }; zone "shared-cnd.com" { type master; notify no; file "null.zone.file"; }; +zone "shared.outlook.inky.com" { type master; notify no; file "null.zone.file"; }; zone "shareddocuments.ml" { type master; notify no; file "null.zone.file"; }; zone "shareddynamics.com" { type master; notify no; file "null.zone.file"; }; zone "sharedeconomy.eu" { type master; notify no; file "null.zone.file"; }; @@ -84935,9 +84936,11 @@ zone "stdymjventsluzcafoik.dns.army" { type master; notify no; file "null.zone.f zone "stdymjventsluzcafsrp.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stdymorcmmylntwincdq.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stdymorcmmylntwinstr.dns.army" { type master; notify no; file "null.zone.file"; }; +zone "stdynbnbnewagedevixz.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stdynbnbnewagedevsmn.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stdynbnbnewagedevxaz.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stdyneverwalkachinese2loneinlifekstgqm.ydns.eu" { type master; notify no; file "null.zone.file"; }; +zone "stdynmxwllminoragest.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stdyperezluzcafeyzst.dns.navy" { type master; notify no; file "null.zone.file"; }; zone "stdypmrimelimtwstogy.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stdypycsslwinnerscot.dns.army" { type master; notify no; file "null.zone.file"; }; @@ -84968,6 +84971,7 @@ zone "stdytoprehtwoyertwfd.dns.army" { type master; notify no; file "null.zone.f zone "stdytopreoneenversrw.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stdytopreoneenvervaj.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu" { type master; notify no; file "null.zone.file"; }; +zone "stdyunitedkesokokgst.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stdyunitedkesokostdr.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stdyunitedkesokostri.dns.navy" { type master; notify no; file "null.zone.file"; }; zone "stdyunitedkesokostxc.dns.army" { type master; notify no; file "null.zone.file"; }; @@ -84977,7 +84981,9 @@ zone "stdyworkfineanotherrainbowlomoyentstbmd.duckdns.org" { type master; notify zone "stdyworkfineanotherrainbowlomoyentwkgls.duckdns.org" { type master; notify no; file "null.zone.file"; }; zone "stdyworkfinesanotherrainbowlomoyentstfcp.ydns.eu" { type master; notify no; file "null.zone.file"; }; zone "stdyworkfinesanotherrainbowlomoyentstgot.ydns.eu" { type master; notify no; file "null.zone.file"; }; +zone "stdyworkfinetraingst.dns.army" { type master; notify no; file "null.zone.file"; }; zone "stdyzgchgcloudgostgt.dns.army" { type master; notify no; file "null.zone.file"; }; +zone "stdyzgchgcloudgostxs.dns.army" { type master; notify no; file "null.zone.file"; }; zone "steadyrestmanufacturers.com" { type master; notify no; file "null.zone.file"; }; zone "steak.wpress.dk" { type master; notify no; file "null.zone.file"; }; zone "steakhouse.com.ua" { type master; notify no; file "null.zone.file"; }; @@ -85537,6 +85543,7 @@ zone "strend.net" { type master; notify no; file "null.zone.file"; }; zone "strengthandvigour.com" { type master; notify no; file "null.zone.file"; }; zone "strengthrer.com" { type master; notify no; file "null.zone.file"; }; zone "strenover.ga" { type master; notify no; file "null.zone.file"; }; +zone "stressing.pw" { type master; notify no; file "null.zone.file"; }; zone "stressnada.com" { type master; notify no; file "null.zone.file"; }; zone "stretchpilates.fit" { type master; notify no; file "null.zone.file"; }; zone "strewn.org" { type master; notify no; file "null.zone.file"; }; @@ -86228,6 +86235,7 @@ zone "supercrystal.am" { type master; notify no; file "null.zone.file"; }; zone "supercutscissors.com" { type master; notify no; file "null.zone.file"; }; zone "superdad.id" { type master; notify no; file "null.zone.file"; }; zone "superdigitalguy.xyz" { type master; notify no; file "null.zone.file"; }; +zone "superdomain1709.info" { type master; notify no; file "null.zone.file"; }; zone "superdot.rs" { type master; notify no; file "null.zone.file"; }; zone "superecruiters.com" { type master; notify no; file "null.zone.file"; }; zone "superfacil.center" { type master; notify no; file "null.zone.file"; }; @@ -86331,7 +86339,6 @@ zone "support.m2mservices.com" { type master; notify no; file "null.zone.file"; zone "support.mdsol.com" { type master; notify no; file "null.zone.file"; }; zone "support.nordenrecycling.com" { type master; notify no; file "null.zone.file"; }; zone "support.nuvemit.com" { type master; notify no; file "null.zone.file"; }; -zone "support.pubg.com" { type master; notify no; file "null.zone.file"; }; zone "support.redbook.aero" { type master; notify no; file "null.zone.file"; }; zone "support.revolus.xyz" { type master; notify no; file "null.zone.file"; }; zone "support.servu.co.uk" { type master; notify no; file "null.zone.file"; }; @@ -86676,7 +86683,6 @@ zone "swiat-ksiegowosci.pl" { type master; notify no; file "null.zone.file"; }; zone "swicoservers.co.uk" { type master; notify no; file "null.zone.file"; }; zone "swieradowbiega.pl" { type master; notify no; file "null.zone.file"; }; zone "swifck.xmr.ac" { type master; notify no; file "null.zone.file"; }; -zone "swift-cloud.com" { type master; notify no; file "null.zone.file"; }; zone "swiftbusinesspay.com" { type master; notify no; file "null.zone.file"; }; zone "swiftee.co.uk" { type master; notify no; file "null.zone.file"; }; zone "swiftender.com" { type master; notify no; file "null.zone.file"; }; @@ -87521,7 +87527,6 @@ zone "tarexfinal.trade" { type master; notify no; file "null.zone.file"; }; zone "targas.de" { type master; notify no; file "null.zone.file"; }; zone "targat-china.com" { type master; notify no; file "null.zone.file"; }; zone "target-events.com" { type master; notify no; file "null.zone.file"; }; -zone "target-support.online" { type master; notify no; file "null.zone.file"; }; zone "target2cloud.com" { type master; notify no; file "null.zone.file"; }; zone "targetbizbd.com" { type master; notify no; file "null.zone.file"; }; zone "targetcm.net" { type master; notify no; file "null.zone.file"; }; @@ -89102,7 +89107,6 @@ zone "thacci.com.br" { type master; notify no; file "null.zone.file"; }; zone "thachastew.com" { type master; notify no; file "null.zone.file"; }; zone "thachvietstone.com" { type master; notify no; file "null.zone.file"; }; zone "thadathilfarmresort.com" { type master; notify no; file "null.zone.file"; }; -zone "thaddeusarmstrong.com" { type master; notify no; file "null.zone.file"; }; zone "thadinnoo.co" { type master; notify no; file "null.zone.file"; }; zone "thagreymatter.com" { type master; notify no; file "null.zone.file"; }; zone "thai-chana.asia" { type master; notify no; file "null.zone.file"; }; @@ -90824,7 +90828,6 @@ zone "tlcc.com.gt" { type master; notify no; file "null.zone.file"; }; zone "tlcid.org" { type master; notify no; file "null.zone.file"; }; zone "tlckids-or.ga" { type master; notify no; file "null.zone.file"; }; zone "tlcmoto.com" { type master; notify no; file "null.zone.file"; }; -zone "tldrbox.top" { type master; notify no; file "null.zone.file"; }; zone "tldrnet.top" { type master; notify no; file "null.zone.file"; }; zone "tlextreme.com" { type master; notify no; file "null.zone.file"; }; zone "tlfthelifefactory.com.au" { type master; notify no; file "null.zone.file"; }; @@ -92421,6 +92424,7 @@ zone "ts-deals.me" { type master; notify no; file "null.zone.file"; }; zone "ts.7rb.xyz" { type master; notify no; file "null.zone.file"; }; zone "ts0ev73.com" { type master; notify no; file "null.zone.file"; }; zone "tsal.com" { type master; notify no; file "null.zone.file"; }; +zone "tsapparel.com.my" { type master; notify no; file "null.zone.file"; }; zone "tsareva-garden.ru" { type master; notify no; file "null.zone.file"; }; zone "tsatsi.co.za" { type master; notify no; file "null.zone.file"; }; zone "tsauctions.com" { type master; notify no; file "null.zone.file"; }; @@ -92648,6 +92652,7 @@ zone "tunnelpros.com" { type master; notify no; file "null.zone.file"; }; zone "tunnelview.co.uk" { type master; notify no; file "null.zone.file"; }; zone "tunuvo.com" { type master; notify no; file "null.zone.file"; }; zone "tuobrasocial.com.ar" { type master; notify no; file "null.zone.file"; }; +zone "tuoitrethainguyen.vn" { type master; notify no; file "null.zone.file"; }; zone "tupibaje.com" { type master; notify no; file "null.zone.file"; }; zone "tupperware.michaelroberge.ca" { type master; notify no; file "null.zone.file"; }; zone "tur.000webhostapp.com" { type master; notify no; file "null.zone.file"; }; @@ -93794,7 +93799,6 @@ zone "unlimit517.co.jp" { type master; notify no; file "null.zone.file"; }; zone "unlimited.nu" { type master; notify no; file "null.zone.file"; }; zone "unlimitedbags.club" { type master; notify no; file "null.zone.file"; }; zone "unlimitedfreightco.com" { type master; notify no; file "null.zone.file"; }; -zone "unlimitedimportandexport.com" { type master; notify no; file "null.zone.file"; }; zone "unlock-king.com" { type master; notify no; file "null.zone.file"; }; zone "unlock2.neagoeandrei.com" { type master; notify no; file "null.zone.file"; }; zone "unlockall.neagoeandrei.com" { type master; notify no; file "null.zone.file"; }; @@ -94120,6 +94124,7 @@ zone "url-update.com" { type master; notify no; file "null.zone.file"; }; zone "url-validation-clients.com" { type master; notify no; file "null.zone.file"; }; zone "url.246546.com" { type master; notify no; file "null.zone.file"; }; zone "url.57569.fr.snd52.ch" { type master; notify no; file "null.zone.file"; }; +zone "url2.mailanyone.net" { type master; notify no; file "null.zone.file"; }; zone "url3.mailanyone.net" { type master; notify no; file "null.zone.file"; }; zone "url5459.41southbar.com" { type master; notify no; file "null.zone.file"; }; zone "url675.textilmallorca.com" { type master; notify no; file "null.zone.file"; }; @@ -94323,7 +94328,6 @@ zone "utterstock.in" { type master; notify no; file "null.zone.file"; }; zone "utting.org" { type master; notify no; file "null.zone.file"; }; zone "utv.sakeronline.se" { type master; notify no; file "null.zone.file"; }; zone "utv1.enliden.net" { type master; notify no; file "null.zone.file"; }; -zone "uujian.cn" { type master; notify no; file "null.zone.file"; }; zone "uumove.com" { type master; notify no; file "null.zone.file"; }; zone "uurty87e8rt7rt.com" { type master; notify no; file "null.zone.file"; }; zone "uutiset.helppokoti.fi" { type master; notify no; file "null.zone.file"; }; @@ -96297,7 +96301,6 @@ zone "voin.staysafe.pk" { type master; notify no; file "null.zone.file"; }; zone "voingani.it" { type master; notify no; file "null.zone.file"; }; zone "voip96.ru" { type master; notify no; file "null.zone.file"; }; zone "voipminic.com" { type master; notify no; file "null.zone.file"; }; -zone "vokasi.ub.ac.id" { type master; notify no; file "null.zone.file"; }; zone "vokzalrf.ru" { type master; notify no; file "null.zone.file"; }; zone "vol.agency" { type master; notify no; file "null.zone.file"; }; zone "vol2.pw" { type master; notify no; file "null.zone.file"; }; @@ -96925,7 +96928,6 @@ zone "washnworks.com" { type master; notify no; file "null.zone.file"; }; zone "washuis.nl" { type master; notify no; file "null.zone.file"; }; zone "wasidora.com" { type master; notify no; file "null.zone.file"; }; zone "wasilewski-online.de" { type master; notify no; file "null.zone.file"; }; -zone "wasimjee.com" { type master; notify no; file "null.zone.file"; }; zone "wasino.co.th" { type master; notify no; file "null.zone.file"; }; zone "wasobd.net" { type master; notify no; file "null.zone.file"; }; zone "waspha.com" { type master; notify no; file "null.zone.file"; }; @@ -98465,7 +98467,6 @@ zone "woaldi2.com" { type master; notify no; file "null.zone.file"; }; zone "woatinkwoo.com" { type master; notify no; file "null.zone.file"; }; zone "woclawoffers.fun" { type master; notify no; file "null.zone.file"; }; zone "wocomm.marketingmindz.com" { type master; notify no; file "null.zone.file"; }; -zone "wodfitapparel.fr" { type master; notify no; file "null.zone.file"; }; zone "wodmetaldom.pl" { type master; notify no; file "null.zone.file"; }; zone "wodsuit.com" { type master; notify no; file "null.zone.file"; }; zone "woelf.in" { type master; notify no; file "null.zone.file"; }; @@ -101094,7 +101095,9 @@ zone "yoyoplease.com" { type master; notify no; file "null.zone.file"; }; zone "yoyoso.nz" { type master; notify no; file "null.zone.file"; }; zone "yoyoteacher.cn" { type master; notify no; file "null.zone.file"; }; zone "yp.dcyazilim.com" { type master; notify no; file "null.zone.file"; }; +zone "yp.hnggzyjy.cn" { type master; notify no; file "null.zone.file"; }; zone "ypbb.or.id" { type master; notify no; file "null.zone.file"; }; +zone "ypddf.org" { type master; notify no; file "null.zone.file"; }; zone "ypicsdy.cf" { type master; notify no; file "null.zone.file"; }; zone "ypko-55.gq" { type master; notify no; file "null.zone.file"; }; zone "ypom.com.br" { type master; notify no; file "null.zone.file"; }; @@ -101253,7 +101256,6 @@ zone "yusukelife.com" { type master; notify no; file "null.zone.file"; }; zone "yuti.kr" { type master; notify no; file "null.zone.file"; }; zone "yuvann.com" { type master; notify no; file "null.zone.file"; }; zone "yuvikadvertisments.com" { type master; notify no; file "null.zone.file"; }; -zone "yuwaraja.vokasi.ub.ac.id" { type master; notify no; file "null.zone.file"; }; zone "yuweis.com" { type master; notify no; file "null.zone.file"; }; zone "yuxigon.com" { type master; notify no; file "null.zone.file"; }; zone "yuxuanknit.com" { type master; notify no; file "null.zone.file"; }; diff --git a/urlhaus-filter-dnsmasq-online.conf b/urlhaus-filter-dnsmasq-online.conf index ad2c812f..861d7b4f 100644 --- a/urlhaus-filter-dnsmasq-online.conf +++ b/urlhaus-filter-dnsmasq-online.conf @@ -1,5 +1,5 @@ # Title: Online Malicious Domains dnsmasq Blocklist -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -33,7 +33,6 @@ address=/addahealingmusic.com/0.0.0.0 address=/adithimedia.com/0.0.0.0 address=/adithimedia.memengers.com/0.0.0.0 address=/admin.erapor.smk-alasror.net/0.0.0.0 -address=/admin.gentbcn.org/0.0.0.0 address=/admin.grandoceanvilla.com/0.0.0.0 address=/admission.kmctartskuttippuram.org/0.0.0.0 address=/adventureexplorer.in/0.0.0.0 @@ -49,6 +48,7 @@ address=/aiecons.com/0.0.0.0 address=/aiqtest.com/0.0.0.0 address=/ajpharmaholding.com/0.0.0.0 address=/akdvidyalaya.com/0.0.0.0 +address=/al-wahd.com/0.0.0.0 address=/alasdemariposas.org/0.0.0.0 address=/alberts.diamondrelationscrm.us/0.0.0.0 address=/alemelektronik.com/0.0.0.0 @@ -86,7 +86,6 @@ address=/aps-sv.com/0.0.0.0 address=/artedibujoyarquitectura.com/0.0.0.0 address=/arwenyapi.com/0.0.0.0 address=/ask-regard.call-save.biz/0.0.0.0 -address=/asucssa.live/0.0.0.0 address=/atfile.com/0.0.0.0 address=/athenacapsg.com/0.0.0.0 address=/atlasconcreteworks.com/0.0.0.0 @@ -98,15 +97,17 @@ address=/australianpga.com.au/0.0.0.0 address=/automaticrefreshments.com/0.0.0.0 address=/avadhanagames.com/0.0.0.0 address=/aventuramotorhome.com/0.0.0.0 +address=/awumad01.top/0.0.0.0 +address=/awuqze02.top/0.0.0.0 address=/ayahuascasp.com.br/0.0.0.0 address=/ayamallah.com/0.0.0.0 -address=/aycconsultoriaempresarial.com/0.0.0.0 address=/azmeasurement.com/0.0.0.0 address=/azraktours.com/0.0.0.0 address=/b.r.uce.lee.b.es.t@zytrox.tk/0.0.0.0 address=/b2b.toptanakaryakit.com.tr/0.0.0.0 address=/backgrounds.pk/0.0.0.0 address=/badeggdesign.com/0.0.0.0 +address=/bakamla.go.id/0.0.0.0 address=/balealgodon.mx/0.0.0.0 address=/bangkok-orchids.com/0.0.0.0 address=/bangladeshunbound.com/0.0.0.0 @@ -127,7 +128,6 @@ address=/beor360.com/0.0.0.0 address=/bespokeweddings.ie/0.0.0.0 address=/bestcarenepal.com/0.0.0.0 address=/betone.co.kr/0.0.0.0 -address=/betycopaints.com/0.0.0.0 address=/beveragesmiami.solucioneslink.com/0.0.0.0 address=/bhavaniengineering.com/0.0.0.0 address=/bigmikesupplies.co.za/0.0.0.0 @@ -183,12 +183,12 @@ address=/canadianwork.cc/0.0.0.0 address=/capitalgroup-kw.com/0.0.0.0 address=/capoeiraventrelivre.com/0.0.0.0 address=/cashyinvestment.org/0.0.0.0 +address=/casiomaneflirt.cf/0.0.0.0 address=/catchpoolshetlands.co.uk/0.0.0.0 address=/cazyacustomfurniture.com/0.0.0.0 address=/cbn.hypervoizd.com/0.0.0.0 address=/ccauthority.net/0.0.0.0 address=/cdaonline.com.ar/0.0.0.0 -address=/cdn-10049480.file.myqcloud.com/0.0.0.0 address=/cec.asso.ac-amiens.fr/0.0.0.0 address=/cellas.sk/0.0.0.0 address=/cendekiabinaaksara.com/0.0.0.0 @@ -202,17 +202,17 @@ address=/chinhdropfile.myvnc.com/0.0.0.0 address=/chinhdropfile80.myvnc.com/0.0.0.0 address=/cible-energy.com/0.0.0.0 address=/cifeer.net/0.0.0.0 +address=/citiconstructioncorp.com/0.0.0.0 address=/citihits.lk/0.0.0.0 address=/citssolutions.co.za/0.0.0.0 -address=/citycapproperty.ru/0.0.0.0 address=/cityglobalgospel.com/0.0.0.0 address=/civi.istmejia.com/0.0.0.0 address=/cleanbydesignllc.com/0.0.0.0 address=/cloud.fc.co.mz/0.0.0.0 address=/cnc.tacobelllover.tk/0.0.0.0 address=/codsambal.com/0.0.0.0 -address=/colinde.pricesne.com/0.0.0.0 address=/colorpak.pl/0.0.0.0 +address=/columbia.aula-web.net/0.0.0.0 address=/community.reimclub.com/0.0.0.0 address=/competancy.indigoconsult.net/0.0.0.0 address=/conceptimagine.ro/0.0.0.0 @@ -222,9 +222,11 @@ address=/constructoralyon.com/0.0.0.0 address=/consulateins.solucioneslink.com/0.0.0.0 address=/contributeindustry.com/0.0.0.0 address=/copelandscapes.com/0.0.0.0 +address=/corwin-tommie06f.ru.com/0.0.0.0 address=/coulsongraphics.com/0.0.0.0 address=/count.mail.163.com.impactmedfoundation.com/0.0.0.0 address=/covid19.cyberschool.or.id/0.0.0.0 +address=/covid19vaccinations.hopto.org/0.0.0.0 address=/cr-sq.com/0.0.0.0 address=/craftech.nxtnet.ga/0.0.0.0 address=/crearechile.cl/0.0.0.0 @@ -287,6 +289,7 @@ address=/dl.1003b.56a.com/0.0.0.0 address=/dl.198424.com/0.0.0.0 address=/dl.installcdn-aws.com/0.0.0.0 address=/dl.packetstormsecurity.net/0.0.0.0 +address=/dl.pandasecur.com/0.0.0.0 address=/dl.rina-roleplay.com/0.0.0.0 address=/dnn.alibuf.com/0.0.0.0 address=/dns.alibuf.com/0.0.0.0 @@ -343,11 +346,11 @@ address=/endurotanzania.co.tz/0.0.0.0 address=/ennovate.elin.co.za/0.0.0.0 address=/equimination.ee/0.0.0.0 address=/erp.nanotechproautocare.com/0.0.0.0 +address=/esaja09.top/0.0.0.0 address=/escola.probommar.org.br/0.0.0.0 address=/eservices.immigration.gov.lk/0.0.0.0 address=/esnconsultants.com/0.0.0.0 address=/essentia.org.br/0.0.0.0 -address=/ethereality.info/0.0.0.0 address=/eubanks7.com/0.0.0.0 address=/europeanzonexxi.com/0.0.0.0 address=/exilum.com/0.0.0.0 @@ -365,7 +368,7 @@ address=/fineartgallerym.com/0.0.0.0 address=/fisconline.bar/0.0.0.0 address=/fisconline.casa/0.0.0.0 address=/fix-america-now.org/0.0.0.0 -address=/fixauto.illumetechnology.com/0.0.0.0 +address=/fkd.derpcity.ru/0.0.0.0 address=/flexypay.dsquaregroup.com/0.0.0.0 address=/flintspin.com/0.0.0.0 address=/flyingbuddhadesign.com/0.0.0.0 @@ -386,7 +389,6 @@ address=/fusionfiresolutions.com/0.0.0.0 address=/futbolpr.com/0.0.0.0 address=/futuregraphics.com.ar/0.0.0.0 address=/g.pinmonkey.xyz/0.0.0.0 -address=/gaditastour.com/0.0.0.0 address=/gametwogame.com/0.0.0.0 address=/garciadogshow.com/0.0.0.0 address=/garenanow.myvnc.com/0.0.0.0 @@ -416,7 +418,6 @@ address=/goldenasiacapital.com/0.0.0.0 address=/goldmen.in/0.0.0.0 address=/gpotecnosystems.com/0.0.0.0 address=/gracejukes.com/0.0.0.0 -address=/greataccesstoserver.com/0.0.0.0 address=/grupoinmare.com/0.0.0.0 address=/gruposelt.000webhostapp.com/0.0.0.0 address=/gs.monerorx.com/0.0.0.0 @@ -447,17 +448,13 @@ address=/hitstation.nl/0.0.0.0 address=/hmpmall.co.kr/0.0.0.0 address=/hoagietesting10.com/0.0.0.0 address=/hoayeuthuong-my.sharepoint.com/0.0.0.0 -address=/holmesservices.mobiledevsite.co/0.0.0.0 address=/homefindersolutions.com/0.0.0.0 address=/hometownchick.com/0.0.0.0 -address=/hongluosi.com/0.0.0.0 address=/hookedupboatclub.com/0.0.0.0 address=/hostingparacolombia.com/0.0.0.0 address=/hostzaa.com/0.0.0.0 -address=/houstonshutters.site/0.0.0.0 address=/hr2019.vrcom7.com/0.0.0.0 address=/hseda.com/0.0.0.0 -address=/hsmwebapp.com/0.0.0.0 address=/htownbars.com/0.0.0.0 address=/hubtech.co.za/0.0.0.0 address=/huellacero.cl/0.0.0.0 @@ -505,6 +502,8 @@ address=/isso.ps/0.0.0.0 address=/it123.ru/0.0.0.0 address=/italiandirezione.casa/0.0.0.0 address=/itc-demo.softgig.co.ke/0.0.0.0 +address=/itsrlytry.000webhostapp.com/0.0.0.0 +address=/jaishomo.info/0.0.0.0 address=/jamiekaylive.com/0.0.0.0 address=/jamshed.pk/0.0.0.0 address=/jansen-heesch.nl/0.0.0.0 @@ -532,11 +531,11 @@ address=/kalogirosfinance.com/0.0.0.0 address=/kaptaanchapal.com/0.0.0.0 address=/karer.by/0.0.0.0 address=/katanvetov.co.il/0.0.0.0 +address=/katelynn9506a.ru.com/0.0.0.0 address=/kensingtondriving.com/0.0.0.0 address=/ketofitnessexpert.com/0.0.0.0 address=/kevinjewelry.com.co/0.0.0.0 address=/keywatch.yourpageserver.com/0.0.0.0 -address=/kihn-delaney30gn.ru.com/0.0.0.0 address=/kingssa.co.za/0.0.0.0 address=/kjcpromo.com/0.0.0.0 address=/kleinendeli.co.za/0.0.0.0 @@ -544,7 +543,6 @@ address=/korrectconceptservices.com/0.0.0.0 address=/krisbadminton.com/0.0.0.0 address=/ktb.sch.id/0.0.0.0 address=/kubatoglubaklava.com.tr/0.0.0.0 -address=/kullumanalitours.com/0.0.0.0 address=/kumaralok.in/0.0.0.0 address=/kwanfromhongkong.com/0.0.0.0 address=/kz.sldov.ru/0.0.0.0 @@ -601,7 +599,6 @@ address=/mail.jeffsono.org/0.0.0.0 address=/maksi.feb.unib.ac.id/0.0.0.0 address=/malaya.tv/0.0.0.0 address=/malwarecoding.github.io/0.0.0.0 -address=/managed.oss-cn-beijing.aliyuncs.com/0.0.0.0 address=/managemysalon.in/0.0.0.0 address=/manantialesdelnorte.uy/0.0.0.0 address=/manhtien.net/0.0.0.0 @@ -644,6 +641,7 @@ address=/michimal2.000webhostapp.com/0.0.0.0 address=/microblading.mirliandias.com.br/0.0.0.0 address=/microcomm-group.com/0.0.0.0 address=/mikhailmotoringschool.com/0.0.0.0 +address=/mills-skyla30ec.com/0.0.0.0 address=/mingguanwms.com/0.0.0.0 address=/minuevavida.org/0.0.0.0 address=/mirror.mypage.sk/0.0.0.0 @@ -660,6 +658,7 @@ address=/monetization.business/0.0.0.0 address=/moninediy.com/0.0.0.0 address=/moreirawag.ac.ug/0.0.0.0 address=/motorcomunicacion.com/0.0.0.0 +address=/moumitas.com/0.0.0.0 address=/msacontabil.com.br/0.0.0.0 address=/mumgee.co.za/0.0.0.0 address=/muzimbiti.xigubo.co.mz/0.0.0.0 @@ -709,6 +708,7 @@ address=/nyasabigbullets.com/0.0.0.0 address=/nyeh2o.com.au/0.0.0.0 address=/obseques-conseils.com/0.0.0.0 address=/oecteam.com/0.0.0.0 +address=/ohe.ie/0.0.0.0 address=/ohsewgorgeous.co.uk/0.0.0.0 address=/oleholeh.memangbeda.website/0.0.0.0 address=/omaia.org/0.0.0.0 @@ -719,7 +719,6 @@ address=/omscoc.pappai.com/0.0.0.0 address=/onedigitalcard.granvizionnecorp.com/0.0.0.0 address=/onedrive.listifyapp.co/0.0.0.0 address=/online.creedglobal.in/0.0.0.0 -address=/open.rawntech.com/0.0.0.0 address=/open.warehousesaas.co.uk/0.0.0.0 address=/opolis.io/0.0.0.0 address=/optimus.com.sg/0.0.0.0 @@ -794,6 +793,7 @@ address=/prox.realunix.cc/0.0.0.0 address=/pujashoppe.in/0.0.0.0 address=/punchdialogues.com/0.0.0.0 address=/punjabdevelopersassociation.com.pk/0.0.0.0 +address=/pvcprinting.co.uk/0.0.0.0 address=/qadir.tickfa.ir/0.0.0.0 address=/qatarglobalconsulting.com/0.0.0.0 address=/qmsled.com/0.0.0.0 @@ -820,16 +820,15 @@ address=/readwrite26.nl/0.0.0.0 address=/readymmade.com/0.0.0.0 address=/recyclethesurplus.com/0.0.0.0 address=/redbats.co.in/0.0.0.0 +address=/redboxmultimedia.com/0.0.0.0 address=/redchillicrackers.com/0.0.0.0 address=/reifenquick.de/0.0.0.0 -address=/relaxindulge.co.nz/0.0.0.0 address=/renehavis.com.ua/0.0.0.0 address=/repatriacioncolombia.com/0.0.0.0 address=/res.uf1.cn/0.0.0.0 address=/reseller.digimitra.in/0.0.0.0 address=/reseller.itechbrasil.com/0.0.0.0 address=/resuco.net/0.0.0.0 -address=/revolet-sa.com/0.0.0.0 address=/rezkabum.ru/0.0.0.0 address=/rhema.com.sg/0.0.0.0 address=/richmondminerals.co.zm/0.0.0.0 @@ -844,6 +843,7 @@ address=/romanianpoints.com/0.0.0.0 address=/ronnietucker.co.uk/0.0.0.0 address=/roomsvc.servegate.kr/0.0.0.0 address=/roshnijewellery.com/0.0.0.0 +address=/rotronics.com.ph/0.0.0.0 address=/rsgym.net/0.0.0.0 address=/rubazar.pro/0.0.0.0 address=/rubycityvietnam.com/0.0.0.0 @@ -872,6 +872,7 @@ address=/scheff.com/0.0.0.0 address=/schoolbustracker.softgig.co.ke/0.0.0.0 address=/sculetus.nl/0.0.0.0 address=/secure-doc-reader.com/0.0.0.0 +address=/secure.activedirect.xyz/0.0.0.0 address=/segalsmetals.elin.co.za/0.0.0.0 address=/sellmyphonela.com/0.0.0.0 address=/selltechtoday.com/0.0.0.0 @@ -881,7 +882,9 @@ address=/serendibsourcing.com/0.0.0.0 address=/sericaasia.com/0.0.0.0 address=/servicemhkd.myvnc.com/0.0.0.0 address=/servicemhkd80.myvnc.com/0.0.0.0 +address=/serviciovirtual.com.ar/0.0.0.0 address=/sexologistpakistan.net/0.0.0.0 +address=/sgb.ac.ke/0.0.0.0 address=/sgessy.com.br/0.0.0.0 address=/shaheentbfoundation.com/0.0.0.0 address=/shahikhana.cstdevs.com/0.0.0.0 @@ -919,7 +922,6 @@ address=/sobariko.com/0.0.0.0 address=/sobethuacademy.com/0.0.0.0 address=/soft.110route.com/0.0.0.0 address=/soft.officelabo.net/0.0.0.0 -address=/sogecoenergy.com/0.0.0.0 address=/sohs.conceptechs.info/0.0.0.0 address=/solar.amazingtribe.lk/0.0.0.0 address=/somcorbera.cat/0.0.0.0 @@ -933,7 +935,6 @@ address=/spent.com.pl/0.0.0.0 address=/spetsesyachtcharter.gr/0.0.0.0 address=/spititourism.com/0.0.0.0 address=/spittinfire.com/0.0.0.0 -address=/springbedspetroleum.com/0.0.0.0 address=/src1.minibai.com/0.0.0.0 address=/sreenivasapaintingworks.com/0.0.0.0 address=/sriglobalit.com/0.0.0.0 @@ -944,16 +945,23 @@ address=/st.devcodin.com/0.0.0.0 address=/staging.apparelpunch.com/0.0.0.0 address=/starcountry.net/0.0.0.0 address=/static.3001.net/0.0.0.0 +address=/stdynbnbnewagedevixz.dns.army/0.0.0.0 +address=/stdynmxwllminoragest.dns.army/0.0.0.0 +address=/stdyunitedkesokokgst.dns.army/0.0.0.0 +address=/stdyworkfinetraingst.dns.army/0.0.0.0 +address=/stdyzgchgcloudgostxs.dns.army/0.0.0.0 address=/stiau.iuc.ac/0.0.0.0 address=/sticker.jewsjuice.com/0.0.0.0 address=/stiepancasetia.ac.id/0.0.0.0 address=/stlukesohag.com/0.0.0.0 address=/store.ericalgarin.com/0.0.0.0 address=/stott-thompson.co.uk/0.0.0.0 +address=/stratexec.co.za/0.0.0.0 address=/streetdemo.yourpageserver.com/0.0.0.0 address=/suboldesign.com/0.0.0.0 address=/sumerians.org/0.0.0.0 address=/sunaryem.com.tr/0.0.0.0 +address=/sunbrero.com.au/0.0.0.0 address=/sunmarkholidays.com/0.0.0.0 address=/support-4-free.com/0.0.0.0 address=/support.clz.kr/0.0.0.0 @@ -1032,7 +1040,6 @@ address=/topcell9.com/0.0.0.0 address=/toplevel.com.br/0.0.0.0 address=/topmask.co.za/0.0.0.0 address=/torresquinterocorp.com/0.0.0.0 -address=/towme.services/0.0.0.0 address=/toyotacollege.ac.th/0.0.0.0 address=/tpke.hu/0.0.0.0 address=/translaterjemah.com/0.0.0.0 @@ -1059,7 +1066,6 @@ address=/union.jctrip.cn/0.0.0.0 address=/unyazitelecom.com/0.0.0.0 address=/up.llw0.com/0.0.0.0 address=/upcbpta.com/0.0.0.0 -address=/used-jeans.fr/0.0.0.0 address=/useformoney.000webhostapp.com/0.0.0.0 address=/uss.ac.th/0.0.0.0 address=/uzzepay.com.br/0.0.0.0 @@ -1068,7 +1074,6 @@ address=/vbcargo.hu/0.0.0.0 address=/vcah.co.uk/0.0.0.0 address=/vectarts.com/0.0.0.0 address=/vegadelcasero.cl/0.0.0.0 -address=/velma-harber30ku.com/0.0.0.0 address=/vendas.lidiacarmeli.com.br/0.0.0.0 address=/veterinariadrpopui.com/0.0.0.0 address=/vfocus.net/0.0.0.0 @@ -1084,7 +1089,6 @@ address=/vivationdesign.com/0.0.0.0 address=/viveirodoiscorregos.com.br/0.0.0.0 address=/vksales.com/0.0.0.0 address=/vocalterra.com/0.0.0.0 -address=/vokasi.ub.ac.id/0.0.0.0 address=/vologroup.com.br/0.0.0.0 address=/voteyouramerica.dekitout.com/0.0.0.0 address=/vpts.co.za/0.0.0.0 @@ -1105,6 +1109,7 @@ address=/webpresario.com/0.0.0.0 address=/weinsteincounseling.com/0.0.0.0 address=/wfinance.com.br/0.0.0.0 address=/whcms.yourpageserver.com/0.0.0.0 +address=/whiteglovetailgate.com/0.0.0.0 address=/whiteresponse.com/0.0.0.0 address=/wi522012.ferozo.com/0.0.0.0 address=/wikalen.co.za/0.0.0.0 @@ -1134,6 +1139,7 @@ address=/yeichner.com/0.0.0.0 address=/yeq.i.u.j.ia.n.3@zytrox.tk/0.0.0.0 address=/ylfpremium.com/0.0.0.0 address=/yoast.yourpageserver.com/0.0.0.0 +address=/yp.hnggzyjy.cn/0.0.0.0 address=/yummyyogaudaipur.com/0.0.0.0 address=/yzkzixun.com/0.0.0.0 address=/ziyker4gaming@zytrox.tk/0.0.0.0 diff --git a/urlhaus-filter-dnsmasq.conf b/urlhaus-filter-dnsmasq.conf index 560f6a51..356288be 100644 --- a/urlhaus-filter-dnsmasq.conf +++ b/urlhaus-filter-dnsmasq.conf @@ -1,5 +1,5 @@ # Title: Malicious Domains dnsmasq Blocklist -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -1438,7 +1438,6 @@ address=/6481254.ru/0.0.0.0 address=/649924.nchsoftwarecom.com/0.0.0.0 address=/64x9bg.ch.files.1drv.com/0.0.0.0 address=/650x.com/0.0.0.0 -address=/654tyfcdr4654fytfy.top/0.0.0.0 address=/65k2.com/0.0.0.0 address=/66-gifts.com/0.0.0.0 address=/662ekeep6.com/0.0.0.0 @@ -1476,7 +1475,6 @@ address=/6gsdlmpym.com/0.0.0.0 address=/6gue98ddw4220152.freebackup.site/0.0.0.0 address=/6hffgq.dm.files.1drv.com/0.0.0.0 address=/6hu.xyz/0.0.0.0 -address=/6ip.us/0.0.0.0 address=/6iptv.com/0.0.0.0 address=/6itokam.com/0.0.0.0 address=/6kd743o1w.com/0.0.0.0 @@ -1869,7 +1867,6 @@ address=/a.deadnig.ga/0.0.0.0 address=/a.doko.moe/0.0.0.0 address=/a.gg.fm/0.0.0.0 address=/a.heritageandterre.com/0.0.0.0 -address=/a.pomf.cat/0.0.0.0 address=/a.pomf.se/0.0.0.0 address=/a.pomf.space/0.0.0.0 address=/a.pomf.su/0.0.0.0 @@ -6583,7 +6580,6 @@ address=/anmingsi.com/0.0.0.0 address=/anmocnhien.vn/0.0.0.0 address=/anmolanwar.com/0.0.0.0 address=/ann141.net/0.0.0.0 -address=/anna.websaiting.ru/0.0.0.0 address=/annaaluminium.annagroup.net/0.0.0.0 address=/annabelle-hamande.be/0.0.0.0 address=/annabphotography.co.uk/0.0.0.0 @@ -7098,6 +7094,7 @@ address=/app.bigplan-alex.com/0.0.0.0 address=/app.boxrcdn.com/0.0.0.0 address=/app.bridgeimpex.org/0.0.0.0 address=/app.calag.at/0.0.0.0 +address=/app.casetabs.com/0.0.0.0 address=/app.catholicchurch.co.in/0.0.0.0 address=/app.choiphui.com/0.0.0.0 address=/app.cloudindustry.net/0.0.0.0 @@ -9004,6 +9001,7 @@ address=/atpcsm.be/0.0.0.0 address=/atphitech.com/0.0.0.0 address=/atpn.ir/0.0.0.0 address=/atprofessional.org/0.0.0.0 +address=/atpscan.global.hornetsecurity.com/0.0.0.0 address=/atr.it/0.0.0.0 address=/atradex.com/0.0.0.0 address=/atragon.co.uk/0.0.0.0 @@ -9764,6 +9762,8 @@ address=/awswx.xyz/0.0.0.0 address=/awsxb.xyz/0.0.0.0 address=/awsyscloud.com/0.0.0.0 address=/awtinfostore.co.business/0.0.0.0 +address=/awumad01.top/0.0.0.0 +address=/awuqze02.top/0.0.0.0 address=/ax-yogado.com/0.0.0.0 address=/axalize.vn/0.0.0.0 address=/axalta.grupojenrab.mx/0.0.0.0 @@ -11161,6 +11161,7 @@ address=/bbfjjf8.com/0.0.0.0 address=/bbfr.cba.pl/0.0.0.0 address=/bbgiardinodoriente.it/0.0.0.0 address=/bbgk.de/0.0.0.0 +address=/bbgroup.com.vn/0.0.0.0 address=/bbh-design.de/0.0.0.0 address=/bbhdata.com/0.0.0.0 address=/bbhs.org.ng/0.0.0.0 @@ -11600,7 +11601,6 @@ address=/bekurov.org/0.0.0.0 address=/bel-med-tour.ru/0.0.0.0 address=/belabargelro.com/0.0.0.0 address=/belair.btwstudio.ch/0.0.0.0 -address=/belairinternet.com/0.0.0.0 address=/belamater.com.br/0.0.0.0 address=/belangel.by/0.0.0.0 address=/belanja-berkah.xyz/0.0.0.0 @@ -11719,7 +11719,6 @@ address=/belyi.ug/0.0.0.0 address=/belz-development.de/0.0.0.0 address=/belznerdesign.de/0.0.0.0 address=/bem.fkep.unpad.ac.id/0.0.0.0 -address=/bem.hukum.ub.ac.id/0.0.0.0 address=/bem.unimal.ac.id/0.0.0.0 address=/bemagazine.club/0.0.0.0 address=/bemakeup.ru/0.0.0.0 @@ -12492,6 +12491,7 @@ address=/bieres.lavachenoiresud.com/0.0.0.0 address=/bierne-les-villages.fr/0.0.0.0 address=/biese.eu/0.0.0.0 address=/bietthubien.org/0.0.0.0 +address=/bietthudep902.com/0.0.0.0 address=/bietthulambach.com/0.0.0.0 address=/bietthulienkegamuda.net/0.0.0.0 address=/bietthumau.com/0.0.0.0 @@ -16387,7 +16387,6 @@ address=/callonenergy.com/0.0.0.0 address=/callpetercatering.com/0.0.0.0 address=/callrealtyaz.com/0.0.0.0 address=/callshaal.com/0.0.0.0 -address=/callsmaster.com/0.0.0.0 address=/calltoprimus.ru/0.0.0.0 address=/callumstokes.com/0.0.0.0 address=/calm-tech.africa/0.0.0.0 @@ -17647,7 +17646,6 @@ address=/cdncomfortgroup.website/0.0.0.0 address=/cdndownloadlp.club/0.0.0.0 address=/cdnmultimedia.com/0.0.0.0 address=/cdnpic.mgyun.com/0.0.0.0 -address=/cdnrep.reimageplus.com/0.0.0.0 address=/cdnxh.net/0.0.0.0 address=/cdoconsult.com.br/0.0.0.0 address=/cdolechon.com/0.0.0.0 @@ -18439,7 +18437,6 @@ address=/cheekie2.neagoeandrei.com/0.0.0.0 address=/cheematransxpressinc.com/0.0.0.0 address=/cheerchile.cl/0.0.0.0 address=/cheerfulgiversneverlack.com/0.0.0.0 -address=/cheerfullydo.com/0.0.0.0 address=/cheesecakery.com.br/0.0.0.0 address=/cheetahridge.mediadevstaging.com/0.0.0.0 address=/chef-solutions.dreamscape.co.in/0.0.0.0 @@ -19370,6 +19367,7 @@ address=/clarrywillow.top/0.0.0.0 address=/clarte-thailand.com/0.0.0.0 address=/clashofclansgems.nl/0.0.0.0 address=/clasificados.diaadianews.com/0.0.0.0 +address=/clasificadosmaule.com/0.0.0.0 address=/class.britishonline.co/0.0.0.0 address=/class.snph.ir/0.0.0.0 address=/classbrain.net/0.0.0.0 @@ -19667,6 +19665,7 @@ address=/clntnjkstdycloudstcy.dns.army/0.0.0.0 address=/cloakingtds.xyz/0.0.0.0 address=/clock.noixun.com/0.0.0.0 address=/clodflarechk.com/0.0.0.0 +address=/clodura.ai/0.0.0.0 address=/clone.affordable.cm/0.0.0.0 address=/clone.system-standex.dk/0.0.0.0 address=/cloned.in/0.0.0.0 @@ -19852,7 +19851,6 @@ address=/cmeaststar.de/0.0.0.0 address=/cmecobrancas.com/0.0.0.0 address=/cmelik.com/0.0.0.0 address=/cmessagers.com/0.0.0.0 -address=/cmg.asia/0.0.0.0 address=/cmg.ma/0.0.0.0 address=/cmgroup.com.ua/0.0.0.0 address=/cmhighschool.edu.bd/0.0.0.0 @@ -22391,7 +22389,6 @@ address=/cuacuonsieure.com/0.0.0.0 address=/cuadros.pe/0.0.0.0 address=/cuahangphongthuy.net/0.0.0.0 address=/cuahangstore.com/0.0.0.0 -address=/cuahangvattu.com/0.0.0.0 address=/cualtis.com/0.0.0.0 address=/cuanhomxingfanhapkhau.com/0.0.0.0 address=/cuasotinhoc.net/0.0.0.0 @@ -22820,6 +22817,7 @@ address=/d.powerofwish.com/0.0.0.0 address=/d.qiluwl.com/0.0.0.0 address=/d.teamworx.ph/0.0.0.0 address=/d.techmartbd.com/0.0.0.0 +address=/d.top4top.io/0.0.0.0 address=/d.top4top.net/0.0.0.0 address=/d.ttr3p.com/0.0.0.0 address=/d04.data39.helldata.com/0.0.0.0 @@ -24801,6 +24799,7 @@ address=/deportetotal.mx/0.0.0.0 address=/deposayim.ml/0.0.0.0 address=/depositoclara.com.br/0.0.0.0 address=/depot7.com/0.0.0.0 +address=/depozituldegeneratoare.ro/0.0.0.0 address=/depraetere.net/0.0.0.0 address=/deprealty.ru/0.0.0.0 address=/depressionted.com/0.0.0.0 @@ -26527,7 +26526,6 @@ address=/dl-45538429.onedrives-en-live.com/0.0.0.0 address=/dl-675423.store-downloads.com/0.0.0.0 address=/dl-80076342.md-downloads.com/0.0.0.0 address=/dl-97674424.md-downloads.com/0.0.0.0 -address=/dl-gameplayer.dmm.com/0.0.0.0 address=/dl-link.link/0.0.0.0 address=/dl-link.live/0.0.0.0 address=/dl-link.network/0.0.0.0 @@ -26550,9 +26548,9 @@ address=/dl.ikiki.cn/0.0.0.0 address=/dl.imht.ir/0.0.0.0 address=/dl.installcdn-aws.com/0.0.0.0 address=/dl.mqego.com/0.0.0.0 -address=/dl.mydown.com/0.0.0.0 address=/dl.ossdown.fun/0.0.0.0 address=/dl.packetstormsecurity.net/0.0.0.0 +address=/dl.pandasecur.com/0.0.0.0 address=/dl.popupgrade.com/0.0.0.0 address=/dl.repairlabshost.com/0.0.0.0 address=/dl.rina-roleplay.com/0.0.0.0 @@ -26729,6 +26727,9 @@ address=/dobrojutrodjevojke.com/0.0.0.0 address=/dobroviz.com.ua/0.0.0.0 address=/dobrovorot.su/0.0.0.0 address=/dobsoncentral.com/0.0.0.0 +address=/doc-0s-7c-docs.googleusercontent.com/0.0.0.0 +address=/doc-10-0c-docs.googleusercontent.com/0.0.0.0 +address=/doc-10-8s-docs.googleusercontent.com/0.0.0.0 address=/doc-hub.healthycheapfast.com/0.0.0.0 address=/doc-japan.com/0.0.0.0 address=/doc.albaspizzaastoria.com/0.0.0.0 @@ -29003,6 +29004,7 @@ address=/ec2-52-56-233-157.eu-west-2.compute.amazonaws.com/0.0.0.0 address=/ec2-54-207-92-161.sa-east-1.compute.amazonaws.com/0.0.0.0 address=/ec2-54-212-231-68.us-west-2.compute.amazonaws.com/0.0.0.0 address=/ec2-54-94-215-87.sa-east-1.compute.amazonaws.com/0.0.0.0 +address=/ec2euc1.boxcloud.com/0.0.0.0 address=/ec2test.ga/0.0.0.0 address=/ec3-design.com/0.0.0.0 address=/ecadigital.com/0.0.0.0 @@ -31303,6 +31305,7 @@ address=/es.thevoucherstop.com/0.0.0.0 address=/esaarc.com/0.0.0.0 address=/esacbd.com/0.0.0.0 address=/esagarautomobiles.com/0.0.0.0 +address=/esaja09.top/0.0.0.0 address=/esanjobs.org/0.0.0.0 address=/esar.weenets.com/0.0.0.0 address=/esascom.com/0.0.0.0 @@ -37097,7 +37100,6 @@ address=/genregis.com/0.0.0.0 address=/genrjw.dm.files.1drv.com/0.0.0.0 address=/genstaff.gov.kg/0.0.0.0 address=/gentcreativa.com/0.0.0.0 -address=/gentecoyol.com/0.0.0.0 address=/gentesanluis.com/0.0.0.0 address=/gentiane-salers.com/0.0.0.0 address=/gentlechirocenter.com/0.0.0.0 @@ -39846,6 +39848,7 @@ address=/gvou7g.by.files.1drv.com/0.0.0.0 address=/gvpcdpgc.edu.in/0.0.0.0 address=/gvpmacademy.co.za/0.0.0.0 address=/gvsme.com/0.0.0.0 +address=/gw.daelimcloud.com/0.0.0.0 address=/gw.hitlin.com/0.0.0.0 address=/gwangjuhotels.kr/0.0.0.0 address=/gwavellc.com/0.0.0.0 @@ -42657,7 +42660,6 @@ address=/hotelvip-bron.ru/0.0.0.0 address=/hotelwaldblick.com/0.0.0.0 address=/hotexpress.co/0.0.0.0 address=/hotfacts.org/0.0.0.0 -address=/hotgifts.online/0.0.0.0 address=/hotilife.com/0.0.0.0 address=/hotissue.xyz/0.0.0.0 address=/hotkine.com/0.0.0.0 @@ -43035,7 +43037,6 @@ address=/hukouec-ltd.com/0.0.0.0 address=/hukuen-motokare.xyz/0.0.0.0 address=/hukuki.site/0.0.0.0 address=/hukukportal.com/0.0.0.0 -address=/hukum.ub.ac.id/0.0.0.0 address=/hukum.unwiku.ac.id/0.0.0.0 address=/hulianwang114.com/0.0.0.0 address=/huliot.in/0.0.0.0 @@ -43357,6 +43358,7 @@ address=/i-sharecloud.com/0.0.0.0 address=/i-supportcharity.com/0.0.0.0 address=/i-vnsweyu.pl/0.0.0.0 address=/i-voda.com/0.0.0.0 +address=/i.fiery.me/0.0.0.0 address=/i.fluffy.cc/0.0.0.0 address=/i.funtourspt.eu/0.0.0.0 address=/i.n.t.e.rloca.l.qs.j.y@jfas.top/0.0.0.0 @@ -46637,6 +46639,7 @@ address=/itspread.com/0.0.0.0 address=/itspsc.com.ua/0.0.0.0 address=/itspueh.nl/0.0.0.0 address=/itsquare.yrcreations.com/0.0.0.0 +address=/itsrlytry.000webhostapp.com/0.0.0.0 address=/itssprout.com/0.0.0.0 address=/itstelecom.com.br/0.0.0.0 address=/itsweezle.com/0.0.0.0 @@ -46836,6 +46839,7 @@ address=/j-skill.ru/0.0.0.0 address=/j-stage.jp/0.0.0.0 address=/j-toputvoutfitters.com/0.0.0.0 address=/j.kyryl.ru/0.0.0.0 +address=/j.top4top.io/0.0.0.0 address=/j11g9xecuxe43xu.xyz/0.0.0.0 address=/j12z7407gwtzk.xyz/0.0.0.0 address=/j13.biz/0.0.0.0 @@ -46968,6 +46972,7 @@ address=/jaipurjungle.co.in/0.0.0.0 address=/jaipurweddingphotography.com/0.0.0.0 address=/jairathsnatural.ca/0.0.0.0 address=/jairozapata.000webhostapp.com/0.0.0.0 +address=/jaishomo.info/0.0.0.0 address=/jaishritours.com/0.0.0.0 address=/jaiswalsupplement.com/0.0.0.0 address=/jajadomains.com/0.0.0.0 @@ -50996,7 +51001,6 @@ address=/kodiakpro.ca/0.0.0.0 address=/kodim0112sabang.com/0.0.0.0 address=/kodingeko.com/0.0.0.0 address=/kodip.nfile.net/0.0.0.0 -address=/kodjdsjsdjf.tk/0.0.0.0 address=/kodlacan.site/0.0.0.0 address=/kodmuje.com/0.0.0.0 address=/kodolios.000webhostapp.com/0.0.0.0 @@ -53636,6 +53640,7 @@ address=/library.arihantmbainstitute.ac.in/0.0.0.0 address=/library.cifor.org/0.0.0.0 address=/library.dhl-xom.com/0.0.0.0 address=/library.iainbengkulu.ac.id/0.0.0.0 +address=/library.mju.ac.th/0.0.0.0 address=/library.phibi.my.id/0.0.0.0 address=/library.piet.co.in/0.0.0.0 address=/library.strophicmusic.com/0.0.0.0 @@ -54322,7 +54327,6 @@ address=/livechallenge.fr/0.0.0.0 address=/livecigarevent.com/0.0.0.0 address=/livecricketscorecard.info/0.0.0.0 address=/livedaynews.com/0.0.0.0 -address=/livedemo00.template-help.com/0.0.0.0 address=/livedownload.in/0.0.0.0 address=/livedrumtracks.com/0.0.0.0 address=/livefarma.com/0.0.0.0 @@ -54355,7 +54359,6 @@ address=/livesouvenir.com/0.0.0.0 address=/livestreams.vn/0.0.0.0 address=/livesuitesapartdaire.com/0.0.0.0 address=/livesurgerycourse.ir/0.0.0.0 -address=/liveswinburneeduau-my.sharepoint.com/0.0.0.0 address=/liveswindow.casa/0.0.0.0 address=/liveswindow.cyou/0.0.0.0 address=/liveswindows.bar/0.0.0.0 @@ -55530,7 +55533,6 @@ address=/luzbarbosa.com.br/0.0.0.0 address=/luzconsulting.com.br/0.0.0.0 address=/luzevida.com.br/0.0.0.0 address=/luzfloral.com/0.0.0.0 -address=/luzy.vn/0.0.0.0 address=/luzzeri.com/0.0.0.0 address=/lvajnczdy.cf/0.0.0.0 address=/lvcfund.org.vn/0.0.0.0 @@ -58568,7 +58570,6 @@ address=/mecflui.com.br/0.0.0.0 address=/mecgwl.ac.in/0.0.0.0 address=/mechanicaltools.club/0.0.0.0 address=/mechanicsthatcometoyou.com/0.0.0.0 -address=/mecharnise.ir/0.0.0.0 address=/mechathrones.com/0.0.0.0 address=/mechauto.co.za/0.0.0.0 address=/mechdesign.com/0.0.0.0 @@ -59154,7 +59155,6 @@ address=/menxhiqi.com/0.0.0.0 address=/menziesadvisory-my.sharepoint.com/0.0.0.0 address=/menzway.com/0.0.0.0 address=/meogiambeo.com/0.0.0.0 -address=/meohaybotui.com/0.0.0.0 address=/meolamdephay.com/0.0.0.0 address=/mepsgen.com/0.0.0.0 address=/mera.ddns.net/0.0.0.0 @@ -59472,6 +59472,7 @@ address=/mfmr.gov.sl/0.0.0.0 address=/mfomjr.com/0.0.0.0 address=/mfotovideo.ro/0.0.0.0 address=/mfpburundi.bi/0.0.0.0 +address=/mfpc.org.my/0.0.0.0 address=/mfppanel.xyz/0.0.0.0 address=/mfpvision.com/0.0.0.0 address=/mfronza.com.br/0.0.0.0 @@ -64504,7 +64505,6 @@ address=/nhadatphonglinh.com/0.0.0.0 address=/nhadatquan2.xyz/0.0.0.0 address=/nhadatthienthoi.com/0.0.0.0 address=/nhadephungyen.com/0.0.0.0 -address=/nhadepkientruc.net/0.0.0.0 address=/nhahangdaihung.com/0.0.0.0 address=/nhahanghaivuong.vn/0.0.0.0 address=/nhahanglegiang.vn/0.0.0.0 @@ -64718,7 +64718,6 @@ address=/nikanbearing.com/0.0.0.0 address=/nikanpolimer.ir/0.0.0.0 address=/nikastroi.ru/0.0.0.0 address=/nikavkuchyni.sk/0.0.0.0 -address=/nikayu.com/0.0.0.0 address=/nikbox.ru/0.0.0.0 address=/nikeshyadav.com/0.0.0.0 address=/nikhil.webscript.co.in/0.0.0.0 @@ -67234,7 +67233,6 @@ address=/optimusforce.nl/0.0.0.0 address=/option47.us/0.0.0.0 address=/optioncapitalgroup.ru/0.0.0.0 address=/optionrp.com/0.0.0.0 -address=/optionscity.com/0.0.0.0 address=/optisaving.com/0.0.0.0 address=/optitechsa.co.za/0.0.0.0 address=/optocen.ru/0.0.0.0 @@ -67529,7 +67527,6 @@ address=/osethmaayurveda.com/0.0.0.0 address=/osezrayonner.ma/0.0.0.0 address=/osgbforum.com/0.0.0.0 address=/oshattorney.com/0.0.0.0 -address=/oshi.at/0.0.0.0 address=/oshodrycleaning.com/0.0.0.0 address=/oshonafitness.com/0.0.0.0 address=/oshop.es/0.0.0.0 @@ -71229,7 +71226,6 @@ address=/posmaster.co.kr/0.0.0.0 address=/posmicrosystems.com/0.0.0.0 address=/posnxqmp.ru/0.0.0.0 address=/pospeeps.com/0.0.0.0 -address=/posqit.net/0.0.0.0 address=/possessionnow.com/0.0.0.0 address=/possible.re/0.0.0.0 address=/possopagar.com.br/0.0.0.0 @@ -71865,7 +71861,6 @@ address=/prishaartcreations.com/0.0.0.0 address=/prisidmart.com/0.0.0.0 address=/priskat.net/0.0.0.0 address=/prism-photo.com/0.0.0.0 -address=/prisma.fp.ub.ac.id/0.0.0.0 address=/prismaxis.com/0.0.0.0 address=/prismfox.com/0.0.0.0 address=/prismware.ml/0.0.0.0 @@ -72457,6 +72452,7 @@ address=/protech.binarybizz.com/0.0.0.0 address=/protech.mn/0.0.0.0 address=/protechcarpetcare.com/0.0.0.0 address=/protechgroup1.com/0.0.0.0 +address=/protect.mimecast-offshore.com/0.0.0.0 address=/protectiadatelor.biz/0.0.0.0 address=/protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org/0.0.0.0 address=/protection.pecol.eu/0.0.0.0 @@ -72538,6 +72534,7 @@ address=/proxima-solution.com/0.0.0.0 address=/proxy-ipv4.com/0.0.0.0 address=/proxy.2u0apcm6ylhdy7s.com/0.0.0.0 address=/proxy.hueaudio.com/0.0.0.0 +address=/proxy.qualtrics.com/0.0.0.0 address=/proxygrnd.xyz/0.0.0.0 address=/proxyholding.com/0.0.0.0 address=/proxyresume.com/0.0.0.0 @@ -75051,6 +75048,7 @@ address=/redlk.com/0.0.0.0 address=/redlogisticsmaroc.com/0.0.0.0 address=/redloop.io/0.0.0.0 address=/redlotusevents.com/0.0.0.0 +address=/redm1az1.000webhostapp.com/0.0.0.0 address=/redmag.by/0.0.0.0 address=/redmarcial.ossmarcial.com/0.0.0.0 address=/redmediasigns.com/0.0.0.0 @@ -76222,6 +76220,7 @@ address=/rkbicycle.com/0.0.0.0 address=/rkcable.co.in/0.0.0.0 address=/rkfplumbing.co.uk/0.0.0.0 address=/rkinstitute.org/0.0.0.0 +address=/rkkrstdygorgiousejbg.dns.army/0.0.0.0 address=/rkkrstdygorgiousejds.dns.army/0.0.0.0 address=/rkkrstdygorgiousejtw.dns.army/0.0.0.0 address=/rklkpgcollege.com/0.0.0.0 @@ -76778,6 +76777,7 @@ address=/rotiyes.co.id/0.0.0.0 address=/rotoblast.org/0.0.0.0 address=/rotor.olsztyn.pl/0.0.0.0 address=/rotoscoop.com/0.0.0.0 +address=/rotronics.com.ph/0.0.0.0 address=/rott-mtr.de/0.0.0.0 address=/rotterdammeetings.nl/0.0.0.0 address=/rotulosalarcon.com/0.0.0.0 @@ -77191,7 +77191,6 @@ address=/runmagazine.es/0.0.0.0 address=/runmureed.com/0.0.0.0 address=/runmyweb.com/0.0.0.0 address=/runnected.kaiman.fr/0.0.0.0 -address=/runnerbd.com/0.0.0.0 address=/runnerschool.com/0.0.0.0 address=/running-bike.com/0.0.0.0 address=/runningcrewteam.com/0.0.0.0 @@ -78713,6 +78712,7 @@ address=/savemodificationgloballyfromthepinaltypo.duckdns.org/0.0.0.0 address=/savemyfile.3utilities.com/0.0.0.0 address=/savemyseatnow.com/0.0.0.0 address=/saveraahealthcare.com/0.0.0.0 +address=/saveserpnow.com/0.0.0.0 address=/saveserpresults.com/0.0.0.0 address=/savestudio.com/0.0.0.0 address=/savetax.idfcmf.com/0.0.0.0 @@ -79390,6 +79390,7 @@ address=/secure-net.tech/0.0.0.0 address=/secure-risk.namaskara.me/0.0.0.0 address=/secure-snupa.com/0.0.0.0 address=/secure.accounts.resourses.com/0.0.0.0 +address=/secure.activedirect.xyz/0.0.0.0 address=/secure.anchorssb.co/0.0.0.0 address=/secure.app-amazon.com.recovery-account.amazon.com.alphatravelmongolia.com/0.0.0.0 address=/secure.bodybuilderabs.net/0.0.0.0 @@ -80067,7 +80068,6 @@ address=/service.atlink.ir/0.0.0.0 address=/service.dawat.fr/0.0.0.0 address=/service.drnjithendran.com/0.0.0.0 address=/service.eftformotherissues.com/0.0.0.0 -address=/service.ezsoftwareupdater.com/0.0.0.0 address=/service.heritageimagingcenter.com/0.0.0.0 address=/service.hybridhomesteam.com/0.0.0.0 address=/service.idealfurnitureoutlet.com/0.0.0.0 @@ -80572,6 +80572,7 @@ address=/shareallfilesthroughsecureexchangesystem.duckdns.org/0.0.0.0 address=/sharebook.tk/0.0.0.0 address=/sharechautari.com/0.0.0.0 address=/shared-cnd.com/0.0.0.0 +address=/shared.outlook.inky.com/0.0.0.0 address=/shareddocuments.ml/0.0.0.0 address=/shareddynamics.com/0.0.0.0 address=/sharedeconomy.eu/0.0.0.0 @@ -84935,9 +84936,11 @@ address=/stdymjventsluzcafoik.dns.army/0.0.0.0 address=/stdymjventsluzcafsrp.dns.army/0.0.0.0 address=/stdymorcmmylntwincdq.dns.army/0.0.0.0 address=/stdymorcmmylntwinstr.dns.army/0.0.0.0 +address=/stdynbnbnewagedevixz.dns.army/0.0.0.0 address=/stdynbnbnewagedevsmn.dns.army/0.0.0.0 address=/stdynbnbnewagedevxaz.dns.army/0.0.0.0 address=/stdyneverwalkachinese2loneinlifekstgqm.ydns.eu/0.0.0.0 +address=/stdynmxwllminoragest.dns.army/0.0.0.0 address=/stdyperezluzcafeyzst.dns.navy/0.0.0.0 address=/stdypmrimelimtwstogy.dns.army/0.0.0.0 address=/stdypycsslwinnerscot.dns.army/0.0.0.0 @@ -84968,6 +84971,7 @@ address=/stdytoprehtwoyertwfd.dns.army/0.0.0.0 address=/stdytopreoneenversrw.dns.army/0.0.0.0 address=/stdytopreoneenvervaj.dns.army/0.0.0.0 address=/stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu/0.0.0.0 +address=/stdyunitedkesokokgst.dns.army/0.0.0.0 address=/stdyunitedkesokostdr.dns.army/0.0.0.0 address=/stdyunitedkesokostri.dns.navy/0.0.0.0 address=/stdyunitedkesokostxc.dns.army/0.0.0.0 @@ -84977,7 +84981,9 @@ address=/stdyworkfineanotherrainbowlomoyentstbmd.duckdns.org/0.0.0.0 address=/stdyworkfineanotherrainbowlomoyentwkgls.duckdns.org/0.0.0.0 address=/stdyworkfinesanotherrainbowlomoyentstfcp.ydns.eu/0.0.0.0 address=/stdyworkfinesanotherrainbowlomoyentstgot.ydns.eu/0.0.0.0 +address=/stdyworkfinetraingst.dns.army/0.0.0.0 address=/stdyzgchgcloudgostgt.dns.army/0.0.0.0 +address=/stdyzgchgcloudgostxs.dns.army/0.0.0.0 address=/steadyrestmanufacturers.com/0.0.0.0 address=/steak.wpress.dk/0.0.0.0 address=/steakhouse.com.ua/0.0.0.0 @@ -85537,6 +85543,7 @@ address=/strend.net/0.0.0.0 address=/strengthandvigour.com/0.0.0.0 address=/strengthrer.com/0.0.0.0 address=/strenover.ga/0.0.0.0 +address=/stressing.pw/0.0.0.0 address=/stressnada.com/0.0.0.0 address=/stretchpilates.fit/0.0.0.0 address=/strewn.org/0.0.0.0 @@ -86228,6 +86235,7 @@ address=/supercrystal.am/0.0.0.0 address=/supercutscissors.com/0.0.0.0 address=/superdad.id/0.0.0.0 address=/superdigitalguy.xyz/0.0.0.0 +address=/superdomain1709.info/0.0.0.0 address=/superdot.rs/0.0.0.0 address=/superecruiters.com/0.0.0.0 address=/superfacil.center/0.0.0.0 @@ -86331,7 +86339,6 @@ address=/support.m2mservices.com/0.0.0.0 address=/support.mdsol.com/0.0.0.0 address=/support.nordenrecycling.com/0.0.0.0 address=/support.nuvemit.com/0.0.0.0 -address=/support.pubg.com/0.0.0.0 address=/support.redbook.aero/0.0.0.0 address=/support.revolus.xyz/0.0.0.0 address=/support.servu.co.uk/0.0.0.0 @@ -86676,7 +86683,6 @@ address=/swiat-ksiegowosci.pl/0.0.0.0 address=/swicoservers.co.uk/0.0.0.0 address=/swieradowbiega.pl/0.0.0.0 address=/swifck.xmr.ac/0.0.0.0 -address=/swift-cloud.com/0.0.0.0 address=/swiftbusinesspay.com/0.0.0.0 address=/swiftee.co.uk/0.0.0.0 address=/swiftender.com/0.0.0.0 @@ -87521,7 +87527,6 @@ address=/tarexfinal.trade/0.0.0.0 address=/targas.de/0.0.0.0 address=/targat-china.com/0.0.0.0 address=/target-events.com/0.0.0.0 -address=/target-support.online/0.0.0.0 address=/target2cloud.com/0.0.0.0 address=/targetbizbd.com/0.0.0.0 address=/targetcm.net/0.0.0.0 @@ -89102,7 +89107,6 @@ address=/thacci.com.br/0.0.0.0 address=/thachastew.com/0.0.0.0 address=/thachvietstone.com/0.0.0.0 address=/thadathilfarmresort.com/0.0.0.0 -address=/thaddeusarmstrong.com/0.0.0.0 address=/thadinnoo.co/0.0.0.0 address=/thagreymatter.com/0.0.0.0 address=/thai-chana.asia/0.0.0.0 @@ -90824,7 +90828,6 @@ address=/tlcc.com.gt/0.0.0.0 address=/tlcid.org/0.0.0.0 address=/tlckids-or.ga/0.0.0.0 address=/tlcmoto.com/0.0.0.0 -address=/tldrbox.top/0.0.0.0 address=/tldrnet.top/0.0.0.0 address=/tlextreme.com/0.0.0.0 address=/tlfthelifefactory.com.au/0.0.0.0 @@ -92421,6 +92424,7 @@ address=/ts-deals.me/0.0.0.0 address=/ts.7rb.xyz/0.0.0.0 address=/ts0ev73.com/0.0.0.0 address=/tsal.com/0.0.0.0 +address=/tsapparel.com.my/0.0.0.0 address=/tsareva-garden.ru/0.0.0.0 address=/tsatsi.co.za/0.0.0.0 address=/tsauctions.com/0.0.0.0 @@ -92648,6 +92652,7 @@ address=/tunnelpros.com/0.0.0.0 address=/tunnelview.co.uk/0.0.0.0 address=/tunuvo.com/0.0.0.0 address=/tuobrasocial.com.ar/0.0.0.0 +address=/tuoitrethainguyen.vn/0.0.0.0 address=/tupibaje.com/0.0.0.0 address=/tupperware.michaelroberge.ca/0.0.0.0 address=/tur.000webhostapp.com/0.0.0.0 @@ -93794,7 +93799,6 @@ address=/unlimit517.co.jp/0.0.0.0 address=/unlimited.nu/0.0.0.0 address=/unlimitedbags.club/0.0.0.0 address=/unlimitedfreightco.com/0.0.0.0 -address=/unlimitedimportandexport.com/0.0.0.0 address=/unlock-king.com/0.0.0.0 address=/unlock2.neagoeandrei.com/0.0.0.0 address=/unlockall.neagoeandrei.com/0.0.0.0 @@ -94120,6 +94124,7 @@ address=/url-update.com/0.0.0.0 address=/url-validation-clients.com/0.0.0.0 address=/url.246546.com/0.0.0.0 address=/url.57569.fr.snd52.ch/0.0.0.0 +address=/url2.mailanyone.net/0.0.0.0 address=/url3.mailanyone.net/0.0.0.0 address=/url5459.41southbar.com/0.0.0.0 address=/url675.textilmallorca.com/0.0.0.0 @@ -94323,7 +94328,6 @@ address=/utterstock.in/0.0.0.0 address=/utting.org/0.0.0.0 address=/utv.sakeronline.se/0.0.0.0 address=/utv1.enliden.net/0.0.0.0 -address=/uujian.cn/0.0.0.0 address=/uumove.com/0.0.0.0 address=/uurty87e8rt7rt.com/0.0.0.0 address=/uutiset.helppokoti.fi/0.0.0.0 @@ -96297,7 +96301,6 @@ address=/voin.staysafe.pk/0.0.0.0 address=/voingani.it/0.0.0.0 address=/voip96.ru/0.0.0.0 address=/voipminic.com/0.0.0.0 -address=/vokasi.ub.ac.id/0.0.0.0 address=/vokzalrf.ru/0.0.0.0 address=/vol.agency/0.0.0.0 address=/vol2.pw/0.0.0.0 @@ -96925,7 +96928,6 @@ address=/washnworks.com/0.0.0.0 address=/washuis.nl/0.0.0.0 address=/wasidora.com/0.0.0.0 address=/wasilewski-online.de/0.0.0.0 -address=/wasimjee.com/0.0.0.0 address=/wasino.co.th/0.0.0.0 address=/wasobd.net/0.0.0.0 address=/waspha.com/0.0.0.0 @@ -98465,7 +98467,6 @@ address=/woaldi2.com/0.0.0.0 address=/woatinkwoo.com/0.0.0.0 address=/woclawoffers.fun/0.0.0.0 address=/wocomm.marketingmindz.com/0.0.0.0 -address=/wodfitapparel.fr/0.0.0.0 address=/wodmetaldom.pl/0.0.0.0 address=/wodsuit.com/0.0.0.0 address=/woelf.in/0.0.0.0 @@ -101094,7 +101095,9 @@ address=/yoyoplease.com/0.0.0.0 address=/yoyoso.nz/0.0.0.0 address=/yoyoteacher.cn/0.0.0.0 address=/yp.dcyazilim.com/0.0.0.0 +address=/yp.hnggzyjy.cn/0.0.0.0 address=/ypbb.or.id/0.0.0.0 +address=/ypddf.org/0.0.0.0 address=/ypicsdy.cf/0.0.0.0 address=/ypko-55.gq/0.0.0.0 address=/ypom.com.br/0.0.0.0 @@ -101253,7 +101256,6 @@ address=/yusukelife.com/0.0.0.0 address=/yuti.kr/0.0.0.0 address=/yuvann.com/0.0.0.0 address=/yuvikadvertisments.com/0.0.0.0 -address=/yuwaraja.vokasi.ub.ac.id/0.0.0.0 address=/yuweis.com/0.0.0.0 address=/yuxigon.com/0.0.0.0 address=/yuxuanknit.com/0.0.0.0 diff --git a/urlhaus-filter-domains-online.txt b/urlhaus-filter-domains-online.txt index aa7f9692..7769dddf 100644 --- a/urlhaus-filter-domains-online.txt +++ b/urlhaus-filter-domains-online.txt @@ -1,5 +1,5 @@ # Title: Online Malicious Domains Blocklist -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -39,7 +39,6 @@ 1.246.222.98 1.246.223.10 1.246.223.105 -1.246.223.109 1.246.223.126 1.246.223.127 1.246.223.130 @@ -70,7 +69,8 @@ 1008691.com 101.108.129.251 101.108.130.121 -101.108.131.47 +101.108.131.99 +101.108.138.150 101.16.183.179 101.229.85.127 101.255.36.154 @@ -78,6 +78,8 @@ 101.28.218.245 101.28.76.34 101.75.157.99 +101.99.91.200 +101.99.94.15 102.130.115.14 102.141.240.139 103.113.99.79 @@ -92,25 +94,18 @@ 103.237.21.36 103.238.228.3 103.240.249.121 -103.4.117.26 -103.47.104.246 103.79.112.254 -103.82.98.170 +103.82.81.37 103.84.240.130 103.84.241.94 103.91.245.12 -103.91.245.13 103.91.245.14 -103.91.245.16 -103.91.245.17 -103.91.245.27 -103.91.245.3 +103.91.245.19 103.91.245.36 -103.91.245.46 -103.91.245.47 +103.91.245.48 103.92.25.90 103.92.25.95 -104.168.44.57 +103.97.184.180 104.184.75.123 104.206.93.94 104.33.52.85 @@ -121,6 +116,7 @@ 106.105.33.43 107.172.104.105 107.172.141.115 +107.172.156.3 107.172.249.148 107.173.219.80 107.173.23.240 @@ -137,10 +133,10 @@ 108.190.250.48 108.239.155.26 108.249.194.121 -109.104.151.108 109.124.90.229 109.233.196.232 109.235.7.228 +109.248.58.238 109.86.85.253 109.95.200.102 109.95.200.230 @@ -156,13 +152,13 @@ 110.248.251.194 110.251.10.18 110.253.213.198 +110.35.145.127 110.35.208.21 -110.35.209.175 -110.35.223.92 -110.35.225.24 +110.35.221.77 110.35.235.57 +110.35.249.21 110.35.4.2 -111.118.88.128 +110.89.10.147 111.118.88.61 111.119.245.114 111.125.67.125 @@ -177,12 +173,9 @@ 111.185.49.223 111.38.103.114 111.38.103.122 -111.38.104.141 111.38.121.222 -111.38.121.223 111.38.121.226 111.38.123.136 -111.38.123.15 111.38.123.200 111.38.26.243 111.38.8.81 @@ -203,12 +196,8 @@ 112.230.168.103 112.232.0.112 112.237.141.241 -112.237.144.226 -112.237.75.157 -112.237.99.207 112.238.143.135 112.238.190.207 -112.238.227.228 112.238.39.2 112.239.101.146 112.240.216.17 @@ -222,6 +211,7 @@ 112.247.214.146 112.247.240.226 112.247.82.122 +112.248.109.156 112.248.148.90 112.248.63.212 112.249.109.217 @@ -241,6 +231,7 @@ 112.27.124.143 112.27.124.147 112.27.124.149 +112.27.124.150 112.27.124.158 112.27.124.165 112.27.124.175 @@ -273,34 +264,34 @@ 112.30.1.60 112.30.1.90 112.30.1.91 +112.30.110.30 112.30.110.38 112.30.110.45 112.30.110.60 112.30.35.237 -112.30.4.103 112.30.4.118 112.30.4.124 112.30.4.53 112.30.4.61 112.30.4.68 -112.30.4.70 112.30.4.73 112.30.4.90 112.31.0.113 112.31.177.39 -112.31.211.135 112.31.216.207 -112.31.240.239 112.53.224.79 112.53.227.66 112.65.53.175 +112.72.162.159 112.72.162.49 112.72.175.147 112.72.176.112 +112.72.176.84 112.72.226.202 112.80.215.101 112.82.146.253 112.82.224.139 +112.9.155.122 112.93.29.211 113.11.95.254 113.118.249.97 @@ -308,65 +299,77 @@ 113.13.241.32 113.161.58.249 113.161.78.185 +113.194.131.72 +113.194.135.223 +113.226.42.250 113.230.86.107 113.231.184.245 113.231.211.131 113.254.169.251 113.59.128.133 +113.59.136.39 +113.59.144.42 113.59.149.125 -113.59.154.21 -113.59.180.40 113.59.191.47 113.61.204.205 113.65.10.139 -113.88.153.5 -113.88.192.87 +113.88.123.22 +113.88.228.152 113.89.43.165 -114.199.204.37 114.199.253.235 114.201.201.68 114.224.203.128 114.30.54.64 -114.35.254.7 114.79.172.42 115.165.216.112 115.171.204.161 115.42.47.36 -115.48.140.22 -115.49.77.222 +115.49.232.197 +115.50.172.22 +115.50.2.148 115.51.106.238 +115.51.91.81 115.53.203.161 -115.54.241.214 +115.54.212.175 115.55.156.203 +115.55.7.9 115.56.131.242 115.56.133.96 115.56.155.202 -115.56.178.168 -115.56.182.146 -115.56.182.151 -115.58.111.76 -115.58.132.140 -115.59.203.197 115.59.214.205 115.59.233.160 115.59.252.120 115.61.110.120 +115.61.167.21 +115.62.172.140 +115.62.26.113 115.73.3.11 115.75.217.79 115.88.133.148 115.92.174.231 -115.97.139.110 +116.108.92.154 116.124.219.2 116.206.164.46 116.211.100.26 +117.194.162.12 117.20.204.138 117.20.204.5 117.20.210.52 +117.20.220.126 117.20.243.40 117.201.205.232 -117.251.59.124 +117.202.64.149 +117.213.12.177 +117.213.47.94 +117.213.9.42 +117.215.249.250 +117.222.173.91 +117.222.175.134 +117.242.208.197 +117.247.201.45 117.26.124.173 117.63.113.146 +117.63.133.251 117.63.53.15 117.86.105.110 118.101.7.28 @@ -390,10 +393,9 @@ 118.233.65.93 118.42.125.246 118.43.180.33 +118.79.113.239 118.79.218.213 118.79.50.203 -118.79.74.77 -118.91.41.135 118.99.179.164 118.99.183.235 118.99.239.217 @@ -412,6 +414,7 @@ 119.179.43.1 119.179.58.163 119.18.38.144 +119.18.88.78 119.180.106.217 119.181.119.21 119.182.97.232 @@ -427,14 +430,14 @@ 119.191.255.236 119.204.30.144 119.250.129.231 -119.251.105.221 119.56.131.155 119.56.143.46 119.56.143.71 119.56.148.115 119.56.155.57 -119.56.166.36 +119.56.206.43 119.96.38.150 +119.99.52.69 12.132.113.2 12.15.69.83 12.178.187.6 @@ -457,23 +460,20 @@ 120.193.91.201 120.193.91.202 120.193.91.204 -120.193.91.208 120.193.91.215 120.193.91.233 +120.209.126.206 120.209.126.235 120.209.126.239 -120.209.126.25 120.209.126.250 120.209.126.60 120.209.126.74 120.209.99.127 120.50.66.60 120.50.93.115 -120.57.123.202 120.6.8.11 120.7.75.99 120.83.79.42 -120.85.172.111 121.100.114.164 121.100.96.8 121.121.44.222 @@ -494,6 +494,7 @@ 121.254.76.17 121.61.96.158 121.61.97.64 +121.8.107.214 121.88.99.236 122.100.150.204 122.137.53.134 @@ -505,7 +506,7 @@ 122.232.227.128 122.254.33.214 123.0.240.58 -123.10.137.193 +123.10.32.252 123.11.202.178 123.110.124.244 123.110.170.237 @@ -513,7 +514,6 @@ 123.110.19.248 123.110.200.98 123.110.238.188 -123.12.164.165 123.129.2.28 123.129.84.36 123.130.208.52 @@ -527,6 +527,7 @@ 123.134.14.130 123.135.20.164 123.135.246.180 +123.14.95.26 123.154.236.114 123.159.8.100 123.183.16.71 @@ -552,11 +553,11 @@ 123.241.148.58 123.241.184.124 123.28.217.23 -123.4.204.223 -123.4.251.81 -123.8.250.132 -123.9.193.253 -123.9.85.25 +123.4.242.19 +123.4.47.57 +123.5.148.182 +123.5.189.15 +123.9.36.120 124.129.221.150 124.129.76.230 124.130.40.31 @@ -592,24 +593,20 @@ 125.40.1.235 125.40.146.46 125.40.3.71 +125.41.14.228 125.43.82.59 -125.44.8.154 125.45.186.88 125.45.66.253 -125.47.244.8 +125.47.244.126 125.47.74.230 -125.47.93.160 126.39.155.210 128.116.133.92 -13.114.247.134 130.255.159.133 -134.119.186.214 135.148.36.127 138.99.204.224 139.159.226.180 139.170.173.198 139.216.102.151 -14.102.17.222 14.136.80.242 14.138.8.215 14.138.8.51 @@ -623,10 +620,15 @@ 14.50.129.248 14.55.29.2 140.237.12.32 +141.105.65.94 142.11.216.5 142.177.56.127 +143.198.120.58 148.69.108.177 149.255.15.134 +149.255.15.170 +149.255.15.29 +149.255.15.44 149.255.15.99 149.3.124.194 14karatvisions.com @@ -646,9 +648,8 @@ 162.191.165.238 162.194.28.60 162.209.98.174 -163.125.200.234 +162.245.221.121 163.125.206.193 -163.53.206.228 167.114.172.177 170.81.238.178 171.121.255.12 @@ -686,17 +687,18 @@ 175.201.104.192 175.208.230.8 175.213.25.192 -175.42.46.118 176.111.174.35 176.111.174.66 176.111.174.67 176.113.161.104 176.113.161.121 176.113.161.59 +176.113.161.65 176.113.161.66 176.113.161.71 176.113.161.76 176.113.161.84 +176.113.161.91 176.113.161.95 176.12.117.70 176.123.7.115 @@ -704,7 +706,6 @@ 176.124.7.225 176.221.188.251 176.240.84.106 -177.11.92.78 177.131.226.235 177.54.82.154 178.124.182.187 @@ -712,7 +713,6 @@ 178.150.174.65 178.151.143.2 178.165.122.141 -178.17.171.144 178.175.0.145 178.175.0.24 178.175.1.179 @@ -721,128 +721,130 @@ 178.175.10.124 178.175.10.182 178.175.10.221 +178.175.10.247 178.175.10.96 +178.175.100.104 178.175.100.151 +178.175.101.212 178.175.101.252 178.175.102.207 178.175.102.217 178.175.102.25 -178.175.103.52 +178.175.103.14 178.175.103.58 178.175.104.112 +178.175.104.115 178.175.105.67 -178.175.105.89 178.175.106.160 178.175.106.179 -178.175.106.199 +178.175.107.135 178.175.107.142 -178.175.107.156 178.175.107.224 178.175.108.127 178.175.108.173 -178.175.108.87 178.175.109.165 178.175.109.181 +178.175.11.100 178.175.11.101 178.175.11.139 178.175.11.6 178.175.110.191 178.175.110.195 -178.175.111.190 178.175.112.111 178.175.112.183 -178.175.112.254 178.175.112.85 +178.175.112.87 178.175.113.174 +178.175.114.117 178.175.114.151 178.175.114.51 178.175.115.106 178.175.115.208 178.175.116.254 -178.175.116.56 -178.175.117.110 -178.175.118.112 -178.175.118.129 178.175.118.174 178.175.118.41 178.175.119.161 178.175.119.43 -178.175.12.222 178.175.12.68 +178.175.12.91 178.175.120.12 +178.175.121.125 +178.175.121.130 178.175.121.151 178.175.121.169 +178.175.121.243 +178.175.121.77 178.175.122.172 -178.175.122.28 +178.175.122.197 178.175.122.47 -178.175.123.202 178.175.123.53 +178.175.124.113 178.175.124.38 -178.175.125.149 178.175.125.218 -178.175.125.52 178.175.126.129 178.175.126.18 178.175.126.234 -178.175.126.46 +178.175.126.43 178.175.126.80 178.175.127.202 178.175.127.90 -178.175.14.222 -178.175.14.248 -178.175.14.34 +178.175.13.219 178.175.15.19 +178.175.15.196 178.175.15.232 178.175.15.250 178.175.15.72 +178.175.16.224 178.175.16.26 178.175.16.86 -178.175.17.13 178.175.17.135 178.175.17.14 178.175.17.50 -178.175.17.54 178.175.17.9 -178.175.19.163 -178.175.2.183 +178.175.18.177 +178.175.18.31 178.175.2.189 178.175.2.217 +178.175.2.23 178.175.2.46 178.175.2.71 178.175.20.117 178.175.20.126 178.175.20.231 178.175.21.194 -178.175.21.34 +178.175.21.53 178.175.21.71 178.175.22.120 +178.175.22.198 178.175.22.206 178.175.22.51 +178.175.22.74 178.175.22.93 178.175.22.94 178.175.24.107 178.175.24.176 178.175.24.183 -178.175.24.232 -178.175.25.114 -178.175.25.56 +178.175.24.52 +178.175.25.162 178.175.26.215 178.175.27.151 +178.175.27.203 178.175.27.32 -178.175.28.48 +178.175.27.43 178.175.28.5 178.175.29.135 178.175.29.233 -178.175.29.35 178.175.3.109 178.175.30.187 -178.175.30.254 178.175.30.71 +178.175.30.90 178.175.31.128 +178.175.31.216 178.175.31.55 178.175.31.92 178.175.32.34 178.175.33.190 +178.175.33.233 178.175.34.180 178.175.34.222 178.175.35.83 @@ -853,18 +855,18 @@ 178.175.36.250 178.175.36.98 178.175.37.10 -178.175.37.122 178.175.37.149 178.175.37.215 178.175.37.234 178.175.38.12 178.175.38.74 178.175.38.88 -178.175.39.157 +178.175.39.110 178.175.39.158 178.175.39.203 178.175.39.210 178.175.4.120 +178.175.4.14 178.175.4.180 178.175.4.225 178.175.40.108 @@ -873,87 +875,91 @@ 178.175.41.139 178.175.41.182 178.175.41.217 +178.175.41.230 178.175.41.68 178.175.42.221 178.175.42.28 178.175.42.46 178.175.43.114 178.175.43.217 -178.175.43.238 +178.175.43.90 178.175.44.186 178.175.44.38 178.175.44.56 178.175.44.78 -178.175.45.125 178.175.45.234 +178.175.46.110 178.175.46.113 -178.175.46.196 -178.175.46.208 178.175.47.11 178.175.47.122 +178.175.47.127 178.175.47.2 178.175.47.222 178.175.47.75 178.175.47.80 178.175.47.99 +178.175.48.164 178.175.48.185 178.175.48.194 178.175.48.223 +178.175.49.104 +178.175.49.253 178.175.49.30 178.175.49.51 178.175.49.54 178.175.49.82 -178.175.5.254 +178.175.5.223 178.175.5.44 178.175.50.217 178.175.50.3 178.175.50.42 178.175.50.54 178.175.50.68 -178.175.51.177 +178.175.51.117 178.175.51.2 +178.175.52.114 +178.175.52.139 178.175.52.15 178.175.52.176 178.175.52.181 178.175.52.24 +178.175.52.255 178.175.53.214 178.175.53.231 178.175.53.62 178.175.53.79 +178.175.53.87 178.175.54.100 -178.175.54.196 +178.175.54.119 +178.175.54.78 +178.175.55.118 178.175.55.170 178.175.55.60 178.175.55.99 178.175.56.30 178.175.56.64 178.175.56.74 -178.175.57.112 +178.175.57.121 178.175.57.145 178.175.58.12 -178.175.58.235 +178.175.58.130 +178.175.58.18 178.175.59.103 -178.175.59.106 178.175.59.12 -178.175.59.158 -178.175.6.144 -178.175.6.180 -178.175.60.158 -178.175.60.49 -178.175.60.7 -178.175.61.250 +178.175.59.173 +178.175.59.8 +178.175.6.201 +178.175.6.203 +178.175.61.212 178.175.61.28 -178.175.62.137 +178.175.62.130 178.175.62.151 178.175.62.206 -178.175.63.223 178.175.63.53 178.175.64.116 178.175.65.234 178.175.65.237 -178.175.66.140 178.175.66.186 -178.175.66.214 178.175.67.28 178.175.67.65 178.175.68.140 @@ -964,9 +970,7 @@ 178.175.68.35 178.175.68.4 178.175.68.5 -178.175.69.18 178.175.7.113 -178.175.7.19 178.175.7.198 178.175.70.108 178.175.70.177 @@ -977,40 +981,37 @@ 178.175.71.69 178.175.72.208 178.175.72.220 +178.175.72.58 178.175.74.223 178.175.75.94 178.175.76.146 178.175.76.221 178.175.76.33 +178.175.76.34 178.175.76.8 -178.175.77.47 178.175.78.118 -178.175.78.125 178.175.78.250 178.175.79.128 178.175.79.146 178.175.79.198 +178.175.79.27 178.175.8.119 -178.175.8.13 -178.175.8.130 178.175.8.40 -178.175.81.114 178.175.81.144 178.175.81.189 178.175.82.110 178.175.82.73 178.175.83.125 +178.175.83.17 +178.175.84.146 178.175.84.154 178.175.84.201 178.175.84.237 178.175.85.190 -178.175.86.117 178.175.86.49 -178.175.86.59 178.175.87.151 178.175.87.161 178.175.87.202 -178.175.87.207 178.175.87.227 178.175.88.102 178.175.88.130 @@ -1018,34 +1019,31 @@ 178.175.88.204 178.175.88.85 178.175.89.152 -178.175.89.69 +178.175.89.195 +178.175.9.217 178.175.9.223 -178.175.9.24 178.175.90.137 178.175.90.236 178.175.90.3 178.175.90.79 +178.175.91.243 178.175.91.3 178.175.91.97 178.175.92.170 -178.175.93.115 +178.175.92.213 178.175.93.120 +178.175.93.204 178.175.93.234 178.175.93.42 -178.175.93.98 -178.175.94.248 -178.175.94.27 178.175.95.105 178.175.95.54 +178.175.95.83 178.175.96.136 178.175.96.177 -178.175.96.198 178.175.96.225 178.175.97.248 -178.175.97.70 178.175.98.63 178.175.99.45 -178.175.99.90 178.19.183.14 178.205.101.33 178.21.164.68 @@ -1073,7 +1071,9 @@ 180.177.104.65 180.177.180.6 180.177.242.73 +180.177.5.36 180.218.5.171 +180.248.80.38 180.66.111.36 180.66.53.93 180.94.170.166 @@ -1090,40 +1090,45 @@ 181.49.236.4 181.49.59.162 182.112.177.134 -182.114.88.240 -182.114.88.247 -182.115.176.253 +182.113.4.247 +182.114.194.183 182.116.102.190 -182.116.35.52 +182.117.29.27 182.119.200.55 +182.119.23.75 +182.119.48.230 182.120.16.22 182.120.192.88 182.120.34.180 -182.121.73.158 +182.121.200.137 +182.121.205.246 182.122.254.7 +182.126.109.194 +182.126.126.162 182.126.87.210 182.126.87.246 -182.127.213.136 +182.127.207.187 +182.127.80.240 182.160.98.250 182.233.0.252 182.235.252.31 182.53.197.62 -182.59.170.157 182.88.27.89 183.105.104.83 183.109.169.45 +183.141.61.174 183.17.145.112 183.188.144.204 -183.188.146.216 -183.83.109.216 +183.49.86.54 183.83.14.20 183.97.40.9 184.164.185.41 184.175.115.10 184.74.149.230 185.106.209.68 -185.107.3.8 185.117.2.107 +185.117.21.212 +185.132.53.182 185.172.110.209 185.172.110.235 185.174.101.41 @@ -1140,14 +1145,13 @@ 185.245.96.94 185.26.113.95 185.34.16.231 +185.38.142.194 185.55.1.182 185.68.230.207 185.81.154.208 185.81.157.186 185.82.217.185 185.82.217.213 -185.82.219.160 -185.82.219.161 185.82.219.219 185.82.219.80 186.151.144.85 @@ -1161,7 +1165,6 @@ 186.28.60.184 186.34.4.40 186.73.188.132 -186.73.188.134 187.12.10.98 187.135.141.192 187.188.124.229 @@ -1173,12 +1176,15 @@ 188.152.41.141 188.169.178.50 188.169.179.127 +188.169.199.59 188.169.30.30 188.169.36.163 +188.169.45.140 188.242.242.144 188.69.251.12 188.83.202.25 -189.201.250.184 +189.171.22.132 +189.175.214.112 189.252.184.115 190.0.42.106 190.109.178.139 @@ -1193,7 +1199,6 @@ 190.122.112.42 190.122.112.76 190.130.20.14 -190.141.117.41 190.147.16.184 190.159.240.9 190.210.214.130 @@ -1209,19 +1214,20 @@ 190.98.37.200 190.98.41.33 191.255.248.220 -192.153.57.94 192.210.175.130 +192.227.185.106 192.227.220.55 192.227.228.67 +192.99.221.230 192.99.240.77 194.113.107.243 194.147.142.230 -194.15.36.167 194.152.35.139 194.38.20.199 195.139.126.51 195.228.231.218 195.24.94.187 +195.5.3.162 196.202.26.182 196.218.48.82 196.221.148.90 @@ -1229,15 +1235,12 @@ 197.159.2.106 197.50.27.115 198.23.133.218 -198.23.174.104 -198.23.207.121 +198.23.213.61 198.23.251.105 -198.46.132.132 1am.co.nz 2.239.22.188 2.36.231.201 2.37.149.230 -2.37.203.65 2.45.111.158 2.45.4.24 2.55.125.182 @@ -1250,7 +1253,6 @@ 200.105.167.98 200.111.189.70 200.194.4.24 -200.2.161.171 200.29.105.207 200.30.132.50 201.170.46.2 @@ -1261,14 +1263,13 @@ 202.107.233.41 202.111.131.236 202.166.217.54 -202.182.125.175 202.29.95.12 202.4.124.58 -202.44.228.125 202.51.176.114 202.51.191.174 202.74.236.9 203.109.201.243 +203.130.69.205 203.159.80.128 203.159.80.129 203.159.80.164 @@ -1295,12 +1296,12 @@ 210.180.237.212 210.216.152.122 210.216.153.142 -210.57.237.70 210.57.245.109 210.68.242.114 211.187.132.204 211.187.75.220 211.200.160.239 +211.203.111.207 211.204.215.157 211.210.66.179 211.210.93.93 @@ -1309,7 +1310,6 @@ 211.237.120.13 211.237.246.137 211.238.83.238 -211.247.5.96 212.122.86.105 212.156.215.178 212.46.197.114 @@ -1319,7 +1319,7 @@ 213.14.173.117 213.149.190.193 213.163.104.160 -213.163.104.99 +213.163.104.20 213.163.113.225 213.163.113.51 213.163.114.202 @@ -1336,7 +1336,7 @@ 213.163.118.227 213.163.126.176 213.163.126.201 -213.163.126.7 +213.163.127.204 213.163.127.250 213.163.127.46 213.189.178.163 @@ -1356,7 +1356,6 @@ 218.2.40.34 218.234.165.18 218.238.246.3 -218.32.118.1 218.35.207.119 218.35.227.133 218.35.68.35 @@ -1366,11 +1365,12 @@ 218.79.103.159 218.93.102.63 218.93.102.75 +219.154.113.171 219.154.127.194 -219.154.137.93 -219.156.73.171 +219.155.226.205 219.157.136.212 -219.157.139.165 +219.157.14.239 +219.157.178.196 219.157.37.210 219.241.6.180 219.68.1.148 @@ -1385,7 +1385,6 @@ 219.85.145.194 21robo.com 220.126.237.74 -220.132.106.247 220.173.160.185 220.200.22.163 220.81.134.72 @@ -1393,7 +1392,9 @@ 221.124.78.15 221.13.150.74 221.14.162.20 +221.14.47.204 221.15.127.60 +221.15.182.72 221.15.3.50 221.157.191.178 221.160.136.213 @@ -1411,18 +1412,17 @@ 221.232.183.167 221.235.137.36 221.3.68.16 +222.107.145.56 222.108.17.64 222.118.248.149 222.119.65.145 -222.132.125.138 222.135.9.5 222.137.122.105 222.137.139.86 -222.137.170.17 222.137.72.66 222.138.133.186 -222.138.17.203 222.139.21.190 +222.140.163.181 222.140.17.245 222.187.9.178 222.211.72.66 @@ -1445,9 +1445,9 @@ 23.24.213.121 23.243.149.13 23.243.21.167 -23.92.213.108 23.94.190.101 23.95.122.24 +23.95.122.25 24.103.74.180 24.11.141.134 24.119.158.74 @@ -1518,9 +1518,7 @@ 27.213.255.202 27.213.66.112 27.213.84.74 -27.214.37.129 27.215.139.242 -27.215.190.172 27.215.212.209 27.215.253.149 27.215.71.243 @@ -1532,7 +1530,6 @@ 27.217.191.58 27.218.135.3 27.219.132.71 -27.219.151.83 27.219.160.112 27.219.176.72 27.219.83.244 @@ -1548,16 +1545,14 @@ 27.35.154.13 27.35.212.124 27.35.58.5 -27.40.120.108 -27.40.73.175 +27.40.79.170 27.41.36.97 -27.45.90.246 -27.5.44.190 31.0.98.131 31.11.51.57 31.13.23.180 31.168.124.130 31.168.146.199 +31.168.16.68 31.168.179.83 31.168.184.59 31.168.191.243 @@ -1607,7 +1602,6 @@ 39.113.245.254 39.113.98.136 39.114.137.102 -39.115.0.100 39.117.31.162 39.162.104.119 39.162.98.216 @@ -1668,27 +1662,34 @@ 40.88.2.151 41.139.209.46 41.165.130.43 -41.190.63.174 41.193.192.100 41.219.185.171 41.226.60.115 +41.72.203.82 +41.76.157.2 41.86.18.147 41.86.18.152 -41.86.18.204 -41.86.19.146 -41.86.19.206 -41.86.21.28 -41.86.21.60 -41.86.5.198 +41.86.21.38 +41.86.21.59 +41.86.5.103 +41.86.5.197 +41.86.5.48 42.202.101.181 42.202.101.199 +42.224.171.165 42.224.176.27 +42.224.254.220 +42.224.4.110 +42.227.222.189 +42.227.225.253 42.228.40.143 -42.228.60.114 +42.230.143.162 +42.233.97.141 +42.235.84.85 42.236.161.72 42.236.212.157 +42.237.114.80 42.238.141.250 -42.56.15.227 42.61.99.155 42.82.217.241 43.230.207.204 @@ -1707,6 +1708,7 @@ 45.144.225.27 45.148.10.47 45.148.10.94 +45.15.143.191 45.176.108.248 45.176.109.205 45.176.110.146 @@ -1715,6 +1717,7 @@ 45.229.53.148 45.27.253.137 45.51.104.59 +45.77.9.151 45.85.90.131 45.9.148.37 45.92.108.35 @@ -1735,8 +1738,8 @@ 46.42.118.86 46.42.86.128 46.97.76.242 +47.136.96.53 47.145.152.26 -47.151.23.172 47.157.97.71 47.16.131.51 47.21.202.98 @@ -1756,6 +1759,7 @@ 5.14.122.233 5.188.62.111 5.95.226.154 +50.115.174.103 50.115.174.106 50.121.91.255 50.247.83.66 @@ -1780,32 +1784,39 @@ 58.240.147.97 58.241.78.55 58.242.91.219 -58.249.73.208 +58.249.22.24 58.249.75.128 +58.249.75.146 +58.249.77.141 58.249.80.36 -58.252.176.140 58.253.15.184 58.51.219.200 58.72.165.153 58.72.165.39 59.0.211.161 59.102.168.189 -59.126.26.220 59.151.202.3 59.151.214.4 -59.151.237.51 -59.151.246.125 59.173.135.51 59.175.63.177 59.23.114.97 59.26.181.228 59.30.12.254 -59.60.117.163 +59.50.23.23 +59.89.242.116 +59.92.217.215 +59.92.218.82 +59.93.21.140 +59.93.21.172 +59.94.182.212 +59.95.175.49 +59.97.170.146 60.13.61.12 60.209.122.57 60.209.216.23 60.209.233.94 60.211.6.112 +60.211.80.216 60.212.100.83 60.212.111.39 60.212.206.246 @@ -1813,31 +1824,30 @@ 60.212.220.167 60.212.254.178 60.213.83.55 +60.214.53.159 60.214.85.149 60.217.177.196 60.217.86.208 -60.220.159.240 -60.253.15.104 -60.253.39.88 60.253.4.72 60.253.51.127 60.253.60.174 60.253.8.81 -60.254.36.135 60.7.10.121 60.7.8.43 61.146.108.150 +61.163.131.67 61.179.91.194 61.247.224.66 +61.3.150.101 61.52.101.143 +61.52.186.186 61.52.241.252 61.52.57.40 61.52.9.166 +61.52.97.68 61.52.98.43 61.52.99.161 61.53.117.152 -61.53.249.58 -61.53.74.236 61.54.103.56 61.56.180.67 61.56.181.7 @@ -1869,7 +1879,6 @@ 66.108.199.144 66.57.55.210 66.74.7.197 -66.91.21.31 66.97.181.196 67.245.151.203 67.8.138.101 @@ -1931,6 +1940,7 @@ 74.64.139.223 74.75.165.81 75.127.141.52 +75.83.102.27 75.99.213.61 76.170.11.82 76.178.22.145 @@ -1940,14 +1950,12 @@ 76.84.134.33 76.89.107.69 76.95.12.137 -77.111.182.31 77.237.25.210 77.71.50.153 77.89.203.238 77st.net 78.138.98.134 78.145.224.45 -78.187.141.144 78.187.41.200 78.188.106.235 78.188.168.64 @@ -1968,7 +1976,6 @@ 80.107.89.207 80.19.101.218 80.211.181.77 -80.217.12.7 80.99.128.61 81.136.146.213 81.165.44.109 @@ -1985,7 +1992,6 @@ 81.92.36.96 82.103.108.72 82.135.196.130 -82.166.212.178 82.166.85.112 82.207.61.194 82.209.250.155 @@ -2036,14 +2042,17 @@ 85.105.208.25 85.105.224.141 85.105.241.2 -85.108.133.19 85.214.149.236 85.241.39.182 +85.250.147.134 85.64.181.50 85.74.215.180 85.97.130.227 86.35.43.220 +86.98.23.78 +87.117.11.46 87.172.19.130 +87.251.71.78 87du.vip 88.119.171.253 88.129.208.43 @@ -2070,7 +2079,6 @@ 8poieq.bn.files.1drv.com 90.152.144.139 91.132.197.39 -91.138.215.5 91.177.139.132 91.187.103.32 91.212.150.241 @@ -2085,6 +2093,7 @@ 92.54.237.237 92.83.62.139 92.85.18.138 +93.157.63.221 93.159.169.190 93.173.235.110 93.21.224.154 @@ -2098,13 +2107,13 @@ 94.136.69.199 94.143.53.34 94.154.17.170 +94.154.82.190 94.200.16.22 94.224.83.208 94.53.120.109 94.85.0.3 95.132.129.250 95.133.158.20 -95.154.20.231 95.158.19.130 95.170.113.227 95.170.201.34 @@ -2140,7 +2149,6 @@ addahealingmusic.com adithimedia.com adithimedia.memengers.com admin.erapor.smk-alasror.net -admin.gentbcn.org admin.grandoceanvilla.com admission.kmctartskuttippuram.org adventureexplorer.in @@ -2156,6 +2164,7 @@ aiecons.com aiqtest.com ajpharmaholding.com akdvidyalaya.com +al-wahd.com alasdemariposas.org alberts.diamondrelationscrm.us alemelektronik.com @@ -2194,7 +2203,6 @@ aps-sv.com artedibujoyarquitectura.com arwenyapi.com ask-regard.call-save.biz -asucssa.live atfile.com athenacapsg.com atlasconcreteworks.com @@ -2206,15 +2214,17 @@ australianpga.com.au automaticrefreshments.com avadhanagames.com aventuramotorhome.com +awumad01.top +awuqze02.top ayahuascasp.com.br ayamallah.com -aycconsultoriaempresarial.com azmeasurement.com azraktours.com b.r.uce.lee.b.es.t@zytrox.tk b2b.toptanakaryakit.com.tr backgrounds.pk badeggdesign.com +bakamla.go.id balealgodon.mx bangkok-orchids.com bangladeshunbound.com @@ -2235,7 +2245,6 @@ beor360.com bespokeweddings.ie bestcarenepal.com betone.co.kr -betycopaints.com beveragesmiami.solucioneslink.com bhavaniengineering.com bigmikesupplies.co.za @@ -2291,12 +2300,12 @@ canadianwork.cc capitalgroup-kw.com capoeiraventrelivre.com cashyinvestment.org +casiomaneflirt.cf catchpoolshetlands.co.uk cazyacustomfurniture.com cbn.hypervoizd.com ccauthority.net cdaonline.com.ar -cdn-10049480.file.myqcloud.com cec.asso.ac-amiens.fr cellas.sk cendekiabinaaksara.com @@ -2310,17 +2319,17 @@ chinhdropfile.myvnc.com chinhdropfile80.myvnc.com cible-energy.com cifeer.net +citiconstructioncorp.com citihits.lk citssolutions.co.za -citycapproperty.ru cityglobalgospel.com civi.istmejia.com cleanbydesignllc.com cloud.fc.co.mz cnc.tacobelllover.tk codsambal.com -colinde.pricesne.com colorpak.pl +columbia.aula-web.net community.reimclub.com competancy.indigoconsult.net conceptimagine.ro @@ -2330,9 +2339,11 @@ constructoralyon.com consulateins.solucioneslink.com contributeindustry.com copelandscapes.com +corwin-tommie06f.ru.com coulsongraphics.com count.mail.163.com.impactmedfoundation.com covid19.cyberschool.or.id +covid19vaccinations.hopto.org cr-sq.com craftech.nxtnet.ga crearechile.cl @@ -2395,6 +2406,7 @@ dl.1003b.56a.com dl.198424.com dl.installcdn-aws.com dl.packetstormsecurity.net +dl.pandasecur.com dl.rina-roleplay.com dnn.alibuf.com dns.alibuf.com @@ -2451,11 +2463,11 @@ endurotanzania.co.tz ennovate.elin.co.za equimination.ee erp.nanotechproautocare.com +esaja09.top escola.probommar.org.br eservices.immigration.gov.lk esnconsultants.com essentia.org.br -ethereality.info eubanks7.com europeanzonexxi.com exilum.com @@ -2473,7 +2485,7 @@ fineartgallerym.com fisconline.bar fisconline.casa fix-america-now.org -fixauto.illumetechnology.com +fkd.derpcity.ru flexypay.dsquaregroup.com flintspin.com flyingbuddhadesign.com @@ -2494,7 +2506,6 @@ fusionfiresolutions.com futbolpr.com futuregraphics.com.ar g.pinmonkey.xyz -gaditastour.com gametwogame.com garciadogshow.com garenanow.myvnc.com @@ -2524,7 +2535,6 @@ goldenasiacapital.com goldmen.in gpotecnosystems.com gracejukes.com -greataccesstoserver.com grupoinmare.com gruposelt.000webhostapp.com gs.monerorx.com @@ -2555,17 +2565,13 @@ hitstation.nl hmpmall.co.kr hoagietesting10.com hoayeuthuong-my.sharepoint.com -holmesservices.mobiledevsite.co homefindersolutions.com hometownchick.com -hongluosi.com hookedupboatclub.com hostingparacolombia.com hostzaa.com -houstonshutters.site hr2019.vrcom7.com hseda.com -hsmwebapp.com htownbars.com hubtech.co.za huellacero.cl @@ -2613,6 +2619,8 @@ isso.ps it123.ru italiandirezione.casa itc-demo.softgig.co.ke +itsrlytry.000webhostapp.com +jaishomo.info jamiekaylive.com jamshed.pk jansen-heesch.nl @@ -2640,11 +2648,11 @@ kalogirosfinance.com kaptaanchapal.com karer.by katanvetov.co.il +katelynn9506a.ru.com kensingtondriving.com ketofitnessexpert.com kevinjewelry.com.co keywatch.yourpageserver.com -kihn-delaney30gn.ru.com kingssa.co.za kjcpromo.com kleinendeli.co.za @@ -2652,7 +2660,6 @@ korrectconceptservices.com krisbadminton.com ktb.sch.id kubatoglubaklava.com.tr -kullumanalitours.com kumaralok.in kwanfromhongkong.com kz.sldov.ru @@ -2709,7 +2716,6 @@ mail.jeffsono.org maksi.feb.unib.ac.id malaya.tv malwarecoding.github.io -managed.oss-cn-beijing.aliyuncs.com managemysalon.in manantialesdelnorte.uy manhtien.net @@ -2752,6 +2758,7 @@ michimal2.000webhostapp.com microblading.mirliandias.com.br microcomm-group.com mikhailmotoringschool.com +mills-skyla30ec.com mingguanwms.com minuevavida.org mirror.mypage.sk @@ -2768,6 +2775,7 @@ monetization.business moninediy.com moreirawag.ac.ug motorcomunicacion.com +moumitas.com msacontabil.com.br mumgee.co.za muzimbiti.xigubo.co.mz @@ -2817,6 +2825,7 @@ nyasabigbullets.com nyeh2o.com.au obseques-conseils.com oecteam.com +ohe.ie ohsewgorgeous.co.uk oleholeh.memangbeda.website omaia.org @@ -2827,7 +2836,6 @@ omscoc.pappai.com onedigitalcard.granvizionnecorp.com onedrive.listifyapp.co online.creedglobal.in -open.rawntech.com open.warehousesaas.co.uk opolis.io optimus.com.sg @@ -2902,6 +2910,7 @@ prox.realunix.cc pujashoppe.in punchdialogues.com punjabdevelopersassociation.com.pk +pvcprinting.co.uk qadir.tickfa.ir qatarglobalconsulting.com qmsled.com @@ -2928,16 +2937,15 @@ readwrite26.nl readymmade.com recyclethesurplus.com redbats.co.in +redboxmultimedia.com redchillicrackers.com reifenquick.de -relaxindulge.co.nz renehavis.com.ua repatriacioncolombia.com res.uf1.cn reseller.digimitra.in reseller.itechbrasil.com resuco.net -revolet-sa.com rezkabum.ru rhema.com.sg richmondminerals.co.zm @@ -2952,6 +2960,7 @@ romanianpoints.com ronnietucker.co.uk roomsvc.servegate.kr roshnijewellery.com +rotronics.com.ph rsgym.net rubazar.pro rubycityvietnam.com @@ -2981,6 +2990,7 @@ scheff.com schoolbustracker.softgig.co.ke sculetus.nl secure-doc-reader.com +secure.activedirect.xyz segalsmetals.elin.co.za sellmyphonela.com selltechtoday.com @@ -2990,7 +3000,9 @@ serendibsourcing.com sericaasia.com servicemhkd.myvnc.com servicemhkd80.myvnc.com +serviciovirtual.com.ar sexologistpakistan.net +sgb.ac.ke sgessy.com.br shaheentbfoundation.com shahikhana.cstdevs.com @@ -3028,7 +3040,6 @@ sobariko.com sobethuacademy.com soft.110route.com soft.officelabo.net -sogecoenergy.com sohs.conceptechs.info solar.amazingtribe.lk somcorbera.cat @@ -3042,7 +3053,6 @@ spent.com.pl spetsesyachtcharter.gr spititourism.com spittinfire.com -springbedspetroleum.com src1.minibai.com sreenivasapaintingworks.com sriglobalit.com @@ -3053,16 +3063,23 @@ st.devcodin.com staging.apparelpunch.com starcountry.net static.3001.net +stdynbnbnewagedevixz.dns.army +stdynmxwllminoragest.dns.army +stdyunitedkesokokgst.dns.army +stdyworkfinetraingst.dns.army +stdyzgchgcloudgostxs.dns.army stiau.iuc.ac sticker.jewsjuice.com stiepancasetia.ac.id stlukesohag.com store.ericalgarin.com stott-thompson.co.uk +stratexec.co.za streetdemo.yourpageserver.com suboldesign.com sumerians.org sunaryem.com.tr +sunbrero.com.au sunmarkholidays.com support-4-free.com support.clz.kr @@ -3141,7 +3158,6 @@ topcell9.com toplevel.com.br topmask.co.za torresquinterocorp.com -towme.services toyotacollege.ac.th tpke.hu translaterjemah.com @@ -3168,7 +3184,6 @@ union.jctrip.cn unyazitelecom.com up.llw0.com upcbpta.com -used-jeans.fr useformoney.000webhostapp.com uss.ac.th uzzepay.com.br @@ -3177,7 +3192,6 @@ vbcargo.hu vcah.co.uk vectarts.com vegadelcasero.cl -velma-harber30ku.com vendas.lidiacarmeli.com.br veterinariadrpopui.com vfocus.net @@ -3193,7 +3207,6 @@ vivationdesign.com viveirodoiscorregos.com.br vksales.com vocalterra.com -vokasi.ub.ac.id vologroup.com.br voteyouramerica.dekitout.com vpts.co.za @@ -3214,6 +3227,7 @@ webpresario.com weinsteincounseling.com wfinance.com.br whcms.yourpageserver.com +whiteglovetailgate.com whiteresponse.com wi522012.ferozo.com wikalen.co.za @@ -3243,6 +3257,7 @@ yeichner.com yeq.i.u.j.ia.n.3@zytrox.tk ylfpremium.com yoast.yourpageserver.com +yp.hnggzyjy.cn yummyyogaudaipur.com yzkzixun.com ziyker4gaming@zytrox.tk diff --git a/urlhaus-filter-domains.txt b/urlhaus-filter-domains.txt index 529d316e..9458dd5a 100644 --- a/urlhaus-filter-domains.txt +++ b/urlhaus-filter-domains.txt @@ -1,5 +1,5 @@ # Title: Malicious Domains Blocklist -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -1391,6 +1391,7 @@ 101.0.34.225 101.0.34.229 101.0.34.230 +101.0.34.236 101.0.34.244 101.0.34.247 101.0.34.253 @@ -1657,6 +1658,7 @@ 101.108.131.81 101.108.131.89 101.108.131.92 +101.108.131.99 101.108.132.0 101.108.132.109 101.108.132.110 @@ -1808,6 +1810,7 @@ 101.108.137.77 101.108.138.108 101.108.138.109 +101.108.138.150 101.108.138.155 101.108.138.160 101.108.138.174 @@ -6073,6 +6076,7 @@ 103.91.245.45 103.91.245.46 103.91.245.47 +103.91.245.48 103.91.245.49 103.91.245.5 103.91.245.54 @@ -8785,6 +8789,7 @@ 107.172.153.90 107.172.156.122 107.172.156.153 +107.172.156.3 107.172.157.125 107.172.157.131 107.172.157.176 @@ -12195,6 +12200,7 @@ 111.92.81.107 111.92.81.109 111.92.81.111 +111.92.81.112 111.92.81.113 111.92.81.116 111.92.81.118 @@ -17651,6 +17657,7 @@ 112.248.108.109 112.248.108.18 112.248.108.182 +112.248.109.156 112.248.109.95 112.248.11.123 112.248.110.120 @@ -20361,6 +20368,7 @@ 112.9.149.240 112.9.153.32 112.9.154.61 +112.9.155.122 112.9.157.102 112.9.158.247 112.9.160.95 @@ -23894,6 +23902,7 @@ 113.194.131.162 113.194.131.197 113.194.131.210 +113.194.131.72 113.194.132.207 113.194.132.253 113.194.132.44 @@ -23908,6 +23917,7 @@ 113.194.133.9 113.194.134.64 113.194.135.154 +113.194.135.223 113.194.135.230 113.194.135.238 113.194.135.63 @@ -26565,6 +26575,7 @@ 113.88.122.63 113.88.122.78 113.88.123.145 +113.88.123.22 113.88.123.235 113.88.124.109 113.88.124.119 @@ -26936,6 +26947,7 @@ 113.88.211.95 113.88.224.159 113.88.228.13 +113.88.228.152 113.88.228.16 113.88.228.211 113.88.228.73 @@ -27190,6 +27202,7 @@ 113.88.65.37 113.88.65.38 113.88.65.48 +113.88.65.49 113.88.65.54 113.88.65.80 113.88.66.213 @@ -27396,6 +27409,7 @@ 113.89.247.90 113.89.248.112 113.89.248.181 +113.89.4.189 113.89.4.201 113.89.4.7 113.89.4.74 @@ -27663,6 +27677,7 @@ 113.9.241.101 113.9.29.128 113.9.94.126 +113.90.133.38 113.90.135.225 113.90.135.231 113.90.160.138 @@ -28334,6 +28349,7 @@ 114.223.238.75 114.223.244.108 114.223.28.254 +114.223.43.7 114.223.48.158 114.223.61.204 114.223.63.197 @@ -29092,6 +29108,7 @@ 114.235.211.48 114.235.211.60 114.235.211.88 +114.235.213.31 114.235.22.32 114.235.222.230 114.235.222.24 @@ -30061,6 +30078,7 @@ 114.97.224.73 114.97.225.120 114tv.cc +115.110.193.166 115.120.136.248 115.120.204.211 115.127.96.194 @@ -34705,6 +34723,7 @@ 115.49.232.129 115.49.232.177 115.49.232.185 +115.49.232.197 115.49.232.20 115.49.232.204 115.49.232.210 @@ -37075,6 +37094,7 @@ 115.50.172.21 115.50.172.212 115.50.172.216 +115.50.172.22 115.50.172.223 115.50.172.225 115.50.172.236 @@ -37429,6 +37449,7 @@ 115.50.2.128 115.50.2.132 115.50.2.141 +115.50.2.148 115.50.2.149 115.50.2.159 115.50.2.179 @@ -42351,6 +42372,7 @@ 115.51.91.62 115.51.91.66 115.51.91.70 +115.51.91.81 115.51.91.98 115.51.92.1 115.51.92.114 @@ -45315,6 +45337,7 @@ 115.54.212.163 115.54.212.17 115.54.212.173 +115.54.212.175 115.54.212.180 115.54.212.183 115.54.212.185 @@ -49424,6 +49447,7 @@ 115.55.7.241 115.55.7.55 115.55.7.60 +115.55.7.9 115.55.7.92 115.55.70.113 115.55.71.231 @@ -57123,6 +57147,7 @@ 115.59.248.228 115.59.25.113 115.59.25.169 +115.59.250.37 115.59.250.52 115.59.252.114 115.59.252.12 @@ -59306,6 +59331,7 @@ 115.61.167.185 115.61.167.196 115.61.167.207 +115.61.167.21 115.61.167.225 115.61.167.227 115.61.167.230 @@ -59814,6 +59840,7 @@ 115.61.186.106 115.61.186.11 115.61.186.114 +115.61.186.139 115.61.186.144 115.61.186.153 115.61.186.158 @@ -60695,6 +60722,7 @@ 115.62.171.71 115.62.171.81 115.62.172.135 +115.62.172.140 115.62.172.145 115.62.172.173 115.62.172.200 @@ -60753,6 +60781,7 @@ 115.62.25.100 115.62.26.100 115.62.26.102 +115.62.26.113 115.62.26.114 115.62.26.120 115.62.26.123 @@ -66692,6 +66721,7 @@ 115.96.199.129 115.96.199.132 115.96.199.138 +115.96.199.146 115.96.199.160 115.96.199.163 115.96.199.165 @@ -91491,6 +91521,7 @@ 116.106.77.111 116.108.32.244 116.108.71.196 +116.108.92.154 116.109.108.32 116.109.132.2 116.109.156.14 @@ -93312,6 +93343,7 @@ 116.68.96.98 116.68.96.99 116.68.97.1 +116.68.97.100 116.68.97.102 116.68.97.104 116.68.97.117 @@ -93430,6 +93462,7 @@ 116.68.99.129 116.68.99.132 116.68.99.139 +116.68.99.152 116.68.99.155 116.68.99.158 116.68.99.159 @@ -114168,6 +114201,7 @@ 117.194.162.117 117.194.162.118 117.194.162.119 +117.194.162.12 117.194.162.120 117.194.162.121 117.194.162.122 @@ -116157,6 +116191,7 @@ 117.201.197.124 117.201.199.181 117.201.199.230 +117.201.200.106 117.201.200.236 117.201.201.33 117.201.202.154 @@ -119705,6 +119740,7 @@ 117.213.12.130 117.213.12.148 117.213.12.158 +117.213.12.177 117.213.12.208 117.213.12.218 117.213.12.219 @@ -121202,6 +121238,7 @@ 117.213.9.1 117.213.9.177 117.213.9.203 +117.213.9.42 117.213.9.58 117.213.9.71 117.213.9.77 @@ -121558,6 +121595,7 @@ 117.215.249.174 117.215.249.175 117.215.249.181 +117.215.249.196 117.215.249.197 117.215.249.199 117.215.249.20 @@ -121570,6 +121608,7 @@ 117.215.249.241 117.215.249.242 117.215.249.245 +117.215.249.250 117.215.249.251 117.215.249.255 117.215.249.27 @@ -124072,6 +124111,7 @@ 117.222.175.122 117.222.175.13 117.222.175.130 +117.222.175.134 117.222.175.135 117.222.175.136 117.222.175.138 @@ -126039,6 +126079,7 @@ 117.247.201.42 117.247.201.43 117.247.201.44 +117.247.201.45 117.247.201.47 117.247.201.49 117.247.201.56 @@ -128763,6 +128804,7 @@ 117.63.124.134 117.63.127.23 117.63.130.19 +117.63.133.251 117.63.151.77 117.63.156.234 117.63.157.34 @@ -130763,6 +130805,7 @@ 118.79.112.110 118.79.112.230 118.79.112.54 +118.79.113.239 118.79.113.7 118.79.114.198 118.79.114.78 @@ -137071,6 +137114,7 @@ 119.99.251.129 119.99.30.19 119.99.50.91 +119.99.52.69 119.99.63.42 11bybbsny.com 11degrees.org @@ -145675,6 +145719,7 @@ 123.10.32.196 123.10.32.200 123.10.32.239 +123.10.32.252 123.10.32.87 123.10.32.95 123.10.33.112 @@ -153465,6 +153510,7 @@ 123.14.95.219 123.14.95.24 123.14.95.248 +123.14.95.26 123.14.96.154 123.14.96.157 123.14.96.209 @@ -155846,6 +155892,7 @@ 123.4.242.146 123.4.242.152 123.4.242.163 +123.4.242.19 123.4.242.199 123.4.242.204 123.4.242.21 @@ -156235,6 +156282,7 @@ 123.4.47.248 123.4.47.25 123.4.47.32 +123.4.47.57 123.4.48.128 123.4.48.40 123.4.48.70 @@ -159047,6 +159095,7 @@ 123.5.188.85 123.5.188.86 123.5.188.87 +123.5.188.9 123.5.188.93 123.5.188.97 123.5.189.101 @@ -159060,6 +159109,7 @@ 123.5.189.14 123.5.189.145 123.5.189.147 +123.5.189.15 123.5.189.150 123.5.189.151 123.5.189.154 @@ -161243,6 +161293,7 @@ 123.9.117.236 123.9.117.245 123.9.118.130 +123.9.118.183 123.9.118.79 123.9.119.209 123.9.119.47 @@ -162411,6 +162462,7 @@ 123.9.35.198 123.9.35.6 123.9.35.88 +123.9.36.120 123.9.36.188 123.9.36.222 123.9.36.6 @@ -168259,6 +168311,7 @@ 125.41.14.219 125.41.14.22 125.41.14.220 +125.41.14.228 125.41.14.232 125.41.14.235 125.41.14.237 @@ -188676,6 +188729,7 @@ 143.198.220.102 143.198.48.37 143.198.54.180 +143.198.54.233 143.198.63.143 143.198.65.195 143.198.65.229 @@ -188942,6 +188996,7 @@ 149.255.15.134 149.255.15.138 149.255.15.143 +149.255.15.170 149.255.15.172 149.255.15.180 149.255.15.182 @@ -188950,8 +189005,10 @@ 149.255.15.213 149.255.15.235 149.255.15.27 +149.255.15.29 149.255.15.38 149.255.15.43 +149.255.15.44 149.255.15.87 149.255.15.99 149.255.36.133 @@ -190154,6 +190211,7 @@ 157.90.24.103 157.90.244.110 157.90.244.177 +157.90.8.28 157.97.133.128 157.97.17.46 157.97.2.215 @@ -191386,6 +191444,7 @@ 162.244.81.158 162.244.81.204 162.244.81.55 +162.245.221.121 162.246.15.229 162.246.20.117 162.246.20.236 @@ -203053,6 +203112,7 @@ 178.175.10.224 178.175.10.240 178.175.10.244 +178.175.10.247 178.175.10.248 178.175.10.251 178.175.10.254 @@ -203084,6 +203144,7 @@ 178.175.10.98 178.175.10.99 178.175.100.101 +178.175.100.104 178.175.100.106 178.175.100.109 178.175.100.11 @@ -203234,6 +203295,7 @@ 178.175.101.21 178.175.101.210 178.175.101.211 +178.175.101.212 178.175.101.213 178.175.101.217 178.175.101.219 @@ -203335,6 +203397,7 @@ 178.175.102.179 178.175.102.183 178.175.102.184 +178.175.102.186 178.175.102.188 178.175.102.189 178.175.102.190 @@ -203512,6 +203575,7 @@ 178.175.104.110 178.175.104.112 178.175.104.114 +178.175.104.115 178.175.104.116 178.175.104.12 178.175.104.120 @@ -203858,6 +203922,7 @@ 178.175.107.127 178.175.107.13 178.175.107.133 +178.175.107.135 178.175.107.136 178.175.107.138 178.175.107.140 @@ -204182,6 +204247,7 @@ 178.175.109.96 178.175.109.98 178.175.11.0 +178.175.11.100 178.175.11.101 178.175.11.104 178.175.11.105 @@ -204609,6 +204675,7 @@ 178.175.112.81 178.175.112.85 178.175.112.86 +178.175.112.87 178.175.112.89 178.175.112.90 178.175.112.97 @@ -205641,6 +205708,7 @@ 178.175.121.12 178.175.121.122 178.175.121.123 +178.175.121.125 178.175.121.129 178.175.121.130 178.175.121.133 @@ -206299,6 +206367,7 @@ 178.175.126.38 178.175.126.4 178.175.126.41 +178.175.126.43 178.175.126.44 178.175.126.46 178.175.126.48 @@ -206494,6 +206563,7 @@ 178.175.13.212 178.175.13.213 178.175.13.216 +178.175.13.219 178.175.13.220 178.175.13.221 178.175.13.222 @@ -206597,6 +206667,7 @@ 178.175.14.251 178.175.14.27 178.175.14.28 +178.175.14.29 178.175.14.3 178.175.14.32 178.175.14.33 @@ -206666,6 +206737,7 @@ 178.175.15.190 178.175.15.194 178.175.15.195 +178.175.15.196 178.175.15.197 178.175.15.198 178.175.15.199 @@ -206982,6 +207054,7 @@ 178.175.18.250 178.175.18.253 178.175.18.27 +178.175.18.31 178.175.18.32 178.175.18.36 178.175.18.37 @@ -207165,6 +207238,7 @@ 178.175.2.224 178.175.2.225 178.175.2.226 +178.175.2.23 178.175.2.230 178.175.2.234 178.175.2.236 @@ -207443,6 +207517,7 @@ 178.175.22.187 178.175.22.188 178.175.22.194 +178.175.22.198 178.175.22.203 178.175.22.206 178.175.22.207 @@ -207485,6 +207560,7 @@ 178.175.22.67 178.175.22.69 178.175.22.72 +178.175.22.74 178.175.22.75 178.175.22.78 178.175.22.83 @@ -207720,6 +207796,7 @@ 178.175.25.155 178.175.25.156 178.175.25.159 +178.175.25.162 178.175.25.163 178.175.25.164 178.175.25.166 @@ -207984,6 +208061,7 @@ 178.175.27.25 178.175.27.252 178.175.27.253 +178.175.27.26 178.175.27.30 178.175.27.32 178.175.27.34 @@ -207993,6 +208071,7 @@ 178.175.27.39 178.175.27.4 178.175.27.41 +178.175.27.43 178.175.27.46 178.175.27.47 178.175.27.48 @@ -208406,6 +208485,7 @@ 178.175.30.80 178.175.30.81 178.175.30.86 +178.175.30.90 178.175.30.91 178.175.30.93 178.175.30.96 @@ -208684,6 +208764,7 @@ 178.175.33.228 178.175.33.23 178.175.33.231 +178.175.33.233 178.175.33.234 178.175.33.236 178.175.33.239 @@ -209637,6 +209718,7 @@ 178.175.41.225 178.175.41.229 178.175.41.23 +178.175.41.230 178.175.41.231 178.175.41.235 178.175.41.237 @@ -209994,6 +210076,7 @@ 178.175.44.89 178.175.44.9 178.175.44.90 +178.175.44.93 178.175.44.95 178.175.44.96 178.175.45.10 @@ -210209,6 +210292,7 @@ 178.175.46.54 178.175.46.55 178.175.46.59 +178.175.46.60 178.175.46.61 178.175.46.63 178.175.46.65 @@ -210239,6 +210323,7 @@ 178.175.47.12 178.175.47.122 178.175.47.126 +178.175.47.127 178.175.47.128 178.175.47.132 178.175.47.139 @@ -210369,6 +210454,7 @@ 178.175.48.161 178.175.48.162 178.175.48.163 +178.175.48.164 178.175.48.168 178.175.48.17 178.175.48.172 @@ -210582,6 +210668,7 @@ 178.175.5.22 178.175.5.221 178.175.5.222 +178.175.5.223 178.175.5.226 178.175.5.227 178.175.5.229 @@ -210839,6 +210926,7 @@ 178.175.52.11 178.175.52.111 178.175.52.112 +178.175.52.114 178.175.52.115 178.175.52.118 178.175.52.119 @@ -210898,6 +210986,7 @@ 178.175.52.249 178.175.52.250 178.175.52.252 +178.175.52.255 178.175.52.31 178.175.52.33 178.175.52.34 @@ -211031,6 +211120,7 @@ 178.175.53.83 178.175.53.85 178.175.53.86 +178.175.53.87 178.175.53.9 178.175.53.90 178.175.53.94 @@ -211134,6 +211224,7 @@ 178.175.54.71 178.175.54.72 178.175.54.74 +178.175.54.78 178.175.54.80 178.175.54.81 178.175.54.87 @@ -211154,6 +211245,7 @@ 178.175.55.113 178.175.55.114 178.175.55.117 +178.175.55.118 178.175.55.119 178.175.55.121 178.175.55.125 @@ -211363,6 +211455,7 @@ 178.175.57.102 178.175.57.103 178.175.57.104 +178.175.57.105 178.175.57.108 178.175.57.11 178.175.57.112 @@ -211477,6 +211570,7 @@ 178.175.58.125 178.175.58.126 178.175.58.127 +178.175.58.130 178.175.58.133 178.175.58.139 178.175.58.14 @@ -211499,6 +211593,7 @@ 178.175.58.175 178.175.58.177 178.175.58.178 +178.175.58.18 178.175.58.183 178.175.58.185 178.175.58.188 @@ -211718,6 +211813,8 @@ 178.175.6.196 178.175.6.198 178.175.6.2 +178.175.6.201 +178.175.6.203 178.175.6.204 178.175.6.205 178.175.6.207 @@ -211904,6 +212001,7 @@ 178.175.61.206 178.175.61.209 178.175.61.210 +178.175.61.212 178.175.61.214 178.175.61.217 178.175.61.219 @@ -211971,6 +212069,7 @@ 178.175.62.122 178.175.62.123 178.175.62.128 +178.175.62.130 178.175.62.134 178.175.62.137 178.175.62.141 @@ -212633,6 +212732,7 @@ 178.175.68.161 178.175.68.162 178.175.68.164 +178.175.68.165 178.175.68.166 178.175.68.167 178.175.68.17 @@ -213265,6 +213365,7 @@ 178.175.72.53 178.175.72.54 178.175.72.56 +178.175.72.58 178.175.72.6 178.175.72.61 178.175.72.65 @@ -213661,6 +213762,7 @@ 178.175.76.27 178.175.76.29 178.175.76.33 +178.175.76.34 178.175.76.36 178.175.76.37 178.175.76.43 @@ -213945,6 +214047,7 @@ 178.175.79.244 178.175.79.247 178.175.79.253 +178.175.79.27 178.175.79.30 178.175.79.31 178.175.79.38 @@ -214419,6 +214522,7 @@ 178.175.83.156 178.175.83.158 178.175.83.167 +178.175.83.17 178.175.83.176 178.175.83.18 178.175.83.180 @@ -214687,6 +214791,7 @@ 178.175.85.230 178.175.85.231 178.175.85.234 +178.175.85.235 178.175.85.242 178.175.85.243 178.175.85.244 @@ -215520,6 +215625,7 @@ 178.175.92.208 178.175.92.210 178.175.92.211 +178.175.92.213 178.175.92.214 178.175.92.215 178.175.92.218 @@ -215629,6 +215735,7 @@ 178.175.93.200 178.175.93.202 178.175.93.203 +178.175.93.204 178.175.93.205 178.175.93.207 178.175.93.210 @@ -215915,6 +216022,7 @@ 178.175.95.79 178.175.95.80 178.175.95.82 +178.175.95.83 178.175.95.85 178.175.95.86 178.175.95.88 @@ -218514,6 +218622,7 @@ 180.177.104.65 180.177.180.6 180.177.242.73 +180.177.5.36 180.177.76.161 180.177.80.11 180.178.104.86 @@ -218621,7 +218730,9 @@ 180.188.241.91 180.188.241.99 180.188.247.140 +180.188.247.172 180.188.247.181 +180.188.247.218 180.188.247.26 180.188.252.185 180.188.252.37 @@ -222738,6 +222849,7 @@ 182.113.4.209 182.113.4.223 182.113.4.226 +182.113.4.247 182.113.4.64 182.113.4.68 182.113.4.88 @@ -223708,6 +223820,7 @@ 182.114.193.245 182.114.193.70 182.114.194.116 +182.114.194.183 182.114.194.184 182.114.194.206 182.114.194.210 @@ -235184,6 +235297,7 @@ 182.119.23.62 182.119.23.70 182.119.23.74 +182.119.23.75 182.119.23.9 182.119.23.90 182.119.23.91 @@ -235629,6 +235743,7 @@ 182.119.48.200 182.119.48.205 182.119.48.217 +182.119.48.230 182.119.48.242 182.119.48.250 182.119.48.255 @@ -238500,6 +238615,7 @@ 182.121.123.1 182.121.123.122 182.121.123.124 +182.121.123.134 182.121.123.141 182.121.123.142 182.121.123.16 @@ -239952,6 +240068,7 @@ 182.121.200.115 182.121.200.119 182.121.200.127 +182.121.200.137 182.121.200.143 182.121.200.151 182.121.200.161 @@ -240144,6 +240261,7 @@ 182.121.205.223 182.121.205.228 182.121.205.237 +182.121.205.246 182.121.205.251 182.121.205.39 182.121.205.47 @@ -246639,6 +246757,7 @@ 182.126.109.133 182.126.109.146 182.126.109.150 +182.126.109.194 182.126.109.20 182.126.109.25 182.126.109.255 @@ -247404,6 +247523,7 @@ 182.126.126.150 182.126.126.16 182.126.126.161 +182.126.126.162 182.126.126.170 182.126.126.176 182.126.126.181 @@ -251634,6 +251754,7 @@ 182.127.207.156 182.127.207.158 182.127.207.162 +182.127.207.187 182.127.207.218 182.127.207.226 182.127.207.247 @@ -252690,6 +252811,7 @@ 182.127.80.184 182.127.80.192 182.127.80.229 +182.127.80.240 182.127.80.85 182.127.80.89 182.127.81.114 @@ -253354,6 +253476,7 @@ 182.235.29.89 182.236.124.160 182.239.129.154 +182.240.132.164 182.240.132.203 182.240.213.4 182.240.214.81 @@ -255106,6 +255229,7 @@ 182.57.105.110 182.57.105.161 182.57.105.167 +182.57.105.175 182.57.106.118 182.57.106.190 182.57.106.237 @@ -260593,6 +260717,7 @@ 183.141.54.112 183.141.55.239 183.141.60.120 +183.141.61.174 183.141.61.39 183.142.11.225 183.142.115.155 @@ -261257,6 +261382,7 @@ 183.17.227.102 183.17.227.109 183.17.227.113 +183.17.227.148 183.17.227.162 183.17.227.172 183.17.227.187 @@ -261816,6 +261942,7 @@ 183.49.47.56 183.49.85.243 183.49.85.247 +183.49.86.54 183.49.87.144 183.49.87.220 183.49.87.27 @@ -261904,6 +262031,7 @@ 183.83.103.117 183.83.104.165 183.83.104.44 +183.83.104.55 183.83.104.68 183.83.105.181 183.83.105.21 @@ -262495,6 +262623,7 @@ 185.117.119.71 185.117.155.20 185.117.2.107 +185.117.21.212 185.117.75.111 185.117.75.201 185.117.75.248 @@ -262584,6 +262713,7 @@ 185.132.53.161 185.132.53.166 185.132.53.167 +185.132.53.182 185.132.53.185 185.132.53.186 185.132.53.191 @@ -263778,6 +263908,7 @@ 185.36.59.11 185.36.59.76 185.36.81.43 +185.38.142.194 185.38.142.236 185.39.11.105 185.39.183.48 @@ -265136,6 +265267,7 @@ 186.33.105.7 186.33.105.8 186.33.105.9 +186.33.107.74 186.33.112.100 186.33.112.101 186.33.112.102 @@ -267386,9 +267518,11 @@ 189.170.12.149 189.170.178.180 189.170.40.102 +189.171.22.132 189.171.31.166 189.172.151.237 189.174.35.248 +189.175.214.112 189.176.68.26 189.176.93.82 189.177.144.215 @@ -270021,6 +270155,7 @@ 192.99.169.15 192.99.208.196 192.99.214.32 +192.99.221.230 192.99.240.77 192.99.242.13 192.99.246.11 @@ -273490,6 +273625,7 @@ 202.164.138.156 202.164.138.157 202.164.138.158 +202.164.138.159 202.164.138.160 202.164.138.161 202.164.138.162 @@ -273746,6 +273882,7 @@ 202.164.139.255 202.164.139.26 202.164.139.28 +202.164.139.29 202.164.139.30 202.164.139.31 202.164.139.36 @@ -273764,6 +273901,7 @@ 202.164.139.52 202.164.139.55 202.164.139.56 +202.164.139.57 202.164.139.58 202.164.139.6 202.164.139.60 @@ -277750,6 +277888,7 @@ 206.189.129.96 206.189.131.31 206.189.132.42 +206.189.135.162 206.189.135.253 206.189.138.82 206.189.140.181 @@ -282397,6 +282536,7 @@ 219.154.113.157 219.154.113.161 219.154.113.163 +219.154.113.171 219.154.113.172 219.154.113.177 219.154.113.181 @@ -284758,6 +284898,7 @@ 219.155.226.188 219.155.226.194 219.155.226.198 +219.155.226.205 219.155.226.225 219.155.226.43 219.155.226.50 @@ -288010,6 +288151,7 @@ 219.157.138.38 219.157.138.63 219.157.139.165 +219.157.14.239 219.157.14.85 219.157.140.190 219.157.140.255 @@ -288472,6 +288614,7 @@ 219.157.178.171 219.157.178.179 219.157.178.192 +219.157.178.196 219.157.178.201 219.157.178.205 219.157.178.21 @@ -290642,6 +290785,7 @@ 219.157.48.44 219.157.48.45 219.157.48.46 +219.157.48.5 219.157.48.51 219.157.48.58 219.157.48.59 @@ -293802,6 +293946,7 @@ 221.14.47.162 221.14.47.182 221.14.47.189 +221.14.47.204 221.14.47.225 221.14.47.46 221.14.47.77 @@ -295218,6 +295363,7 @@ 221.15.182.29 221.15.182.40 221.15.182.48 +221.15.182.72 221.15.182.9 221.15.182.94 221.15.183.104 @@ -296761,6 +296907,7 @@ 221.15.53.25 221.15.53.42 221.15.53.46 +221.15.53.55 221.15.53.57 221.15.53.62 221.15.53.74 @@ -307383,6 +307530,7 @@ 222.140.163.15 222.140.163.159 222.140.163.179 +222.140.163.181 222.140.163.184 222.140.163.188 222.140.163.208 @@ -312527,6 +312675,7 @@ 23.95.116.135 23.95.116.144 23.95.122.24 +23.95.122.25 23.95.122.47 23.95.13.131 23.95.13.158 @@ -322752,6 +322901,7 @@ 27.40.71.3 27.40.72.200 27.40.73.175 +27.40.79.170 27.40.79.70 27.40.82.129 27.40.82.201 @@ -347111,6 +347261,7 @@ 31.168.126.45 31.168.146.199 31.168.153.60 +31.168.16.68 31.168.177.37 31.168.178.71 31.168.179.83 @@ -356073,6 +356224,7 @@ 41.143.247.190 41.143.31.149 41.143.57.149 +41.143.69.12 41.144.143.214 41.144.159.85 41.146.243.74 @@ -358334,6 +358486,7 @@ 42.224.171.138 42.224.171.162 42.224.171.163 +42.224.171.165 42.224.171.168 42.224.171.193 42.224.171.196 @@ -360119,6 +360272,7 @@ 42.224.254.199 42.224.254.205 42.224.254.207 +42.224.254.220 42.224.254.224 42.224.254.226 42.224.254.228 @@ -360645,6 +360799,7 @@ 42.224.4.0 42.224.4.1 42.224.4.100 +42.224.4.110 42.224.4.112 42.224.4.12 42.224.4.120 @@ -364813,6 +364968,7 @@ 42.227.222.143 42.227.222.158 42.227.222.174 +42.227.222.189 42.227.222.229 42.227.222.244 42.227.222.43 @@ -364848,6 +365004,7 @@ 42.227.225.154 42.227.225.181 42.227.225.209 +42.227.225.253 42.227.225.45 42.227.225.49 42.227.225.81 @@ -368718,6 +368875,7 @@ 42.230.142.79 42.230.142.82 42.230.143.130 +42.230.143.162 42.230.143.17 42.230.143.174 42.230.143.176 @@ -373091,6 +373249,7 @@ 42.232.169.202 42.232.169.203 42.232.169.209 +42.232.169.211 42.232.169.219 42.232.169.22 42.232.169.223 @@ -374796,6 +374955,7 @@ 42.233.96.52 42.233.96.71 42.233.97.10 +42.233.97.141 42.233.97.149 42.233.97.157 42.233.97.160 @@ -379435,6 +379595,7 @@ 42.235.84.52 42.235.84.54 42.235.84.73 +42.235.84.85 42.235.84.87 42.235.84.88 42.235.84.97 @@ -380646,6 +380807,7 @@ 42.237.114.252 42.237.114.48 42.237.114.50 +42.237.114.80 42.237.114.87 42.237.115.169 42.237.115.175 @@ -384530,6 +384692,7 @@ 45.15.143.158 45.15.143.170 45.15.143.175 +45.15.143.191 45.15.143.253 45.15.25.65 45.15.253.88 @@ -385724,6 +385887,7 @@ 45.229.54.198 45.229.54.199 45.229.54.200 +45.229.54.201 45.229.54.202 45.229.54.203 45.229.54.204 @@ -385825,6 +385989,7 @@ 45.229.55.71 45.229.55.75 45.229.55.79 +45.229.55.80 45.229.55.83 45.229.55.85 45.229.55.98 @@ -386508,6 +386673,7 @@ 45.77.78.41 45.77.79.163 45.77.88.79 +45.77.9.151 45.77.97.236 45.77.98.62 45.78.21.150 @@ -393067,6 +393233,7 @@ 58.249.75.128 58.249.75.13 58.249.75.14 +58.249.75.146 58.249.75.158 58.249.75.159 58.249.75.169 @@ -393128,6 +393295,7 @@ 58.249.77.105 58.249.77.119 58.249.77.12 +58.249.77.141 58.249.77.142 58.249.77.144 58.249.77.147 @@ -393465,6 +393633,7 @@ 58.249.86.20 58.249.86.202 58.249.86.203 +58.249.86.214 58.249.86.227 58.249.86.242 58.249.86.31 @@ -394513,6 +394682,7 @@ 59.126.128.92 59.126.13.182 59.126.132.4 +59.126.132.42 59.126.136.62 59.126.139.144 59.126.148.122 @@ -398537,6 +398707,7 @@ 59.5.192.126 59.5.204.218 59.5.230.140 +59.50.23.23 59.50.28.100 59.51.10.111 59.51.10.55 @@ -400834,6 +401005,7 @@ 59.92.217.210 59.92.217.211 59.92.217.214 +59.92.217.215 59.92.217.217 59.92.217.218 59.92.217.219 @@ -402003,6 +402175,7 @@ 59.93.21.137 59.93.21.138 59.93.21.14 +59.93.21.140 59.93.21.141 59.93.21.146 59.93.21.147 @@ -403285,6 +403458,7 @@ 59.94.182.208 59.94.182.21 59.94.182.210 +59.94.182.212 59.94.182.216 59.94.182.217 59.94.182.22 @@ -404176,6 +404350,7 @@ 59.95.175.46 59.95.175.47 59.95.175.48 +59.95.175.49 59.95.175.5 59.95.175.50 59.95.175.51 @@ -412039,6 +412214,7 @@ 60.211.80.189 60.211.80.208 60.211.80.213 +60.211.80.216 60.211.80.5 60.211.80.9 60.211.81.125 @@ -412694,6 +412870,7 @@ 60.214.52.40 60.214.52.50 60.214.52.96 +60.214.53.159 60.214.53.170 60.214.53.183 60.214.53.242 @@ -422202,6 +422379,7 @@ 60.254.88.6 60.254.88.91 60.254.89.110 +60.254.89.158 60.254.89.160 60.254.89.191 60.254.89.195 @@ -425280,6 +425458,7 @@ 61.3.149.196 61.3.149.197 61.3.149.216 +61.3.149.244 61.3.149.253 61.3.149.26 61.3.149.3 @@ -425294,6 +425473,7 @@ 61.3.149.86 61.3.149.89 61.3.150.0 +61.3.150.101 61.3.150.104 61.3.150.121 61.3.150.140 @@ -425335,9 +425515,11 @@ 61.3.151.90 61.3.152.205 61.3.152.26 +61.3.153.224 61.3.154.201 61.3.154.21 61.3.156.130 +61.3.156.17 61.3.18.2 61.3.18.216 61.3.23.66 @@ -426301,6 +426483,7 @@ 61.52.186.181 61.52.186.184 61.52.186.185 +61.52.186.186 61.52.186.192 61.52.186.195 61.52.186.207 @@ -429240,6 +429423,7 @@ 61.52.97.57 61.52.97.61 61.52.97.64 +61.52.97.68 61.52.97.69 61.52.97.72 61.52.97.74 @@ -434191,7 +434375,6 @@ 65.99.158.218 65.99.176.17 650x.com -654tyfcdr4654fytfy.top 65k2.com 66-gifts.com 66.103.9.249 @@ -434952,7 +435135,6 @@ 6gue98ddw4220152.freebackup.site 6hffgq.dm.files.1drv.com 6hu.xyz -6ip.us 6iptv.com 6itokam.com 6kd743o1w.com @@ -437362,6 +437544,7 @@ 80.92.189.5 80.92.189.70 80.92.204.14 +80.92.204.57 80.93.182.219 80.99.128.61 80001.me @@ -438568,6 +438751,7 @@ 85.245.162.144 85.247.247.175 85.25.213.151 +85.250.147.134 85.250.36.135 85.255.1.93 85.26.250.86 @@ -438745,6 +438929,7 @@ 86.7.86.4 86.82.137.79 86.91.10.91 +86.98.23.78 860259.com 8650hwvaapy.realbrjuridico.email 866appliance.com @@ -438862,6 +439047,7 @@ 87.248.61.60 87.249.204.194 87.251.235.167 +87.251.71.78 87.251.82.211 87.253.0.196 87.253.1.206 @@ -439437,6 +439623,7 @@ 89.148.233.85 89.148.234.101 89.148.234.165 +89.148.234.217 89.148.234.37 89.148.235.94 89.148.237.100 @@ -440867,6 +441054,7 @@ 93.157.62.102 93.157.62.171 93.157.62.58 +93.157.63.221 93.157.63.244 93.159.141.165 93.159.141.166 @@ -442475,7 +442663,6 @@ a.deadnig.ga a.doko.moe a.gg.fm a.heritageandterre.com -a.pomf.cat a.pomf.se a.pomf.space a.pomf.su @@ -447190,7 +447377,6 @@ anmingsi.com anmocnhien.vn anmolanwar.com ann141.net -anna.websaiting.ru annaaluminium.annagroup.net annabelle-hamande.be annabphotography.co.uk @@ -447705,6 +447891,7 @@ app.bigplan-alex.com app.boxrcdn.com app.bridgeimpex.org app.calag.at +app.casetabs.com app.catholicchurch.co.in app.choiphui.com app.cloudindustry.net @@ -449611,6 +449798,7 @@ atpcsm.be atphitech.com atpn.ir atprofessional.org +atpscan.global.hornetsecurity.com atr.it atradex.com atragon.co.uk @@ -450371,6 +450559,8 @@ awswx.xyz awsxb.xyz awsyscloud.com awtinfostore.co.business +awumad01.top +awuqze02.top ax-yogado.com axalize.vn axalta.grupojenrab.mx @@ -451768,6 +451958,7 @@ bbfjjf8.com bbfr.cba.pl bbgiardinodoriente.it bbgk.de +bbgroup.com.vn bbh-design.de bbhdata.com bbhs.org.ng @@ -452207,7 +452398,6 @@ bekurov.org bel-med-tour.ru belabargelro.com belair.btwstudio.ch -belairinternet.com belamater.com.br belangel.by belanja-berkah.xyz @@ -452326,7 +452516,6 @@ belyi.ug belz-development.de belznerdesign.de bem.fkep.unpad.ac.id -bem.hukum.ub.ac.id bem.unimal.ac.id bemagazine.club bemakeup.ru @@ -453099,6 +453288,7 @@ bieres.lavachenoiresud.com bierne-les-villages.fr biese.eu bietthubien.org +bietthudep902.com bietthulambach.com bietthulienkegamuda.net bietthumau.com @@ -456994,7 +457184,6 @@ callonenergy.com callpetercatering.com callrealtyaz.com callshaal.com -callsmaster.com calltoprimus.ru callumstokes.com calm-tech.africa @@ -458254,7 +458443,6 @@ cdncomfortgroup.website cdndownloadlp.club cdnmultimedia.com cdnpic.mgyun.com -cdnrep.reimageplus.com cdnxh.net cdoconsult.com.br cdolechon.com @@ -459046,7 +459234,6 @@ cheekie2.neagoeandrei.com cheematransxpressinc.com cheerchile.cl cheerfulgiversneverlack.com -cheerfullydo.com cheesecakery.com.br cheetahridge.mediadevstaging.com chef-solutions.dreamscape.co.in @@ -459977,6 +460164,7 @@ clarrywillow.top clarte-thailand.com clashofclansgems.nl clasificados.diaadianews.com +clasificadosmaule.com class.britishonline.co class.snph.ir classbrain.net @@ -460274,6 +460462,7 @@ clntnjkstdycloudstcy.dns.army cloakingtds.xyz clock.noixun.com clodflarechk.com +clodura.ai clone.affordable.cm clone.system-standex.dk cloned.in @@ -460459,7 +460648,6 @@ cmeaststar.de cmecobrancas.com cmelik.com cmessagers.com -cmg.asia cmg.ma cmgroup.com.ua cmhighschool.edu.bd @@ -462998,7 +463186,6 @@ cuacuonsieure.com cuadros.pe cuahangphongthuy.net cuahangstore.com -cuahangvattu.com cualtis.com cuanhomxingfanhapkhau.com cuasotinhoc.net @@ -463427,6 +463614,7 @@ d.powerofwish.com d.qiluwl.com d.teamworx.ph d.techmartbd.com +d.top4top.io d.top4top.net d.ttr3p.com d04.data39.helldata.com @@ -465408,6 +465596,7 @@ deportetotal.mx deposayim.ml depositoclara.com.br depot7.com +depozituldegeneratoare.ro depraetere.net deprealty.ru depressionted.com @@ -467134,7 +467323,6 @@ dl-45538429.onedrives-en-live.com dl-675423.store-downloads.com dl-80076342.md-downloads.com dl-97674424.md-downloads.com -dl-gameplayer.dmm.com dl-link.link dl-link.live dl-link.network @@ -467157,9 +467345,9 @@ dl.ikiki.cn dl.imht.ir dl.installcdn-aws.com dl.mqego.com -dl.mydown.com dl.ossdown.fun dl.packetstormsecurity.net +dl.pandasecur.com dl.popupgrade.com dl.repairlabshost.com dl.rina-roleplay.com @@ -467336,6 +467524,9 @@ dobrojutrodjevojke.com dobroviz.com.ua dobrovorot.su dobsoncentral.com +doc-0s-7c-docs.googleusercontent.com +doc-10-0c-docs.googleusercontent.com +doc-10-8s-docs.googleusercontent.com doc-hub.healthycheapfast.com doc-japan.com doc.albaspizzaastoria.com @@ -469610,6 +469801,7 @@ ec2-52-56-233-157.eu-west-2.compute.amazonaws.com ec2-54-207-92-161.sa-east-1.compute.amazonaws.com ec2-54-212-231-68.us-west-2.compute.amazonaws.com ec2-54-94-215-87.sa-east-1.compute.amazonaws.com +ec2euc1.boxcloud.com ec2test.ga ec3-design.com ecadigital.com @@ -471910,6 +472102,7 @@ es.thevoucherstop.com esaarc.com esacbd.com esagarautomobiles.com +esaja09.top esanjobs.org esar.weenets.com esascom.com @@ -477704,7 +477897,6 @@ genregis.com genrjw.dm.files.1drv.com genstaff.gov.kg gentcreativa.com -gentecoyol.com gentesanluis.com gentiane-salers.com gentlechirocenter.com @@ -480453,6 +480645,7 @@ gvou7g.by.files.1drv.com gvpcdpgc.edu.in gvpmacademy.co.za gvsme.com +gw.daelimcloud.com gw.hitlin.com gwangjuhotels.kr gwavellc.com @@ -483264,7 +483457,6 @@ hotelvip-bron.ru hotelwaldblick.com hotexpress.co hotfacts.org -hotgifts.online hotilife.com hotissue.xyz hotkine.com @@ -483642,7 +483834,6 @@ hukouec-ltd.com hukuen-motokare.xyz hukuki.site hukukportal.com -hukum.ub.ac.id hukum.unwiku.ac.id hulianwang114.com huliot.in @@ -483964,6 +484155,7 @@ i-sharecloud.com i-supportcharity.com i-vnsweyu.pl i-voda.com +i.fiery.me i.fluffy.cc i.funtourspt.eu i.n.t.e.rloca.l.qs.j.y@jfas.top @@ -487244,6 +487436,7 @@ itspread.com itspsc.com.ua itspueh.nl itsquare.yrcreations.com +itsrlytry.000webhostapp.com itssprout.com itstelecom.com.br itsweezle.com @@ -487443,6 +487636,7 @@ j-skill.ru j-stage.jp j-toputvoutfitters.com j.kyryl.ru +j.top4top.io j11g9xecuxe43xu.xyz j12z7407gwtzk.xyz j13.biz @@ -487575,6 +487769,7 @@ jaipurjungle.co.in jaipurweddingphotography.com jairathsnatural.ca jairozapata.000webhostapp.com +jaishomo.info jaishritours.com jaiswalsupplement.com jajadomains.com @@ -491603,7 +491798,6 @@ kodiakpro.ca kodim0112sabang.com kodingeko.com kodip.nfile.net -kodjdsjsdjf.tk kodlacan.site kodmuje.com kodolios.000webhostapp.com @@ -494243,6 +494437,7 @@ library.arihantmbainstitute.ac.in library.cifor.org library.dhl-xom.com library.iainbengkulu.ac.id +library.mju.ac.th library.phibi.my.id library.piet.co.in library.strophicmusic.com @@ -494929,7 +495124,6 @@ livechallenge.fr livecigarevent.com livecricketscorecard.info livedaynews.com -livedemo00.template-help.com livedownload.in livedrumtracks.com livefarma.com @@ -494962,7 +495156,6 @@ livesouvenir.com livestreams.vn livesuitesapartdaire.com livesurgerycourse.ir -liveswinburneeduau-my.sharepoint.com liveswindow.casa liveswindow.cyou liveswindows.bar @@ -496137,7 +496330,6 @@ luzbarbosa.com.br luzconsulting.com.br luzevida.com.br luzfloral.com -luzy.vn luzzeri.com lvajnczdy.cf lvcfund.org.vn @@ -499175,7 +499367,6 @@ mecflui.com.br mecgwl.ac.in mechanicaltools.club mechanicsthatcometoyou.com -mecharnise.ir mechathrones.com mechauto.co.za mechdesign.com @@ -499761,7 +499952,6 @@ menxhiqi.com menziesadvisory-my.sharepoint.com menzway.com meogiambeo.com -meohaybotui.com meolamdephay.com mepsgen.com mera.ddns.net @@ -500079,6 +500269,7 @@ mfmr.gov.sl mfomjr.com mfotovideo.ro mfpburundi.bi +mfpc.org.my mfppanel.xyz mfpvision.com mfronza.com.br @@ -505111,7 +505302,6 @@ nhadatphonglinh.com nhadatquan2.xyz nhadatthienthoi.com nhadephungyen.com -nhadepkientruc.net nhahangdaihung.com nhahanghaivuong.vn nhahanglegiang.vn @@ -505325,7 +505515,6 @@ nikanbearing.com nikanpolimer.ir nikastroi.ru nikavkuchyni.sk -nikayu.com nikbox.ru nikeshyadav.com nikhil.webscript.co.in @@ -507841,7 +508030,6 @@ optimusforce.nl option47.us optioncapitalgroup.ru optionrp.com -optionscity.com optisaving.com optitechsa.co.za optocen.ru @@ -508136,7 +508324,6 @@ osethmaayurveda.com osezrayonner.ma osgbforum.com oshattorney.com -oshi.at oshodrycleaning.com oshonafitness.com oshop.es @@ -511836,7 +512023,6 @@ posmaster.co.kr posmicrosystems.com posnxqmp.ru pospeeps.com -posqit.net possessionnow.com possible.re possopagar.com.br @@ -512472,7 +512658,6 @@ prishaartcreations.com prisidmart.com priskat.net prism-photo.com -prisma.fp.ub.ac.id prismaxis.com prismfox.com prismware.ml @@ -513064,6 +513249,7 @@ protech.binarybizz.com protech.mn protechcarpetcare.com protechgroup1.com +protect.mimecast-offshore.com protectiadatelor.biz protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org protection.pecol.eu @@ -513145,6 +513331,7 @@ proxima-solution.com proxy-ipv4.com proxy.2u0apcm6ylhdy7s.com proxy.hueaudio.com +proxy.qualtrics.com proxygrnd.xyz proxyholding.com proxyresume.com @@ -515658,6 +515845,7 @@ redlk.com redlogisticsmaroc.com redloop.io redlotusevents.com +redm1az1.000webhostapp.com redmag.by redmarcial.ossmarcial.com redmediasigns.com @@ -516829,6 +517017,7 @@ rkbicycle.com rkcable.co.in rkfplumbing.co.uk rkinstitute.org +rkkrstdygorgiousejbg.dns.army rkkrstdygorgiousejds.dns.army rkkrstdygorgiousejtw.dns.army rklkpgcollege.com @@ -517385,6 +517574,7 @@ rotiyes.co.id rotoblast.org rotor.olsztyn.pl rotoscoop.com +rotronics.com.ph rott-mtr.de rotterdammeetings.nl rotulosalarcon.com @@ -517798,7 +517988,6 @@ runmagazine.es runmureed.com runmyweb.com runnected.kaiman.fr -runnerbd.com runnerschool.com running-bike.com runningcrewteam.com @@ -519321,6 +519510,7 @@ savemodificationgloballyfromthepinaltypo.duckdns.org savemyfile.3utilities.com savemyseatnow.com saveraahealthcare.com +saveserpnow.com saveserpresults.com savestudio.com savetax.idfcmf.com @@ -519998,6 +520188,7 @@ secure-net.tech secure-risk.namaskara.me secure-snupa.com secure.accounts.resourses.com +secure.activedirect.xyz secure.anchorssb.co secure.app-amazon.com.recovery-account.amazon.com.alphatravelmongolia.com secure.bodybuilderabs.net @@ -520675,7 +520866,6 @@ service.atlink.ir service.dawat.fr service.drnjithendran.com service.eftformotherissues.com -service.ezsoftwareupdater.com service.heritageimagingcenter.com service.hybridhomesteam.com service.idealfurnitureoutlet.com @@ -521180,6 +521370,7 @@ shareallfilesthroughsecureexchangesystem.duckdns.org sharebook.tk sharechautari.com shared-cnd.com +shared.outlook.inky.com shareddocuments.ml shareddynamics.com sharedeconomy.eu @@ -525546,9 +525737,11 @@ stdymjventsluzcafoik.dns.army stdymjventsluzcafsrp.dns.army stdymorcmmylntwincdq.dns.army stdymorcmmylntwinstr.dns.army +stdynbnbnewagedevixz.dns.army stdynbnbnewagedevsmn.dns.army stdynbnbnewagedevxaz.dns.army stdyneverwalkachinese2loneinlifekstgqm.ydns.eu +stdynmxwllminoragest.dns.army stdyperezluzcafeyzst.dns.navy stdypmrimelimtwstogy.dns.army stdypycsslwinnerscot.dns.army @@ -525579,6 +525772,7 @@ stdytoprehtwoyertwfd.dns.army stdytopreoneenversrw.dns.army stdytopreoneenvervaj.dns.army stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu +stdyunitedkesokokgst.dns.army stdyunitedkesokostdr.dns.army stdyunitedkesokostri.dns.navy stdyunitedkesokostxc.dns.army @@ -525588,7 +525782,9 @@ stdyworkfineanotherrainbowlomoyentstbmd.duckdns.org stdyworkfineanotherrainbowlomoyentwkgls.duckdns.org stdyworkfinesanotherrainbowlomoyentstfcp.ydns.eu stdyworkfinesanotherrainbowlomoyentstgot.ydns.eu +stdyworkfinetraingst.dns.army stdyzgchgcloudgostgt.dns.army +stdyzgchgcloudgostxs.dns.army steadyrestmanufacturers.com steak.wpress.dk steakhouse.com.ua @@ -526148,6 +526344,7 @@ strend.net strengthandvigour.com strengthrer.com strenover.ga +stressing.pw stressnada.com stretchpilates.fit strewn.org @@ -526839,6 +527036,7 @@ supercrystal.am supercutscissors.com superdad.id superdigitalguy.xyz +superdomain1709.info superdot.rs superecruiters.com superfacil.center @@ -526942,7 +527140,6 @@ support.m2mservices.com support.mdsol.com support.nordenrecycling.com support.nuvemit.com -support.pubg.com support.redbook.aero support.revolus.xyz support.servu.co.uk @@ -527287,7 +527484,6 @@ swiat-ksiegowosci.pl swicoservers.co.uk swieradowbiega.pl swifck.xmr.ac -swift-cloud.com swiftbusinesspay.com swiftee.co.uk swiftender.com @@ -528132,7 +528328,6 @@ tarexfinal.trade targas.de targat-china.com target-events.com -target-support.online target2cloud.com targetbizbd.com targetcm.net @@ -529713,7 +529908,6 @@ thacci.com.br thachastew.com thachvietstone.com thadathilfarmresort.com -thaddeusarmstrong.com thadinnoo.co thagreymatter.com thai-chana.asia @@ -531435,7 +531629,6 @@ tlcc.com.gt tlcid.org tlckids-or.ga tlcmoto.com -tldrbox.top tldrnet.top tlextreme.com tlfthelifefactory.com.au @@ -533032,6 +533225,7 @@ ts-deals.me ts.7rb.xyz ts0ev73.com tsal.com +tsapparel.com.my tsareva-garden.ru tsatsi.co.za tsauctions.com @@ -533259,6 +533453,7 @@ tunnelpros.com tunnelview.co.uk tunuvo.com tuobrasocial.com.ar +tuoitrethainguyen.vn tupibaje.com tupperware.michaelroberge.ca tur.000webhostapp.com @@ -534405,7 +534600,6 @@ unlimit517.co.jp unlimited.nu unlimitedbags.club unlimitedfreightco.com -unlimitedimportandexport.com unlock-king.com unlock2.neagoeandrei.com unlockall.neagoeandrei.com @@ -534731,6 +534925,7 @@ url-update.com url-validation-clients.com url.246546.com url.57569.fr.snd52.ch +url2.mailanyone.net url3.mailanyone.net url5459.41southbar.com url675.textilmallorca.com @@ -534934,7 +535129,6 @@ utterstock.in utting.org utv.sakeronline.se utv1.enliden.net -uujian.cn uumove.com uurty87e8rt7rt.com uutiset.helppokoti.fi @@ -536908,7 +537102,6 @@ voin.staysafe.pk voingani.it voip96.ru voipminic.com -vokasi.ub.ac.id vokzalrf.ru vol.agency vol2.pw @@ -537536,7 +537729,6 @@ washnworks.com washuis.nl wasidora.com wasilewski-online.de -wasimjee.com wasino.co.th wasobd.net waspha.com @@ -539076,7 +539268,6 @@ woaldi2.com woatinkwoo.com woclawoffers.fun wocomm.marketingmindz.com -wodfitapparel.fr wodmetaldom.pl wodsuit.com woelf.in @@ -541705,7 +541896,9 @@ yoyoplease.com yoyoso.nz yoyoteacher.cn yp.dcyazilim.com +yp.hnggzyjy.cn ypbb.or.id +ypddf.org ypicsdy.cf ypko-55.gq ypom.com.br @@ -541864,7 +542057,6 @@ yusukelife.com yuti.kr yuvann.com yuvikadvertisments.com -yuwaraja.vokasi.ub.ac.id yuweis.com yuxigon.com yuxuanknit.com diff --git a/urlhaus-filter-hosts-online.txt b/urlhaus-filter-hosts-online.txt index 8f52060d..62c8ddc9 100644 --- a/urlhaus-filter-hosts-online.txt +++ b/urlhaus-filter-hosts-online.txt @@ -1,5 +1,5 @@ # Title: Online Malicious Hosts Blocklist -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -33,7 +33,6 @@ 0.0.0.0 adithimedia.com 0.0.0.0 adithimedia.memengers.com 0.0.0.0 admin.erapor.smk-alasror.net -0.0.0.0 admin.gentbcn.org 0.0.0.0 admin.grandoceanvilla.com 0.0.0.0 admission.kmctartskuttippuram.org 0.0.0.0 adventureexplorer.in @@ -49,6 +48,7 @@ 0.0.0.0 aiqtest.com 0.0.0.0 ajpharmaholding.com 0.0.0.0 akdvidyalaya.com +0.0.0.0 al-wahd.com 0.0.0.0 alasdemariposas.org 0.0.0.0 alberts.diamondrelationscrm.us 0.0.0.0 alemelektronik.com @@ -86,7 +86,6 @@ 0.0.0.0 artedibujoyarquitectura.com 0.0.0.0 arwenyapi.com 0.0.0.0 ask-regard.call-save.biz -0.0.0.0 asucssa.live 0.0.0.0 atfile.com 0.0.0.0 athenacapsg.com 0.0.0.0 atlasconcreteworks.com @@ -98,15 +97,17 @@ 0.0.0.0 automaticrefreshments.com 0.0.0.0 avadhanagames.com 0.0.0.0 aventuramotorhome.com +0.0.0.0 awumad01.top +0.0.0.0 awuqze02.top 0.0.0.0 ayahuascasp.com.br 0.0.0.0 ayamallah.com -0.0.0.0 aycconsultoriaempresarial.com 0.0.0.0 azmeasurement.com 0.0.0.0 azraktours.com 0.0.0.0 b.r.uce.lee.b.es.t@zytrox.tk 0.0.0.0 b2b.toptanakaryakit.com.tr 0.0.0.0 backgrounds.pk 0.0.0.0 badeggdesign.com +0.0.0.0 bakamla.go.id 0.0.0.0 balealgodon.mx 0.0.0.0 bangkok-orchids.com 0.0.0.0 bangladeshunbound.com @@ -127,7 +128,6 @@ 0.0.0.0 bespokeweddings.ie 0.0.0.0 bestcarenepal.com 0.0.0.0 betone.co.kr -0.0.0.0 betycopaints.com 0.0.0.0 beveragesmiami.solucioneslink.com 0.0.0.0 bhavaniengineering.com 0.0.0.0 bigmikesupplies.co.za @@ -183,12 +183,12 @@ 0.0.0.0 capitalgroup-kw.com 0.0.0.0 capoeiraventrelivre.com 0.0.0.0 cashyinvestment.org +0.0.0.0 casiomaneflirt.cf 0.0.0.0 catchpoolshetlands.co.uk 0.0.0.0 cazyacustomfurniture.com 0.0.0.0 cbn.hypervoizd.com 0.0.0.0 ccauthority.net 0.0.0.0 cdaonline.com.ar -0.0.0.0 cdn-10049480.file.myqcloud.com 0.0.0.0 cec.asso.ac-amiens.fr 0.0.0.0 cellas.sk 0.0.0.0 cendekiabinaaksara.com @@ -202,17 +202,17 @@ 0.0.0.0 chinhdropfile80.myvnc.com 0.0.0.0 cible-energy.com 0.0.0.0 cifeer.net +0.0.0.0 citiconstructioncorp.com 0.0.0.0 citihits.lk 0.0.0.0 citssolutions.co.za -0.0.0.0 citycapproperty.ru 0.0.0.0 cityglobalgospel.com 0.0.0.0 civi.istmejia.com 0.0.0.0 cleanbydesignllc.com 0.0.0.0 cloud.fc.co.mz 0.0.0.0 cnc.tacobelllover.tk 0.0.0.0 codsambal.com -0.0.0.0 colinde.pricesne.com 0.0.0.0 colorpak.pl +0.0.0.0 columbia.aula-web.net 0.0.0.0 community.reimclub.com 0.0.0.0 competancy.indigoconsult.net 0.0.0.0 conceptimagine.ro @@ -222,9 +222,11 @@ 0.0.0.0 consulateins.solucioneslink.com 0.0.0.0 contributeindustry.com 0.0.0.0 copelandscapes.com +0.0.0.0 corwin-tommie06f.ru.com 0.0.0.0 coulsongraphics.com 0.0.0.0 count.mail.163.com.impactmedfoundation.com 0.0.0.0 covid19.cyberschool.or.id +0.0.0.0 covid19vaccinations.hopto.org 0.0.0.0 cr-sq.com 0.0.0.0 craftech.nxtnet.ga 0.0.0.0 crearechile.cl @@ -287,6 +289,7 @@ 0.0.0.0 dl.198424.com 0.0.0.0 dl.installcdn-aws.com 0.0.0.0 dl.packetstormsecurity.net +0.0.0.0 dl.pandasecur.com 0.0.0.0 dl.rina-roleplay.com 0.0.0.0 dnn.alibuf.com 0.0.0.0 dns.alibuf.com @@ -343,11 +346,11 @@ 0.0.0.0 ennovate.elin.co.za 0.0.0.0 equimination.ee 0.0.0.0 erp.nanotechproautocare.com +0.0.0.0 esaja09.top 0.0.0.0 escola.probommar.org.br 0.0.0.0 eservices.immigration.gov.lk 0.0.0.0 esnconsultants.com 0.0.0.0 essentia.org.br -0.0.0.0 ethereality.info 0.0.0.0 eubanks7.com 0.0.0.0 europeanzonexxi.com 0.0.0.0 exilum.com @@ -365,7 +368,7 @@ 0.0.0.0 fisconline.bar 0.0.0.0 fisconline.casa 0.0.0.0 fix-america-now.org -0.0.0.0 fixauto.illumetechnology.com +0.0.0.0 fkd.derpcity.ru 0.0.0.0 flexypay.dsquaregroup.com 0.0.0.0 flintspin.com 0.0.0.0 flyingbuddhadesign.com @@ -386,7 +389,6 @@ 0.0.0.0 futbolpr.com 0.0.0.0 futuregraphics.com.ar 0.0.0.0 g.pinmonkey.xyz -0.0.0.0 gaditastour.com 0.0.0.0 gametwogame.com 0.0.0.0 garciadogshow.com 0.0.0.0 garenanow.myvnc.com @@ -416,7 +418,6 @@ 0.0.0.0 goldmen.in 0.0.0.0 gpotecnosystems.com 0.0.0.0 gracejukes.com -0.0.0.0 greataccesstoserver.com 0.0.0.0 grupoinmare.com 0.0.0.0 gruposelt.000webhostapp.com 0.0.0.0 gs.monerorx.com @@ -447,17 +448,13 @@ 0.0.0.0 hmpmall.co.kr 0.0.0.0 hoagietesting10.com 0.0.0.0 hoayeuthuong-my.sharepoint.com -0.0.0.0 holmesservices.mobiledevsite.co 0.0.0.0 homefindersolutions.com 0.0.0.0 hometownchick.com -0.0.0.0 hongluosi.com 0.0.0.0 hookedupboatclub.com 0.0.0.0 hostingparacolombia.com 0.0.0.0 hostzaa.com -0.0.0.0 houstonshutters.site 0.0.0.0 hr2019.vrcom7.com 0.0.0.0 hseda.com -0.0.0.0 hsmwebapp.com 0.0.0.0 htownbars.com 0.0.0.0 hubtech.co.za 0.0.0.0 huellacero.cl @@ -505,6 +502,8 @@ 0.0.0.0 it123.ru 0.0.0.0 italiandirezione.casa 0.0.0.0 itc-demo.softgig.co.ke +0.0.0.0 itsrlytry.000webhostapp.com +0.0.0.0 jaishomo.info 0.0.0.0 jamiekaylive.com 0.0.0.0 jamshed.pk 0.0.0.0 jansen-heesch.nl @@ -532,11 +531,11 @@ 0.0.0.0 kaptaanchapal.com 0.0.0.0 karer.by 0.0.0.0 katanvetov.co.il +0.0.0.0 katelynn9506a.ru.com 0.0.0.0 kensingtondriving.com 0.0.0.0 ketofitnessexpert.com 0.0.0.0 kevinjewelry.com.co 0.0.0.0 keywatch.yourpageserver.com -0.0.0.0 kihn-delaney30gn.ru.com 0.0.0.0 kingssa.co.za 0.0.0.0 kjcpromo.com 0.0.0.0 kleinendeli.co.za @@ -544,7 +543,6 @@ 0.0.0.0 krisbadminton.com 0.0.0.0 ktb.sch.id 0.0.0.0 kubatoglubaklava.com.tr -0.0.0.0 kullumanalitours.com 0.0.0.0 kumaralok.in 0.0.0.0 kwanfromhongkong.com 0.0.0.0 kz.sldov.ru @@ -601,7 +599,6 @@ 0.0.0.0 maksi.feb.unib.ac.id 0.0.0.0 malaya.tv 0.0.0.0 malwarecoding.github.io -0.0.0.0 managed.oss-cn-beijing.aliyuncs.com 0.0.0.0 managemysalon.in 0.0.0.0 manantialesdelnorte.uy 0.0.0.0 manhtien.net @@ -644,6 +641,7 @@ 0.0.0.0 microblading.mirliandias.com.br 0.0.0.0 microcomm-group.com 0.0.0.0 mikhailmotoringschool.com +0.0.0.0 mills-skyla30ec.com 0.0.0.0 mingguanwms.com 0.0.0.0 minuevavida.org 0.0.0.0 mirror.mypage.sk @@ -660,6 +658,7 @@ 0.0.0.0 moninediy.com 0.0.0.0 moreirawag.ac.ug 0.0.0.0 motorcomunicacion.com +0.0.0.0 moumitas.com 0.0.0.0 msacontabil.com.br 0.0.0.0 mumgee.co.za 0.0.0.0 muzimbiti.xigubo.co.mz @@ -709,6 +708,7 @@ 0.0.0.0 nyeh2o.com.au 0.0.0.0 obseques-conseils.com 0.0.0.0 oecteam.com +0.0.0.0 ohe.ie 0.0.0.0 ohsewgorgeous.co.uk 0.0.0.0 oleholeh.memangbeda.website 0.0.0.0 omaia.org @@ -719,7 +719,6 @@ 0.0.0.0 onedigitalcard.granvizionnecorp.com 0.0.0.0 onedrive.listifyapp.co 0.0.0.0 online.creedglobal.in -0.0.0.0 open.rawntech.com 0.0.0.0 open.warehousesaas.co.uk 0.0.0.0 opolis.io 0.0.0.0 optimus.com.sg @@ -794,6 +793,7 @@ 0.0.0.0 pujashoppe.in 0.0.0.0 punchdialogues.com 0.0.0.0 punjabdevelopersassociation.com.pk +0.0.0.0 pvcprinting.co.uk 0.0.0.0 qadir.tickfa.ir 0.0.0.0 qatarglobalconsulting.com 0.0.0.0 qmsled.com @@ -820,16 +820,15 @@ 0.0.0.0 readymmade.com 0.0.0.0 recyclethesurplus.com 0.0.0.0 redbats.co.in +0.0.0.0 redboxmultimedia.com 0.0.0.0 redchillicrackers.com 0.0.0.0 reifenquick.de -0.0.0.0 relaxindulge.co.nz 0.0.0.0 renehavis.com.ua 0.0.0.0 repatriacioncolombia.com 0.0.0.0 res.uf1.cn 0.0.0.0 reseller.digimitra.in 0.0.0.0 reseller.itechbrasil.com 0.0.0.0 resuco.net -0.0.0.0 revolet-sa.com 0.0.0.0 rezkabum.ru 0.0.0.0 rhema.com.sg 0.0.0.0 richmondminerals.co.zm @@ -844,6 +843,7 @@ 0.0.0.0 ronnietucker.co.uk 0.0.0.0 roomsvc.servegate.kr 0.0.0.0 roshnijewellery.com +0.0.0.0 rotronics.com.ph 0.0.0.0 rsgym.net 0.0.0.0 rubazar.pro 0.0.0.0 rubycityvietnam.com @@ -872,6 +872,7 @@ 0.0.0.0 schoolbustracker.softgig.co.ke 0.0.0.0 sculetus.nl 0.0.0.0 secure-doc-reader.com +0.0.0.0 secure.activedirect.xyz 0.0.0.0 segalsmetals.elin.co.za 0.0.0.0 sellmyphonela.com 0.0.0.0 selltechtoday.com @@ -881,7 +882,9 @@ 0.0.0.0 sericaasia.com 0.0.0.0 servicemhkd.myvnc.com 0.0.0.0 servicemhkd80.myvnc.com +0.0.0.0 serviciovirtual.com.ar 0.0.0.0 sexologistpakistan.net +0.0.0.0 sgb.ac.ke 0.0.0.0 sgessy.com.br 0.0.0.0 shaheentbfoundation.com 0.0.0.0 shahikhana.cstdevs.com @@ -919,7 +922,6 @@ 0.0.0.0 sobethuacademy.com 0.0.0.0 soft.110route.com 0.0.0.0 soft.officelabo.net -0.0.0.0 sogecoenergy.com 0.0.0.0 sohs.conceptechs.info 0.0.0.0 solar.amazingtribe.lk 0.0.0.0 somcorbera.cat @@ -933,7 +935,6 @@ 0.0.0.0 spetsesyachtcharter.gr 0.0.0.0 spititourism.com 0.0.0.0 spittinfire.com -0.0.0.0 springbedspetroleum.com 0.0.0.0 src1.minibai.com 0.0.0.0 sreenivasapaintingworks.com 0.0.0.0 sriglobalit.com @@ -944,16 +945,23 @@ 0.0.0.0 staging.apparelpunch.com 0.0.0.0 starcountry.net 0.0.0.0 static.3001.net +0.0.0.0 stdynbnbnewagedevixz.dns.army +0.0.0.0 stdynmxwllminoragest.dns.army +0.0.0.0 stdyunitedkesokokgst.dns.army +0.0.0.0 stdyworkfinetraingst.dns.army +0.0.0.0 stdyzgchgcloudgostxs.dns.army 0.0.0.0 stiau.iuc.ac 0.0.0.0 sticker.jewsjuice.com 0.0.0.0 stiepancasetia.ac.id 0.0.0.0 stlukesohag.com 0.0.0.0 store.ericalgarin.com 0.0.0.0 stott-thompson.co.uk +0.0.0.0 stratexec.co.za 0.0.0.0 streetdemo.yourpageserver.com 0.0.0.0 suboldesign.com 0.0.0.0 sumerians.org 0.0.0.0 sunaryem.com.tr +0.0.0.0 sunbrero.com.au 0.0.0.0 sunmarkholidays.com 0.0.0.0 support-4-free.com 0.0.0.0 support.clz.kr @@ -1032,7 +1040,6 @@ 0.0.0.0 toplevel.com.br 0.0.0.0 topmask.co.za 0.0.0.0 torresquinterocorp.com -0.0.0.0 towme.services 0.0.0.0 toyotacollege.ac.th 0.0.0.0 tpke.hu 0.0.0.0 translaterjemah.com @@ -1059,7 +1066,6 @@ 0.0.0.0 unyazitelecom.com 0.0.0.0 up.llw0.com 0.0.0.0 upcbpta.com -0.0.0.0 used-jeans.fr 0.0.0.0 useformoney.000webhostapp.com 0.0.0.0 uss.ac.th 0.0.0.0 uzzepay.com.br @@ -1068,7 +1074,6 @@ 0.0.0.0 vcah.co.uk 0.0.0.0 vectarts.com 0.0.0.0 vegadelcasero.cl -0.0.0.0 velma-harber30ku.com 0.0.0.0 vendas.lidiacarmeli.com.br 0.0.0.0 veterinariadrpopui.com 0.0.0.0 vfocus.net @@ -1084,7 +1089,6 @@ 0.0.0.0 viveirodoiscorregos.com.br 0.0.0.0 vksales.com 0.0.0.0 vocalterra.com -0.0.0.0 vokasi.ub.ac.id 0.0.0.0 vologroup.com.br 0.0.0.0 voteyouramerica.dekitout.com 0.0.0.0 vpts.co.za @@ -1105,6 +1109,7 @@ 0.0.0.0 weinsteincounseling.com 0.0.0.0 wfinance.com.br 0.0.0.0 whcms.yourpageserver.com +0.0.0.0 whiteglovetailgate.com 0.0.0.0 whiteresponse.com 0.0.0.0 wi522012.ferozo.com 0.0.0.0 wikalen.co.za @@ -1134,6 +1139,7 @@ 0.0.0.0 yeq.i.u.j.ia.n.3@zytrox.tk 0.0.0.0 ylfpremium.com 0.0.0.0 yoast.yourpageserver.com +0.0.0.0 yp.hnggzyjy.cn 0.0.0.0 yummyyogaudaipur.com 0.0.0.0 yzkzixun.com 0.0.0.0 ziyker4gaming@zytrox.tk diff --git a/urlhaus-filter-hosts.txt b/urlhaus-filter-hosts.txt index cd4a3758..22bd1432 100644 --- a/urlhaus-filter-hosts.txt +++ b/urlhaus-filter-hosts.txt @@ -1,5 +1,5 @@ # Title: Malicious Hosts Blocklist -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -1438,7 +1438,6 @@ 0.0.0.0 649924.nchsoftwarecom.com 0.0.0.0 64x9bg.ch.files.1drv.com 0.0.0.0 650x.com -0.0.0.0 654tyfcdr4654fytfy.top 0.0.0.0 65k2.com 0.0.0.0 66-gifts.com 0.0.0.0 662ekeep6.com @@ -1476,7 +1475,6 @@ 0.0.0.0 6gue98ddw4220152.freebackup.site 0.0.0.0 6hffgq.dm.files.1drv.com 0.0.0.0 6hu.xyz -0.0.0.0 6ip.us 0.0.0.0 6iptv.com 0.0.0.0 6itokam.com 0.0.0.0 6kd743o1w.com @@ -1869,7 +1867,6 @@ 0.0.0.0 a.doko.moe 0.0.0.0 a.gg.fm 0.0.0.0 a.heritageandterre.com -0.0.0.0 a.pomf.cat 0.0.0.0 a.pomf.se 0.0.0.0 a.pomf.space 0.0.0.0 a.pomf.su @@ -6583,7 +6580,6 @@ 0.0.0.0 anmocnhien.vn 0.0.0.0 anmolanwar.com 0.0.0.0 ann141.net -0.0.0.0 anna.websaiting.ru 0.0.0.0 annaaluminium.annagroup.net 0.0.0.0 annabelle-hamande.be 0.0.0.0 annabphotography.co.uk @@ -7098,6 +7094,7 @@ 0.0.0.0 app.boxrcdn.com 0.0.0.0 app.bridgeimpex.org 0.0.0.0 app.calag.at +0.0.0.0 app.casetabs.com 0.0.0.0 app.catholicchurch.co.in 0.0.0.0 app.choiphui.com 0.0.0.0 app.cloudindustry.net @@ -9004,6 +9001,7 @@ 0.0.0.0 atphitech.com 0.0.0.0 atpn.ir 0.0.0.0 atprofessional.org +0.0.0.0 atpscan.global.hornetsecurity.com 0.0.0.0 atr.it 0.0.0.0 atradex.com 0.0.0.0 atragon.co.uk @@ -9764,6 +9762,8 @@ 0.0.0.0 awsxb.xyz 0.0.0.0 awsyscloud.com 0.0.0.0 awtinfostore.co.business +0.0.0.0 awumad01.top +0.0.0.0 awuqze02.top 0.0.0.0 ax-yogado.com 0.0.0.0 axalize.vn 0.0.0.0 axalta.grupojenrab.mx @@ -11161,6 +11161,7 @@ 0.0.0.0 bbfr.cba.pl 0.0.0.0 bbgiardinodoriente.it 0.0.0.0 bbgk.de +0.0.0.0 bbgroup.com.vn 0.0.0.0 bbh-design.de 0.0.0.0 bbhdata.com 0.0.0.0 bbhs.org.ng @@ -11600,7 +11601,6 @@ 0.0.0.0 bel-med-tour.ru 0.0.0.0 belabargelro.com 0.0.0.0 belair.btwstudio.ch -0.0.0.0 belairinternet.com 0.0.0.0 belamater.com.br 0.0.0.0 belangel.by 0.0.0.0 belanja-berkah.xyz @@ -11719,7 +11719,6 @@ 0.0.0.0 belz-development.de 0.0.0.0 belznerdesign.de 0.0.0.0 bem.fkep.unpad.ac.id -0.0.0.0 bem.hukum.ub.ac.id 0.0.0.0 bem.unimal.ac.id 0.0.0.0 bemagazine.club 0.0.0.0 bemakeup.ru @@ -12492,6 +12491,7 @@ 0.0.0.0 bierne-les-villages.fr 0.0.0.0 biese.eu 0.0.0.0 bietthubien.org +0.0.0.0 bietthudep902.com 0.0.0.0 bietthulambach.com 0.0.0.0 bietthulienkegamuda.net 0.0.0.0 bietthumau.com @@ -16387,7 +16387,6 @@ 0.0.0.0 callpetercatering.com 0.0.0.0 callrealtyaz.com 0.0.0.0 callshaal.com -0.0.0.0 callsmaster.com 0.0.0.0 calltoprimus.ru 0.0.0.0 callumstokes.com 0.0.0.0 calm-tech.africa @@ -17647,7 +17646,6 @@ 0.0.0.0 cdndownloadlp.club 0.0.0.0 cdnmultimedia.com 0.0.0.0 cdnpic.mgyun.com -0.0.0.0 cdnrep.reimageplus.com 0.0.0.0 cdnxh.net 0.0.0.0 cdoconsult.com.br 0.0.0.0 cdolechon.com @@ -18439,7 +18437,6 @@ 0.0.0.0 cheematransxpressinc.com 0.0.0.0 cheerchile.cl 0.0.0.0 cheerfulgiversneverlack.com -0.0.0.0 cheerfullydo.com 0.0.0.0 cheesecakery.com.br 0.0.0.0 cheetahridge.mediadevstaging.com 0.0.0.0 chef-solutions.dreamscape.co.in @@ -19370,6 +19367,7 @@ 0.0.0.0 clarte-thailand.com 0.0.0.0 clashofclansgems.nl 0.0.0.0 clasificados.diaadianews.com +0.0.0.0 clasificadosmaule.com 0.0.0.0 class.britishonline.co 0.0.0.0 class.snph.ir 0.0.0.0 classbrain.net @@ -19667,6 +19665,7 @@ 0.0.0.0 cloakingtds.xyz 0.0.0.0 clock.noixun.com 0.0.0.0 clodflarechk.com +0.0.0.0 clodura.ai 0.0.0.0 clone.affordable.cm 0.0.0.0 clone.system-standex.dk 0.0.0.0 cloned.in @@ -19852,7 +19851,6 @@ 0.0.0.0 cmecobrancas.com 0.0.0.0 cmelik.com 0.0.0.0 cmessagers.com -0.0.0.0 cmg.asia 0.0.0.0 cmg.ma 0.0.0.0 cmgroup.com.ua 0.0.0.0 cmhighschool.edu.bd @@ -22391,7 +22389,6 @@ 0.0.0.0 cuadros.pe 0.0.0.0 cuahangphongthuy.net 0.0.0.0 cuahangstore.com -0.0.0.0 cuahangvattu.com 0.0.0.0 cualtis.com 0.0.0.0 cuanhomxingfanhapkhau.com 0.0.0.0 cuasotinhoc.net @@ -22820,6 +22817,7 @@ 0.0.0.0 d.qiluwl.com 0.0.0.0 d.teamworx.ph 0.0.0.0 d.techmartbd.com +0.0.0.0 d.top4top.io 0.0.0.0 d.top4top.net 0.0.0.0 d.ttr3p.com 0.0.0.0 d04.data39.helldata.com @@ -24801,6 +24799,7 @@ 0.0.0.0 deposayim.ml 0.0.0.0 depositoclara.com.br 0.0.0.0 depot7.com +0.0.0.0 depozituldegeneratoare.ro 0.0.0.0 depraetere.net 0.0.0.0 deprealty.ru 0.0.0.0 depressionted.com @@ -26527,7 +26526,6 @@ 0.0.0.0 dl-675423.store-downloads.com 0.0.0.0 dl-80076342.md-downloads.com 0.0.0.0 dl-97674424.md-downloads.com -0.0.0.0 dl-gameplayer.dmm.com 0.0.0.0 dl-link.link 0.0.0.0 dl-link.live 0.0.0.0 dl-link.network @@ -26550,9 +26548,9 @@ 0.0.0.0 dl.imht.ir 0.0.0.0 dl.installcdn-aws.com 0.0.0.0 dl.mqego.com -0.0.0.0 dl.mydown.com 0.0.0.0 dl.ossdown.fun 0.0.0.0 dl.packetstormsecurity.net +0.0.0.0 dl.pandasecur.com 0.0.0.0 dl.popupgrade.com 0.0.0.0 dl.repairlabshost.com 0.0.0.0 dl.rina-roleplay.com @@ -26729,6 +26727,9 @@ 0.0.0.0 dobroviz.com.ua 0.0.0.0 dobrovorot.su 0.0.0.0 dobsoncentral.com +0.0.0.0 doc-0s-7c-docs.googleusercontent.com +0.0.0.0 doc-10-0c-docs.googleusercontent.com +0.0.0.0 doc-10-8s-docs.googleusercontent.com 0.0.0.0 doc-hub.healthycheapfast.com 0.0.0.0 doc-japan.com 0.0.0.0 doc.albaspizzaastoria.com @@ -29003,6 +29004,7 @@ 0.0.0.0 ec2-54-207-92-161.sa-east-1.compute.amazonaws.com 0.0.0.0 ec2-54-212-231-68.us-west-2.compute.amazonaws.com 0.0.0.0 ec2-54-94-215-87.sa-east-1.compute.amazonaws.com +0.0.0.0 ec2euc1.boxcloud.com 0.0.0.0 ec2test.ga 0.0.0.0 ec3-design.com 0.0.0.0 ecadigital.com @@ -31303,6 +31305,7 @@ 0.0.0.0 esaarc.com 0.0.0.0 esacbd.com 0.0.0.0 esagarautomobiles.com +0.0.0.0 esaja09.top 0.0.0.0 esanjobs.org 0.0.0.0 esar.weenets.com 0.0.0.0 esascom.com @@ -37097,7 +37100,6 @@ 0.0.0.0 genrjw.dm.files.1drv.com 0.0.0.0 genstaff.gov.kg 0.0.0.0 gentcreativa.com -0.0.0.0 gentecoyol.com 0.0.0.0 gentesanluis.com 0.0.0.0 gentiane-salers.com 0.0.0.0 gentlechirocenter.com @@ -39846,6 +39848,7 @@ 0.0.0.0 gvpcdpgc.edu.in 0.0.0.0 gvpmacademy.co.za 0.0.0.0 gvsme.com +0.0.0.0 gw.daelimcloud.com 0.0.0.0 gw.hitlin.com 0.0.0.0 gwangjuhotels.kr 0.0.0.0 gwavellc.com @@ -42657,7 +42660,6 @@ 0.0.0.0 hotelwaldblick.com 0.0.0.0 hotexpress.co 0.0.0.0 hotfacts.org -0.0.0.0 hotgifts.online 0.0.0.0 hotilife.com 0.0.0.0 hotissue.xyz 0.0.0.0 hotkine.com @@ -43035,7 +43037,6 @@ 0.0.0.0 hukuen-motokare.xyz 0.0.0.0 hukuki.site 0.0.0.0 hukukportal.com -0.0.0.0 hukum.ub.ac.id 0.0.0.0 hukum.unwiku.ac.id 0.0.0.0 hulianwang114.com 0.0.0.0 huliot.in @@ -43357,6 +43358,7 @@ 0.0.0.0 i-supportcharity.com 0.0.0.0 i-vnsweyu.pl 0.0.0.0 i-voda.com +0.0.0.0 i.fiery.me 0.0.0.0 i.fluffy.cc 0.0.0.0 i.funtourspt.eu 0.0.0.0 i.n.t.e.rloca.l.qs.j.y@jfas.top @@ -46637,6 +46639,7 @@ 0.0.0.0 itspsc.com.ua 0.0.0.0 itspueh.nl 0.0.0.0 itsquare.yrcreations.com +0.0.0.0 itsrlytry.000webhostapp.com 0.0.0.0 itssprout.com 0.0.0.0 itstelecom.com.br 0.0.0.0 itsweezle.com @@ -46836,6 +46839,7 @@ 0.0.0.0 j-stage.jp 0.0.0.0 j-toputvoutfitters.com 0.0.0.0 j.kyryl.ru +0.0.0.0 j.top4top.io 0.0.0.0 j11g9xecuxe43xu.xyz 0.0.0.0 j12z7407gwtzk.xyz 0.0.0.0 j13.biz @@ -46968,6 +46972,7 @@ 0.0.0.0 jaipurweddingphotography.com 0.0.0.0 jairathsnatural.ca 0.0.0.0 jairozapata.000webhostapp.com +0.0.0.0 jaishomo.info 0.0.0.0 jaishritours.com 0.0.0.0 jaiswalsupplement.com 0.0.0.0 jajadomains.com @@ -50996,7 +51001,6 @@ 0.0.0.0 kodim0112sabang.com 0.0.0.0 kodingeko.com 0.0.0.0 kodip.nfile.net -0.0.0.0 kodjdsjsdjf.tk 0.0.0.0 kodlacan.site 0.0.0.0 kodmuje.com 0.0.0.0 kodolios.000webhostapp.com @@ -53636,6 +53640,7 @@ 0.0.0.0 library.cifor.org 0.0.0.0 library.dhl-xom.com 0.0.0.0 library.iainbengkulu.ac.id +0.0.0.0 library.mju.ac.th 0.0.0.0 library.phibi.my.id 0.0.0.0 library.piet.co.in 0.0.0.0 library.strophicmusic.com @@ -54322,7 +54327,6 @@ 0.0.0.0 livecigarevent.com 0.0.0.0 livecricketscorecard.info 0.0.0.0 livedaynews.com -0.0.0.0 livedemo00.template-help.com 0.0.0.0 livedownload.in 0.0.0.0 livedrumtracks.com 0.0.0.0 livefarma.com @@ -54355,7 +54359,6 @@ 0.0.0.0 livestreams.vn 0.0.0.0 livesuitesapartdaire.com 0.0.0.0 livesurgerycourse.ir -0.0.0.0 liveswinburneeduau-my.sharepoint.com 0.0.0.0 liveswindow.casa 0.0.0.0 liveswindow.cyou 0.0.0.0 liveswindows.bar @@ -55530,7 +55533,6 @@ 0.0.0.0 luzconsulting.com.br 0.0.0.0 luzevida.com.br 0.0.0.0 luzfloral.com -0.0.0.0 luzy.vn 0.0.0.0 luzzeri.com 0.0.0.0 lvajnczdy.cf 0.0.0.0 lvcfund.org.vn @@ -58568,7 +58570,6 @@ 0.0.0.0 mecgwl.ac.in 0.0.0.0 mechanicaltools.club 0.0.0.0 mechanicsthatcometoyou.com -0.0.0.0 mecharnise.ir 0.0.0.0 mechathrones.com 0.0.0.0 mechauto.co.za 0.0.0.0 mechdesign.com @@ -59154,7 +59155,6 @@ 0.0.0.0 menziesadvisory-my.sharepoint.com 0.0.0.0 menzway.com 0.0.0.0 meogiambeo.com -0.0.0.0 meohaybotui.com 0.0.0.0 meolamdephay.com 0.0.0.0 mepsgen.com 0.0.0.0 mera.ddns.net @@ -59472,6 +59472,7 @@ 0.0.0.0 mfomjr.com 0.0.0.0 mfotovideo.ro 0.0.0.0 mfpburundi.bi +0.0.0.0 mfpc.org.my 0.0.0.0 mfppanel.xyz 0.0.0.0 mfpvision.com 0.0.0.0 mfronza.com.br @@ -64504,7 +64505,6 @@ 0.0.0.0 nhadatquan2.xyz 0.0.0.0 nhadatthienthoi.com 0.0.0.0 nhadephungyen.com -0.0.0.0 nhadepkientruc.net 0.0.0.0 nhahangdaihung.com 0.0.0.0 nhahanghaivuong.vn 0.0.0.0 nhahanglegiang.vn @@ -64718,7 +64718,6 @@ 0.0.0.0 nikanpolimer.ir 0.0.0.0 nikastroi.ru 0.0.0.0 nikavkuchyni.sk -0.0.0.0 nikayu.com 0.0.0.0 nikbox.ru 0.0.0.0 nikeshyadav.com 0.0.0.0 nikhil.webscript.co.in @@ -67234,7 +67233,6 @@ 0.0.0.0 option47.us 0.0.0.0 optioncapitalgroup.ru 0.0.0.0 optionrp.com -0.0.0.0 optionscity.com 0.0.0.0 optisaving.com 0.0.0.0 optitechsa.co.za 0.0.0.0 optocen.ru @@ -67529,7 +67527,6 @@ 0.0.0.0 osezrayonner.ma 0.0.0.0 osgbforum.com 0.0.0.0 oshattorney.com -0.0.0.0 oshi.at 0.0.0.0 oshodrycleaning.com 0.0.0.0 oshonafitness.com 0.0.0.0 oshop.es @@ -71229,7 +71226,6 @@ 0.0.0.0 posmicrosystems.com 0.0.0.0 posnxqmp.ru 0.0.0.0 pospeeps.com -0.0.0.0 posqit.net 0.0.0.0 possessionnow.com 0.0.0.0 possible.re 0.0.0.0 possopagar.com.br @@ -71865,7 +71861,6 @@ 0.0.0.0 prisidmart.com 0.0.0.0 priskat.net 0.0.0.0 prism-photo.com -0.0.0.0 prisma.fp.ub.ac.id 0.0.0.0 prismaxis.com 0.0.0.0 prismfox.com 0.0.0.0 prismware.ml @@ -72457,6 +72452,7 @@ 0.0.0.0 protech.mn 0.0.0.0 protechcarpetcare.com 0.0.0.0 protechgroup1.com +0.0.0.0 protect.mimecast-offshore.com 0.0.0.0 protectiadatelor.biz 0.0.0.0 protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org 0.0.0.0 protection.pecol.eu @@ -72538,6 +72534,7 @@ 0.0.0.0 proxy-ipv4.com 0.0.0.0 proxy.2u0apcm6ylhdy7s.com 0.0.0.0 proxy.hueaudio.com +0.0.0.0 proxy.qualtrics.com 0.0.0.0 proxygrnd.xyz 0.0.0.0 proxyholding.com 0.0.0.0 proxyresume.com @@ -75051,6 +75048,7 @@ 0.0.0.0 redlogisticsmaroc.com 0.0.0.0 redloop.io 0.0.0.0 redlotusevents.com +0.0.0.0 redm1az1.000webhostapp.com 0.0.0.0 redmag.by 0.0.0.0 redmarcial.ossmarcial.com 0.0.0.0 redmediasigns.com @@ -76222,6 +76220,7 @@ 0.0.0.0 rkcable.co.in 0.0.0.0 rkfplumbing.co.uk 0.0.0.0 rkinstitute.org +0.0.0.0 rkkrstdygorgiousejbg.dns.army 0.0.0.0 rkkrstdygorgiousejds.dns.army 0.0.0.0 rkkrstdygorgiousejtw.dns.army 0.0.0.0 rklkpgcollege.com @@ -76778,6 +76777,7 @@ 0.0.0.0 rotoblast.org 0.0.0.0 rotor.olsztyn.pl 0.0.0.0 rotoscoop.com +0.0.0.0 rotronics.com.ph 0.0.0.0 rott-mtr.de 0.0.0.0 rotterdammeetings.nl 0.0.0.0 rotulosalarcon.com @@ -77191,7 +77191,6 @@ 0.0.0.0 runmureed.com 0.0.0.0 runmyweb.com 0.0.0.0 runnected.kaiman.fr -0.0.0.0 runnerbd.com 0.0.0.0 runnerschool.com 0.0.0.0 running-bike.com 0.0.0.0 runningcrewteam.com @@ -78713,6 +78712,7 @@ 0.0.0.0 savemyfile.3utilities.com 0.0.0.0 savemyseatnow.com 0.0.0.0 saveraahealthcare.com +0.0.0.0 saveserpnow.com 0.0.0.0 saveserpresults.com 0.0.0.0 savestudio.com 0.0.0.0 savetax.idfcmf.com @@ -79390,6 +79390,7 @@ 0.0.0.0 secure-risk.namaskara.me 0.0.0.0 secure-snupa.com 0.0.0.0 secure.accounts.resourses.com +0.0.0.0 secure.activedirect.xyz 0.0.0.0 secure.anchorssb.co 0.0.0.0 secure.app-amazon.com.recovery-account.amazon.com.alphatravelmongolia.com 0.0.0.0 secure.bodybuilderabs.net @@ -80067,7 +80068,6 @@ 0.0.0.0 service.dawat.fr 0.0.0.0 service.drnjithendran.com 0.0.0.0 service.eftformotherissues.com -0.0.0.0 service.ezsoftwareupdater.com 0.0.0.0 service.heritageimagingcenter.com 0.0.0.0 service.hybridhomesteam.com 0.0.0.0 service.idealfurnitureoutlet.com @@ -80572,6 +80572,7 @@ 0.0.0.0 sharebook.tk 0.0.0.0 sharechautari.com 0.0.0.0 shared-cnd.com +0.0.0.0 shared.outlook.inky.com 0.0.0.0 shareddocuments.ml 0.0.0.0 shareddynamics.com 0.0.0.0 sharedeconomy.eu @@ -84935,9 +84936,11 @@ 0.0.0.0 stdymjventsluzcafsrp.dns.army 0.0.0.0 stdymorcmmylntwincdq.dns.army 0.0.0.0 stdymorcmmylntwinstr.dns.army +0.0.0.0 stdynbnbnewagedevixz.dns.army 0.0.0.0 stdynbnbnewagedevsmn.dns.army 0.0.0.0 stdynbnbnewagedevxaz.dns.army 0.0.0.0 stdyneverwalkachinese2loneinlifekstgqm.ydns.eu +0.0.0.0 stdynmxwllminoragest.dns.army 0.0.0.0 stdyperezluzcafeyzst.dns.navy 0.0.0.0 stdypmrimelimtwstogy.dns.army 0.0.0.0 stdypycsslwinnerscot.dns.army @@ -84968,6 +84971,7 @@ 0.0.0.0 stdytopreoneenversrw.dns.army 0.0.0.0 stdytopreoneenvervaj.dns.army 0.0.0.0 stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu +0.0.0.0 stdyunitedkesokokgst.dns.army 0.0.0.0 stdyunitedkesokostdr.dns.army 0.0.0.0 stdyunitedkesokostri.dns.navy 0.0.0.0 stdyunitedkesokostxc.dns.army @@ -84977,7 +84981,9 @@ 0.0.0.0 stdyworkfineanotherrainbowlomoyentwkgls.duckdns.org 0.0.0.0 stdyworkfinesanotherrainbowlomoyentstfcp.ydns.eu 0.0.0.0 stdyworkfinesanotherrainbowlomoyentstgot.ydns.eu +0.0.0.0 stdyworkfinetraingst.dns.army 0.0.0.0 stdyzgchgcloudgostgt.dns.army +0.0.0.0 stdyzgchgcloudgostxs.dns.army 0.0.0.0 steadyrestmanufacturers.com 0.0.0.0 steak.wpress.dk 0.0.0.0 steakhouse.com.ua @@ -85537,6 +85543,7 @@ 0.0.0.0 strengthandvigour.com 0.0.0.0 strengthrer.com 0.0.0.0 strenover.ga +0.0.0.0 stressing.pw 0.0.0.0 stressnada.com 0.0.0.0 stretchpilates.fit 0.0.0.0 strewn.org @@ -86228,6 +86235,7 @@ 0.0.0.0 supercutscissors.com 0.0.0.0 superdad.id 0.0.0.0 superdigitalguy.xyz +0.0.0.0 superdomain1709.info 0.0.0.0 superdot.rs 0.0.0.0 superecruiters.com 0.0.0.0 superfacil.center @@ -86331,7 +86339,6 @@ 0.0.0.0 support.mdsol.com 0.0.0.0 support.nordenrecycling.com 0.0.0.0 support.nuvemit.com -0.0.0.0 support.pubg.com 0.0.0.0 support.redbook.aero 0.0.0.0 support.revolus.xyz 0.0.0.0 support.servu.co.uk @@ -86676,7 +86683,6 @@ 0.0.0.0 swicoservers.co.uk 0.0.0.0 swieradowbiega.pl 0.0.0.0 swifck.xmr.ac -0.0.0.0 swift-cloud.com 0.0.0.0 swiftbusinesspay.com 0.0.0.0 swiftee.co.uk 0.0.0.0 swiftender.com @@ -87521,7 +87527,6 @@ 0.0.0.0 targas.de 0.0.0.0 targat-china.com 0.0.0.0 target-events.com -0.0.0.0 target-support.online 0.0.0.0 target2cloud.com 0.0.0.0 targetbizbd.com 0.0.0.0 targetcm.net @@ -89102,7 +89107,6 @@ 0.0.0.0 thachastew.com 0.0.0.0 thachvietstone.com 0.0.0.0 thadathilfarmresort.com -0.0.0.0 thaddeusarmstrong.com 0.0.0.0 thadinnoo.co 0.0.0.0 thagreymatter.com 0.0.0.0 thai-chana.asia @@ -90824,7 +90828,6 @@ 0.0.0.0 tlcid.org 0.0.0.0 tlckids-or.ga 0.0.0.0 tlcmoto.com -0.0.0.0 tldrbox.top 0.0.0.0 tldrnet.top 0.0.0.0 tlextreme.com 0.0.0.0 tlfthelifefactory.com.au @@ -92421,6 +92424,7 @@ 0.0.0.0 ts.7rb.xyz 0.0.0.0 ts0ev73.com 0.0.0.0 tsal.com +0.0.0.0 tsapparel.com.my 0.0.0.0 tsareva-garden.ru 0.0.0.0 tsatsi.co.za 0.0.0.0 tsauctions.com @@ -92648,6 +92652,7 @@ 0.0.0.0 tunnelview.co.uk 0.0.0.0 tunuvo.com 0.0.0.0 tuobrasocial.com.ar +0.0.0.0 tuoitrethainguyen.vn 0.0.0.0 tupibaje.com 0.0.0.0 tupperware.michaelroberge.ca 0.0.0.0 tur.000webhostapp.com @@ -93794,7 +93799,6 @@ 0.0.0.0 unlimited.nu 0.0.0.0 unlimitedbags.club 0.0.0.0 unlimitedfreightco.com -0.0.0.0 unlimitedimportandexport.com 0.0.0.0 unlock-king.com 0.0.0.0 unlock2.neagoeandrei.com 0.0.0.0 unlockall.neagoeandrei.com @@ -94120,6 +94124,7 @@ 0.0.0.0 url-validation-clients.com 0.0.0.0 url.246546.com 0.0.0.0 url.57569.fr.snd52.ch +0.0.0.0 url2.mailanyone.net 0.0.0.0 url3.mailanyone.net 0.0.0.0 url5459.41southbar.com 0.0.0.0 url675.textilmallorca.com @@ -94323,7 +94328,6 @@ 0.0.0.0 utting.org 0.0.0.0 utv.sakeronline.se 0.0.0.0 utv1.enliden.net -0.0.0.0 uujian.cn 0.0.0.0 uumove.com 0.0.0.0 uurty87e8rt7rt.com 0.0.0.0 uutiset.helppokoti.fi @@ -96297,7 +96301,6 @@ 0.0.0.0 voingani.it 0.0.0.0 voip96.ru 0.0.0.0 voipminic.com -0.0.0.0 vokasi.ub.ac.id 0.0.0.0 vokzalrf.ru 0.0.0.0 vol.agency 0.0.0.0 vol2.pw @@ -96925,7 +96928,6 @@ 0.0.0.0 washuis.nl 0.0.0.0 wasidora.com 0.0.0.0 wasilewski-online.de -0.0.0.0 wasimjee.com 0.0.0.0 wasino.co.th 0.0.0.0 wasobd.net 0.0.0.0 waspha.com @@ -98465,7 +98467,6 @@ 0.0.0.0 woatinkwoo.com 0.0.0.0 woclawoffers.fun 0.0.0.0 wocomm.marketingmindz.com -0.0.0.0 wodfitapparel.fr 0.0.0.0 wodmetaldom.pl 0.0.0.0 wodsuit.com 0.0.0.0 woelf.in @@ -101094,7 +101095,9 @@ 0.0.0.0 yoyoso.nz 0.0.0.0 yoyoteacher.cn 0.0.0.0 yp.dcyazilim.com +0.0.0.0 yp.hnggzyjy.cn 0.0.0.0 ypbb.or.id +0.0.0.0 ypddf.org 0.0.0.0 ypicsdy.cf 0.0.0.0 ypko-55.gq 0.0.0.0 ypom.com.br @@ -101253,7 +101256,6 @@ 0.0.0.0 yuti.kr 0.0.0.0 yuvann.com 0.0.0.0 yuvikadvertisments.com -0.0.0.0 yuwaraja.vokasi.ub.ac.id 0.0.0.0 yuweis.com 0.0.0.0 yuxigon.com 0.0.0.0 yuxuanknit.com diff --git a/urlhaus-filter-online.tpl b/urlhaus-filter-online.tpl index 0864edfc..0fb7b13f 100644 --- a/urlhaus-filter-online.tpl +++ b/urlhaus-filter-online.tpl @@ -1,6 +1,6 @@ msFilterList # Title: Online Malicious Hosts Blocklist (IE) -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -36,7 +36,6 @@ msFilterList -d adithimedia.com -d adithimedia.memengers.com -d admin.erapor.smk-alasror.net --d admin.gentbcn.org -d admin.grandoceanvilla.com -d admission.kmctartskuttippuram.org -d adventureexplorer.in @@ -52,6 +51,7 @@ msFilterList -d aiqtest.com -d ajpharmaholding.com -d akdvidyalaya.com +-d al-wahd.com -d alasdemariposas.org -d alberts.diamondrelationscrm.us -d alemelektronik.com @@ -89,7 +89,6 @@ msFilterList -d artedibujoyarquitectura.com -d arwenyapi.com -d ask-regard.call-save.biz --d asucssa.live -d atfile.com -d athenacapsg.com -d atlasconcreteworks.com @@ -101,15 +100,17 @@ msFilterList -d automaticrefreshments.com -d avadhanagames.com -d aventuramotorhome.com +-d awumad01.top +-d awuqze02.top -d ayahuascasp.com.br -d ayamallah.com --d aycconsultoriaempresarial.com -d azmeasurement.com -d azraktours.com -d b.r.uce.lee.b.es.t@zytrox.tk -d b2b.toptanakaryakit.com.tr -d backgrounds.pk -d badeggdesign.com +-d bakamla.go.id -d balealgodon.mx -d bangkok-orchids.com -d bangladeshunbound.com @@ -130,7 +131,6 @@ msFilterList -d bespokeweddings.ie -d bestcarenepal.com -d betone.co.kr --d betycopaints.com -d beveragesmiami.solucioneslink.com -d bhavaniengineering.com -d bigmikesupplies.co.za @@ -186,12 +186,12 @@ msFilterList -d capitalgroup-kw.com -d capoeiraventrelivre.com -d cashyinvestment.org +-d casiomaneflirt.cf -d catchpoolshetlands.co.uk -d cazyacustomfurniture.com -d cbn.hypervoizd.com -d ccauthority.net -d cdaonline.com.ar --d cdn-10049480.file.myqcloud.com -d cec.asso.ac-amiens.fr -d cellas.sk -d cendekiabinaaksara.com @@ -205,17 +205,17 @@ msFilterList -d chinhdropfile80.myvnc.com -d cible-energy.com -d cifeer.net +-d citiconstructioncorp.com -d citihits.lk -d citssolutions.co.za --d citycapproperty.ru -d cityglobalgospel.com -d civi.istmejia.com -d cleanbydesignllc.com -d cloud.fc.co.mz -d cnc.tacobelllover.tk -d codsambal.com --d colinde.pricesne.com -d colorpak.pl +-d columbia.aula-web.net -d community.reimclub.com -d competancy.indigoconsult.net -d conceptimagine.ro @@ -225,9 +225,11 @@ msFilterList -d consulateins.solucioneslink.com -d contributeindustry.com -d copelandscapes.com +-d corwin-tommie06f.ru.com -d coulsongraphics.com -d count.mail.163.com.impactmedfoundation.com -d covid19.cyberschool.or.id +-d covid19vaccinations.hopto.org -d cr-sq.com -d craftech.nxtnet.ga -d crearechile.cl @@ -290,6 +292,7 @@ msFilterList -d dl.198424.com -d dl.installcdn-aws.com -d dl.packetstormsecurity.net +-d dl.pandasecur.com -d dl.rina-roleplay.com -d dnn.alibuf.com -d dns.alibuf.com @@ -346,11 +349,11 @@ msFilterList -d ennovate.elin.co.za -d equimination.ee -d erp.nanotechproautocare.com +-d esaja09.top -d escola.probommar.org.br -d eservices.immigration.gov.lk -d esnconsultants.com -d essentia.org.br --d ethereality.info -d eubanks7.com -d europeanzonexxi.com -d exilum.com @@ -368,7 +371,7 @@ msFilterList -d fisconline.bar -d fisconline.casa -d fix-america-now.org --d fixauto.illumetechnology.com +-d fkd.derpcity.ru -d flexypay.dsquaregroup.com -d flintspin.com -d flyingbuddhadesign.com @@ -389,7 +392,6 @@ msFilterList -d futbolpr.com -d futuregraphics.com.ar -d g.pinmonkey.xyz --d gaditastour.com -d gametwogame.com -d garciadogshow.com -d garenanow.myvnc.com @@ -419,7 +421,6 @@ msFilterList -d goldmen.in -d gpotecnosystems.com -d gracejukes.com --d greataccesstoserver.com -d grupoinmare.com -d gruposelt.000webhostapp.com -d gs.monerorx.com @@ -450,17 +451,13 @@ msFilterList -d hmpmall.co.kr -d hoagietesting10.com -d hoayeuthuong-my.sharepoint.com --d holmesservices.mobiledevsite.co -d homefindersolutions.com -d hometownchick.com --d hongluosi.com -d hookedupboatclub.com -d hostingparacolombia.com -d hostzaa.com --d houstonshutters.site -d hr2019.vrcom7.com -d hseda.com --d hsmwebapp.com -d htownbars.com -d hubtech.co.za -d huellacero.cl @@ -508,6 +505,8 @@ msFilterList -d it123.ru -d italiandirezione.casa -d itc-demo.softgig.co.ke +-d itsrlytry.000webhostapp.com +-d jaishomo.info -d jamiekaylive.com -d jamshed.pk -d jansen-heesch.nl @@ -535,11 +534,11 @@ msFilterList -d kaptaanchapal.com -d karer.by -d katanvetov.co.il +-d katelynn9506a.ru.com -d kensingtondriving.com -d ketofitnessexpert.com -d kevinjewelry.com.co -d keywatch.yourpageserver.com --d kihn-delaney30gn.ru.com -d kingssa.co.za -d kjcpromo.com -d kleinendeli.co.za @@ -547,7 +546,6 @@ msFilterList -d krisbadminton.com -d ktb.sch.id -d kubatoglubaklava.com.tr --d kullumanalitours.com -d kumaralok.in -d kwanfromhongkong.com -d kz.sldov.ru @@ -604,7 +602,6 @@ msFilterList -d maksi.feb.unib.ac.id -d malaya.tv -d malwarecoding.github.io --d managed.oss-cn-beijing.aliyuncs.com -d managemysalon.in -d manantialesdelnorte.uy -d manhtien.net @@ -647,6 +644,7 @@ msFilterList -d microblading.mirliandias.com.br -d microcomm-group.com -d mikhailmotoringschool.com +-d mills-skyla30ec.com -d mingguanwms.com -d minuevavida.org -d mirror.mypage.sk @@ -663,6 +661,7 @@ msFilterList -d moninediy.com -d moreirawag.ac.ug -d motorcomunicacion.com +-d moumitas.com -d msacontabil.com.br -d mumgee.co.za -d muzimbiti.xigubo.co.mz @@ -712,6 +711,7 @@ msFilterList -d nyeh2o.com.au -d obseques-conseils.com -d oecteam.com +-d ohe.ie -d ohsewgorgeous.co.uk -d oleholeh.memangbeda.website -d omaia.org @@ -722,7 +722,6 @@ msFilterList -d onedigitalcard.granvizionnecorp.com -d onedrive.listifyapp.co -d online.creedglobal.in --d open.rawntech.com -d open.warehousesaas.co.uk -d opolis.io -d optimus.com.sg @@ -797,6 +796,7 @@ msFilterList -d pujashoppe.in -d punchdialogues.com -d punjabdevelopersassociation.com.pk +-d pvcprinting.co.uk -d qadir.tickfa.ir -d qatarglobalconsulting.com -d qmsled.com @@ -823,16 +823,15 @@ msFilterList -d readymmade.com -d recyclethesurplus.com -d redbats.co.in +-d redboxmultimedia.com -d redchillicrackers.com -d reifenquick.de --d relaxindulge.co.nz -d renehavis.com.ua -d repatriacioncolombia.com -d res.uf1.cn -d reseller.digimitra.in -d reseller.itechbrasil.com -d resuco.net --d revolet-sa.com -d rezkabum.ru -d rhema.com.sg -d richmondminerals.co.zm @@ -847,6 +846,7 @@ msFilterList -d ronnietucker.co.uk -d roomsvc.servegate.kr -d roshnijewellery.com +-d rotronics.com.ph -d rsgym.net -d rubazar.pro -d rubycityvietnam.com @@ -875,6 +875,7 @@ msFilterList -d schoolbustracker.softgig.co.ke -d sculetus.nl -d secure-doc-reader.com +-d secure.activedirect.xyz -d segalsmetals.elin.co.za -d sellmyphonela.com -d selltechtoday.com @@ -884,7 +885,9 @@ msFilterList -d sericaasia.com -d servicemhkd.myvnc.com -d servicemhkd80.myvnc.com +-d serviciovirtual.com.ar -d sexologistpakistan.net +-d sgb.ac.ke -d sgessy.com.br -d shaheentbfoundation.com -d shahikhana.cstdevs.com @@ -922,7 +925,6 @@ msFilterList -d sobethuacademy.com -d soft.110route.com -d soft.officelabo.net --d sogecoenergy.com -d sohs.conceptechs.info -d solar.amazingtribe.lk -d somcorbera.cat @@ -936,7 +938,6 @@ msFilterList -d spetsesyachtcharter.gr -d spititourism.com -d spittinfire.com --d springbedspetroleum.com -d src1.minibai.com -d sreenivasapaintingworks.com -d sriglobalit.com @@ -947,16 +948,23 @@ msFilterList -d staging.apparelpunch.com -d starcountry.net -d static.3001.net +-d stdynbnbnewagedevixz.dns.army +-d stdynmxwllminoragest.dns.army +-d stdyunitedkesokokgst.dns.army +-d stdyworkfinetraingst.dns.army +-d stdyzgchgcloudgostxs.dns.army -d stiau.iuc.ac -d sticker.jewsjuice.com -d stiepancasetia.ac.id -d stlukesohag.com -d store.ericalgarin.com -d stott-thompson.co.uk +-d stratexec.co.za -d streetdemo.yourpageserver.com -d suboldesign.com -d sumerians.org -d sunaryem.com.tr +-d sunbrero.com.au -d sunmarkholidays.com -d support-4-free.com -d support.clz.kr @@ -1035,7 +1043,6 @@ msFilterList -d toplevel.com.br -d topmask.co.za -d torresquinterocorp.com --d towme.services -d toyotacollege.ac.th -d tpke.hu -d translaterjemah.com @@ -1062,7 +1069,6 @@ msFilterList -d unyazitelecom.com -d up.llw0.com -d upcbpta.com --d used-jeans.fr -d useformoney.000webhostapp.com -d uss.ac.th -d uzzepay.com.br @@ -1071,7 +1077,6 @@ msFilterList -d vcah.co.uk -d vectarts.com -d vegadelcasero.cl --d velma-harber30ku.com -d vendas.lidiacarmeli.com.br -d veterinariadrpopui.com -d vfocus.net @@ -1087,7 +1092,6 @@ msFilterList -d viveirodoiscorregos.com.br -d vksales.com -d vocalterra.com --d vokasi.ub.ac.id -d vologroup.com.br -d voteyouramerica.dekitout.com -d vpts.co.za @@ -1108,6 +1112,7 @@ msFilterList -d weinsteincounseling.com -d wfinance.com.br -d whcms.yourpageserver.com +-d whiteglovetailgate.com -d whiteresponse.com -d wi522012.ferozo.com -d wikalen.co.za @@ -1137,6 +1142,7 @@ msFilterList -d yeq.i.u.j.ia.n.3@zytrox.tk -d ylfpremium.com -d yoast.yourpageserver.com +-d yp.hnggzyjy.cn -d yummyyogaudaipur.com -d yzkzixun.com -d ziyker4gaming@zytrox.tk diff --git a/urlhaus-filter-online.txt b/urlhaus-filter-online.txt index 1d4084f6..c83995cb 100644 --- a/urlhaus-filter-online.txt +++ b/urlhaus-filter-online.txt @@ -1,5 +1,5 @@ ! Title: Online Malicious URL Blocklist -! Updated: Mon, 12 Apr 2021 00:12:54 UTC +! Updated: Mon, 12 Apr 2021 12:13:00 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -39,7 +39,6 @@ 1.246.222.98 1.246.223.10 1.246.223.105 -1.246.223.109 1.246.223.126 1.246.223.127 1.246.223.130 @@ -70,7 +69,8 @@ 1008691.com 101.108.129.251 101.108.130.121 -101.108.131.47 +101.108.131.99 +101.108.138.150 101.16.183.179 101.229.85.127 101.255.36.154 @@ -78,6 +78,8 @@ 101.28.218.245 101.28.76.34 101.75.157.99 +101.99.91.200 +101.99.94.15 102.130.115.14 102.141.240.139 103.113.99.79 @@ -92,25 +94,18 @@ 103.237.21.36 103.238.228.3 103.240.249.121 -103.4.117.26 -103.47.104.246 103.79.112.254 -103.82.98.170 +103.82.81.37 103.84.240.130 103.84.241.94 103.91.245.12 -103.91.245.13 103.91.245.14 -103.91.245.16 -103.91.245.17 -103.91.245.27 -103.91.245.3 +103.91.245.19 103.91.245.36 -103.91.245.46 -103.91.245.47 +103.91.245.48 103.92.25.90 103.92.25.95 -104.168.44.57 +103.97.184.180 104.184.75.123 104.206.93.94 104.33.52.85 @@ -121,6 +116,7 @@ 106.105.33.43 107.172.104.105 107.172.141.115 +107.172.156.3 107.172.249.148 107.173.219.80 107.173.23.240 @@ -137,10 +133,10 @@ 108.190.250.48 108.239.155.26 108.249.194.121 -109.104.151.108 109.124.90.229 109.233.196.232 109.235.7.228 +109.248.58.238 109.86.85.253 109.95.200.102 109.95.200.230 @@ -156,13 +152,13 @@ 110.248.251.194 110.251.10.18 110.253.213.198 +110.35.145.127 110.35.208.21 -110.35.209.175 -110.35.223.92 -110.35.225.24 +110.35.221.77 110.35.235.57 +110.35.249.21 110.35.4.2 -111.118.88.128 +110.89.10.147 111.118.88.61 111.119.245.114 111.125.67.125 @@ -177,12 +173,9 @@ 111.185.49.223 111.38.103.114 111.38.103.122 -111.38.104.141 111.38.121.222 -111.38.121.223 111.38.121.226 111.38.123.136 -111.38.123.15 111.38.123.200 111.38.26.243 111.38.8.81 @@ -203,12 +196,8 @@ 112.230.168.103 112.232.0.112 112.237.141.241 -112.237.144.226 -112.237.75.157 -112.237.99.207 112.238.143.135 112.238.190.207 -112.238.227.228 112.238.39.2 112.239.101.146 112.240.216.17 @@ -222,6 +211,7 @@ 112.247.214.146 112.247.240.226 112.247.82.122 +112.248.109.156 112.248.148.90 112.248.63.212 112.249.109.217 @@ -241,6 +231,7 @@ 112.27.124.143 112.27.124.147 112.27.124.149 +112.27.124.150 112.27.124.158 112.27.124.165 112.27.124.175 @@ -273,34 +264,34 @@ 112.30.1.60 112.30.1.90 112.30.1.91 +112.30.110.30 112.30.110.38 112.30.110.45 112.30.110.60 112.30.35.237 -112.30.4.103 112.30.4.118 112.30.4.124 112.30.4.53 112.30.4.61 112.30.4.68 -112.30.4.70 112.30.4.73 112.30.4.90 112.31.0.113 112.31.177.39 -112.31.211.135 112.31.216.207 -112.31.240.239 112.53.224.79 112.53.227.66 112.65.53.175 +112.72.162.159 112.72.162.49 112.72.175.147 112.72.176.112 +112.72.176.84 112.72.226.202 112.80.215.101 112.82.146.253 112.82.224.139 +112.9.155.122 112.93.29.211 113.11.95.254 113.118.249.97 @@ -308,65 +299,77 @@ 113.13.241.32 113.161.58.249 113.161.78.185 +113.194.131.72 +113.194.135.223 +113.226.42.250 113.230.86.107 113.231.184.245 113.231.211.131 113.254.169.251 113.59.128.133 +113.59.136.39 +113.59.144.42 113.59.149.125 -113.59.154.21 -113.59.180.40 113.59.191.47 113.61.204.205 113.65.10.139 -113.88.153.5 -113.88.192.87 +113.88.123.22 +113.88.228.152 113.89.43.165 -114.199.204.37 114.199.253.235 114.201.201.68 114.224.203.128 114.30.54.64 -114.35.254.7 114.79.172.42 115.165.216.112 115.171.204.161 115.42.47.36 -115.48.140.22 -115.49.77.222 +115.49.232.197 +115.50.172.22 +115.50.2.148 115.51.106.238 +115.51.91.81 115.53.203.161 -115.54.241.214 +115.54.212.175 115.55.156.203 +115.55.7.9 115.56.131.242 115.56.133.96 115.56.155.202 -115.56.178.168 -115.56.182.146 -115.56.182.151 -115.58.111.76 -115.58.132.140 -115.59.203.197 115.59.214.205 115.59.233.160 115.59.252.120 115.61.110.120 +115.61.167.21 +115.62.172.140 +115.62.26.113 115.73.3.11 115.75.217.79 115.88.133.148 115.92.174.231 -115.97.139.110 +116.108.92.154 116.124.219.2 116.206.164.46 116.211.100.26 +117.194.162.12 117.20.204.138 117.20.204.5 117.20.210.52 +117.20.220.126 117.20.243.40 117.201.205.232 -117.251.59.124 +117.202.64.149 +117.213.12.177 +117.213.47.94 +117.213.9.42 +117.215.249.250 +117.222.173.91 +117.222.175.134 +117.242.208.197 +117.247.201.45 117.26.124.173 117.63.113.146 +117.63.133.251 117.63.53.15 117.86.105.110 118.101.7.28 @@ -390,10 +393,9 @@ 118.233.65.93 118.42.125.246 118.43.180.33 +118.79.113.239 118.79.218.213 118.79.50.203 -118.79.74.77 -118.91.41.135 118.99.179.164 118.99.183.235 118.99.239.217 @@ -412,6 +414,7 @@ 119.179.43.1 119.179.58.163 119.18.38.144 +119.18.88.78 119.180.106.217 119.181.119.21 119.182.97.232 @@ -427,14 +430,14 @@ 119.191.255.236 119.204.30.144 119.250.129.231 -119.251.105.221 119.56.131.155 119.56.143.46 119.56.143.71 119.56.148.115 119.56.155.57 -119.56.166.36 +119.56.206.43 119.96.38.150 +119.99.52.69 12.132.113.2 12.15.69.83 12.178.187.6 @@ -457,23 +460,20 @@ 120.193.91.201 120.193.91.202 120.193.91.204 -120.193.91.208 120.193.91.215 120.193.91.233 +120.209.126.206 120.209.126.235 120.209.126.239 -120.209.126.25 120.209.126.250 120.209.126.60 120.209.126.74 120.209.99.127 120.50.66.60 120.50.93.115 -120.57.123.202 120.6.8.11 120.7.75.99 120.83.79.42 -120.85.172.111 121.100.114.164 121.100.96.8 121.121.44.222 @@ -494,6 +494,7 @@ 121.254.76.17 121.61.96.158 121.61.97.64 +121.8.107.214 121.88.99.236 122.100.150.204 122.137.53.134 @@ -505,7 +506,7 @@ 122.232.227.128 122.254.33.214 123.0.240.58 -123.10.137.193 +123.10.32.252 123.11.202.178 123.110.124.244 123.110.170.237 @@ -513,7 +514,6 @@ 123.110.19.248 123.110.200.98 123.110.238.188 -123.12.164.165 123.129.2.28 123.129.84.36 123.130.208.52 @@ -527,6 +527,7 @@ 123.134.14.130 123.135.20.164 123.135.246.180 +123.14.95.26 123.154.236.114 123.159.8.100 123.183.16.71 @@ -552,11 +553,11 @@ 123.241.148.58 123.241.184.124 123.28.217.23 -123.4.204.223 -123.4.251.81 -123.8.250.132 -123.9.193.253 -123.9.85.25 +123.4.242.19 +123.4.47.57 +123.5.148.182 +123.5.189.15 +123.9.36.120 124.129.221.150 124.129.76.230 124.130.40.31 @@ -592,24 +593,20 @@ 125.40.1.235 125.40.146.46 125.40.3.71 +125.41.14.228 125.43.82.59 -125.44.8.154 125.45.186.88 125.45.66.253 -125.47.244.8 +125.47.244.126 125.47.74.230 -125.47.93.160 126.39.155.210 128.116.133.92 -13.114.247.134 130.255.159.133 -134.119.186.214 135.148.36.127 138.99.204.224 139.159.226.180 139.170.173.198 139.216.102.151 -14.102.17.222 14.136.80.242 14.138.8.215 14.138.8.51 @@ -623,10 +620,15 @@ 14.50.129.248 14.55.29.2 140.237.12.32 +141.105.65.94 142.11.216.5 142.177.56.127 +143.198.120.58 148.69.108.177 149.255.15.134 +149.255.15.170 +149.255.15.29 +149.255.15.44 149.255.15.99 149.3.124.194 14karatvisions.com @@ -646,9 +648,8 @@ 162.191.165.238 162.194.28.60 162.209.98.174 -163.125.200.234 +162.245.221.121 163.125.206.193 -163.53.206.228 167.114.172.177 170.81.238.178 171.121.255.12 @@ -686,17 +687,18 @@ 175.201.104.192 175.208.230.8 175.213.25.192 -175.42.46.118 176.111.174.35 176.111.174.66 176.111.174.67 176.113.161.104 176.113.161.121 176.113.161.59 +176.113.161.65 176.113.161.66 176.113.161.71 176.113.161.76 176.113.161.84 +176.113.161.91 176.113.161.95 176.12.117.70 176.123.7.115 @@ -704,7 +706,6 @@ 176.124.7.225 176.221.188.251 176.240.84.106 -177.11.92.78 177.131.226.235 177.54.82.154 178.124.182.187 @@ -712,7 +713,6 @@ 178.150.174.65 178.151.143.2 178.165.122.141 -178.17.171.144 178.175.0.145 178.175.0.24 178.175.1.179 @@ -721,128 +721,130 @@ 178.175.10.124 178.175.10.182 178.175.10.221 +178.175.10.247 178.175.10.96 +178.175.100.104 178.175.100.151 +178.175.101.212 178.175.101.252 178.175.102.207 178.175.102.217 178.175.102.25 -178.175.103.52 +178.175.103.14 178.175.103.58 178.175.104.112 +178.175.104.115 178.175.105.67 -178.175.105.89 178.175.106.160 178.175.106.179 -178.175.106.199 +178.175.107.135 178.175.107.142 -178.175.107.156 178.175.107.224 178.175.108.127 178.175.108.173 -178.175.108.87 178.175.109.165 178.175.109.181 +178.175.11.100 178.175.11.101 178.175.11.139 178.175.11.6 178.175.110.191 178.175.110.195 -178.175.111.190 178.175.112.111 178.175.112.183 -178.175.112.254 178.175.112.85 +178.175.112.87 178.175.113.174 +178.175.114.117 178.175.114.151 178.175.114.51 178.175.115.106 178.175.115.208 178.175.116.254 -178.175.116.56 -178.175.117.110 -178.175.118.112 -178.175.118.129 178.175.118.174 178.175.118.41 178.175.119.161 178.175.119.43 -178.175.12.222 178.175.12.68 +178.175.12.91 178.175.120.12 +178.175.121.125 +178.175.121.130 178.175.121.151 178.175.121.169 +178.175.121.243 +178.175.121.77 178.175.122.172 -178.175.122.28 +178.175.122.197 178.175.122.47 -178.175.123.202 178.175.123.53 +178.175.124.113 178.175.124.38 -178.175.125.149 178.175.125.218 -178.175.125.52 178.175.126.129 178.175.126.18 178.175.126.234 -178.175.126.46 +178.175.126.43 178.175.126.80 178.175.127.202 178.175.127.90 -178.175.14.222 -178.175.14.248 -178.175.14.34 +178.175.13.219 178.175.15.19 +178.175.15.196 178.175.15.232 178.175.15.250 178.175.15.72 +178.175.16.224 178.175.16.26 178.175.16.86 -178.175.17.13 178.175.17.135 178.175.17.14 178.175.17.50 -178.175.17.54 178.175.17.9 -178.175.19.163 -178.175.2.183 +178.175.18.177 +178.175.18.31 178.175.2.189 178.175.2.217 +178.175.2.23 178.175.2.46 178.175.2.71 178.175.20.117 178.175.20.126 178.175.20.231 178.175.21.194 -178.175.21.34 +178.175.21.53 178.175.21.71 178.175.22.120 +178.175.22.198 178.175.22.206 178.175.22.51 +178.175.22.74 178.175.22.93 178.175.22.94 178.175.24.107 178.175.24.176 178.175.24.183 -178.175.24.232 -178.175.25.114 -178.175.25.56 +178.175.24.52 +178.175.25.162 178.175.26.215 178.175.27.151 +178.175.27.203 178.175.27.32 -178.175.28.48 +178.175.27.43 178.175.28.5 178.175.29.135 178.175.29.233 -178.175.29.35 178.175.3.109 178.175.30.187 -178.175.30.254 178.175.30.71 +178.175.30.90 178.175.31.128 +178.175.31.216 178.175.31.55 178.175.31.92 178.175.32.34 178.175.33.190 +178.175.33.233 178.175.34.180 178.175.34.222 178.175.35.83 @@ -853,18 +855,18 @@ 178.175.36.250 178.175.36.98 178.175.37.10 -178.175.37.122 178.175.37.149 178.175.37.215 178.175.37.234 178.175.38.12 178.175.38.74 178.175.38.88 -178.175.39.157 +178.175.39.110 178.175.39.158 178.175.39.203 178.175.39.210 178.175.4.120 +178.175.4.14 178.175.4.180 178.175.4.225 178.175.40.108 @@ -873,87 +875,91 @@ 178.175.41.139 178.175.41.182 178.175.41.217 +178.175.41.230 178.175.41.68 178.175.42.221 178.175.42.28 178.175.42.46 178.175.43.114 178.175.43.217 -178.175.43.238 +178.175.43.90 178.175.44.186 178.175.44.38 178.175.44.56 178.175.44.78 -178.175.45.125 178.175.45.234 +178.175.46.110 178.175.46.113 -178.175.46.196 -178.175.46.208 178.175.47.11 178.175.47.122 +178.175.47.127 178.175.47.2 178.175.47.222 178.175.47.75 178.175.47.80 178.175.47.99 +178.175.48.164 178.175.48.185 178.175.48.194 178.175.48.223 +178.175.49.104 +178.175.49.253 178.175.49.30 178.175.49.51 178.175.49.54 178.175.49.82 -178.175.5.254 +178.175.5.223 178.175.5.44 178.175.50.217 178.175.50.3 178.175.50.42 178.175.50.54 178.175.50.68 -178.175.51.177 +178.175.51.117 178.175.51.2 +178.175.52.114 +178.175.52.139 178.175.52.15 178.175.52.176 178.175.52.181 178.175.52.24 +178.175.52.255 178.175.53.214 178.175.53.231 178.175.53.62 178.175.53.79 +178.175.53.87 178.175.54.100 -178.175.54.196 +178.175.54.119 +178.175.54.78 +178.175.55.118 178.175.55.170 178.175.55.60 178.175.55.99 178.175.56.30 178.175.56.64 178.175.56.74 -178.175.57.112 +178.175.57.121 178.175.57.145 178.175.58.12 -178.175.58.235 +178.175.58.130 +178.175.58.18 178.175.59.103 -178.175.59.106 178.175.59.12 -178.175.59.158 -178.175.6.144 -178.175.6.180 -178.175.60.158 -178.175.60.49 -178.175.60.7 -178.175.61.250 +178.175.59.173 +178.175.59.8 +178.175.6.201 +178.175.6.203 +178.175.61.212 178.175.61.28 -178.175.62.137 +178.175.62.130 178.175.62.151 178.175.62.206 -178.175.63.223 178.175.63.53 178.175.64.116 178.175.65.234 178.175.65.237 -178.175.66.140 178.175.66.186 -178.175.66.214 178.175.67.28 178.175.67.65 178.175.68.140 @@ -964,9 +970,7 @@ 178.175.68.35 178.175.68.4 178.175.68.5 -178.175.69.18 178.175.7.113 -178.175.7.19 178.175.7.198 178.175.70.108 178.175.70.177 @@ -977,40 +981,37 @@ 178.175.71.69 178.175.72.208 178.175.72.220 +178.175.72.58 178.175.74.223 178.175.75.94 178.175.76.146 178.175.76.221 178.175.76.33 +178.175.76.34 178.175.76.8 -178.175.77.47 178.175.78.118 -178.175.78.125 178.175.78.250 178.175.79.128 178.175.79.146 178.175.79.198 +178.175.79.27 178.175.8.119 -178.175.8.13 -178.175.8.130 178.175.8.40 -178.175.81.114 178.175.81.144 178.175.81.189 178.175.82.110 178.175.82.73 178.175.83.125 +178.175.83.17 +178.175.84.146 178.175.84.154 178.175.84.201 178.175.84.237 178.175.85.190 -178.175.86.117 178.175.86.49 -178.175.86.59 178.175.87.151 178.175.87.161 178.175.87.202 -178.175.87.207 178.175.87.227 178.175.88.102 178.175.88.130 @@ -1018,34 +1019,31 @@ 178.175.88.204 178.175.88.85 178.175.89.152 -178.175.89.69 +178.175.89.195 +178.175.9.217 178.175.9.223 -178.175.9.24 178.175.90.137 178.175.90.236 178.175.90.3 178.175.90.79 +178.175.91.243 178.175.91.3 178.175.91.97 178.175.92.170 -178.175.93.115 +178.175.92.213 178.175.93.120 +178.175.93.204 178.175.93.234 178.175.93.42 -178.175.93.98 -178.175.94.248 -178.175.94.27 178.175.95.105 178.175.95.54 +178.175.95.83 178.175.96.136 178.175.96.177 -178.175.96.198 178.175.96.225 178.175.97.248 -178.175.97.70 178.175.98.63 178.175.99.45 -178.175.99.90 178.19.183.14 178.205.101.33 178.21.164.68 @@ -1073,7 +1071,9 @@ 180.177.104.65 180.177.180.6 180.177.242.73 +180.177.5.36 180.218.5.171 +180.248.80.38 180.66.111.36 180.66.53.93 180.94.170.166 @@ -1090,40 +1090,45 @@ 181.49.236.4 181.49.59.162 182.112.177.134 -182.114.88.240 -182.114.88.247 -182.115.176.253 +182.113.4.247 +182.114.194.183 182.116.102.190 -182.116.35.52 +182.117.29.27 182.119.200.55 +182.119.23.75 +182.119.48.230 182.120.16.22 182.120.192.88 182.120.34.180 -182.121.73.158 +182.121.200.137 +182.121.205.246 182.122.254.7 +182.126.109.194 +182.126.126.162 182.126.87.210 182.126.87.246 -182.127.213.136 +182.127.207.187 +182.127.80.240 182.160.98.250 182.233.0.252 182.235.252.31 182.53.197.62 -182.59.170.157 182.88.27.89 183.105.104.83 183.109.169.45 +183.141.61.174 183.17.145.112 183.188.144.204 -183.188.146.216 -183.83.109.216 +183.49.86.54 183.83.14.20 183.97.40.9 184.164.185.41 184.175.115.10 184.74.149.230 185.106.209.68 -185.107.3.8 185.117.2.107 +185.117.21.212 +185.132.53.182 185.172.110.209 185.172.110.235 185.174.101.41 @@ -1140,14 +1145,13 @@ 185.245.96.94 185.26.113.95 185.34.16.231 +185.38.142.194 185.55.1.182 185.68.230.207 185.81.154.208 185.81.157.186 185.82.217.185 185.82.217.213 -185.82.219.160 -185.82.219.161 185.82.219.219 185.82.219.80 186.151.144.85 @@ -1161,7 +1165,6 @@ 186.28.60.184 186.34.4.40 186.73.188.132 -186.73.188.134 187.12.10.98 187.135.141.192 187.188.124.229 @@ -1173,12 +1176,15 @@ 188.152.41.141 188.169.178.50 188.169.179.127 +188.169.199.59 188.169.30.30 188.169.36.163 +188.169.45.140 188.242.242.144 188.69.251.12 188.83.202.25 -189.201.250.184 +189.171.22.132 +189.175.214.112 189.252.184.115 190.0.42.106 190.109.178.139 @@ -1193,7 +1199,6 @@ 190.122.112.42 190.122.112.76 190.130.20.14 -190.141.117.41 190.147.16.184 190.159.240.9 190.210.214.130 @@ -1209,19 +1214,20 @@ 190.98.37.200 190.98.41.33 191.255.248.220 -192.153.57.94 192.210.175.130 +192.227.185.106 192.227.220.55 192.227.228.67 +192.99.221.230 192.99.240.77 194.113.107.243 194.147.142.230 -194.15.36.167 194.152.35.139 194.38.20.199 195.139.126.51 195.228.231.218 195.24.94.187 +195.5.3.162 196.202.26.182 196.218.48.82 196.221.148.90 @@ -1229,15 +1235,12 @@ 197.159.2.106 197.50.27.115 198.23.133.218 -198.23.174.104 -198.23.207.121 +198.23.213.61 198.23.251.105 -198.46.132.132 1am.co.nz 2.239.22.188 2.36.231.201 2.37.149.230 -2.37.203.65 2.45.111.158 2.45.4.24 2.55.125.182 @@ -1250,7 +1253,6 @@ 200.105.167.98 200.111.189.70 200.194.4.24 -200.2.161.171 200.29.105.207 200.30.132.50 201.170.46.2 @@ -1261,14 +1263,13 @@ 202.107.233.41 202.111.131.236 202.166.217.54 -202.182.125.175 202.29.95.12 202.4.124.58 -202.44.228.125 202.51.176.114 202.51.191.174 202.74.236.9 203.109.201.243 +203.130.69.205 203.159.80.128 203.159.80.129 203.159.80.164 @@ -1295,12 +1296,12 @@ 210.180.237.212 210.216.152.122 210.216.153.142 -210.57.237.70 210.57.245.109 210.68.242.114 211.187.132.204 211.187.75.220 211.200.160.239 +211.203.111.207 211.204.215.157 211.210.66.179 211.210.93.93 @@ -1309,7 +1310,6 @@ 211.237.120.13 211.237.246.137 211.238.83.238 -211.247.5.96 212.122.86.105 212.156.215.178 212.46.197.114 @@ -1319,7 +1319,7 @@ 213.14.173.117 213.149.190.193 213.163.104.160 -213.163.104.99 +213.163.104.20 213.163.113.225 213.163.113.51 213.163.114.202 @@ -1336,7 +1336,7 @@ 213.163.118.227 213.163.126.176 213.163.126.201 -213.163.126.7 +213.163.127.204 213.163.127.250 213.163.127.46 213.189.178.163 @@ -1356,7 +1356,6 @@ 218.2.40.34 218.234.165.18 218.238.246.3 -218.32.118.1 218.35.207.119 218.35.227.133 218.35.68.35 @@ -1366,11 +1365,12 @@ 218.79.103.159 218.93.102.63 218.93.102.75 +219.154.113.171 219.154.127.194 -219.154.137.93 -219.156.73.171 +219.155.226.205 219.157.136.212 -219.157.139.165 +219.157.14.239 +219.157.178.196 219.157.37.210 219.241.6.180 219.68.1.148 @@ -1385,7 +1385,6 @@ 219.85.145.194 21robo.com 220.126.237.74 -220.132.106.247 220.173.160.185 220.200.22.163 220.81.134.72 @@ -1393,7 +1392,9 @@ 221.124.78.15 221.13.150.74 221.14.162.20 +221.14.47.204 221.15.127.60 +221.15.182.72 221.15.3.50 221.157.191.178 221.160.136.213 @@ -1411,18 +1412,17 @@ 221.232.183.167 221.235.137.36 221.3.68.16 +222.107.145.56 222.108.17.64 222.118.248.149 222.119.65.145 -222.132.125.138 222.135.9.5 222.137.122.105 222.137.139.86 -222.137.170.17 222.137.72.66 222.138.133.186 -222.138.17.203 222.139.21.190 +222.140.163.181 222.140.17.245 222.187.9.178 222.211.72.66 @@ -1445,9 +1445,9 @@ 23.24.213.121 23.243.149.13 23.243.21.167 -23.92.213.108 23.94.190.101 23.95.122.24 +23.95.122.25 24.103.74.180 24.11.141.134 24.119.158.74 @@ -1518,9 +1518,7 @@ 27.213.255.202 27.213.66.112 27.213.84.74 -27.214.37.129 27.215.139.242 -27.215.190.172 27.215.212.209 27.215.253.149 27.215.71.243 @@ -1532,7 +1530,6 @@ 27.217.191.58 27.218.135.3 27.219.132.71 -27.219.151.83 27.219.160.112 27.219.176.72 27.219.83.244 @@ -1548,16 +1545,14 @@ 27.35.154.13 27.35.212.124 27.35.58.5 -27.40.120.108 -27.40.73.175 +27.40.79.170 27.41.36.97 -27.45.90.246 -27.5.44.190 31.0.98.131 31.11.51.57 31.13.23.180 31.168.124.130 31.168.146.199 +31.168.16.68 31.168.179.83 31.168.184.59 31.168.191.243 @@ -1607,7 +1602,6 @@ 39.113.245.254 39.113.98.136 39.114.137.102 -39.115.0.100 39.117.31.162 39.162.104.119 39.162.98.216 @@ -1668,27 +1662,34 @@ 40.88.2.151 41.139.209.46 41.165.130.43 -41.190.63.174 41.193.192.100 41.219.185.171 41.226.60.115 +41.72.203.82 +41.76.157.2 41.86.18.147 41.86.18.152 -41.86.18.204 -41.86.19.146 -41.86.19.206 -41.86.21.28 -41.86.21.60 -41.86.5.198 +41.86.21.38 +41.86.21.59 +41.86.5.103 +41.86.5.197 +41.86.5.48 42.202.101.181 42.202.101.199 +42.224.171.165 42.224.176.27 +42.224.254.220 +42.224.4.110 +42.227.222.189 +42.227.225.253 42.228.40.143 -42.228.60.114 +42.230.143.162 +42.233.97.141 +42.235.84.85 42.236.161.72 42.236.212.157 +42.237.114.80 42.238.141.250 -42.56.15.227 42.61.99.155 42.82.217.241 43.230.207.204 @@ -1707,6 +1708,7 @@ 45.144.225.27 45.148.10.47 45.148.10.94 +45.15.143.191 45.176.108.248 45.176.109.205 45.176.110.146 @@ -1715,6 +1717,7 @@ 45.229.53.148 45.27.253.137 45.51.104.59 +45.77.9.151 45.85.90.131 45.9.148.37 45.92.108.35 @@ -1735,8 +1738,8 @@ 46.42.118.86 46.42.86.128 46.97.76.242 +47.136.96.53 47.145.152.26 -47.151.23.172 47.157.97.71 47.16.131.51 47.21.202.98 @@ -1756,6 +1759,7 @@ 5.14.122.233 5.188.62.111 5.95.226.154 +50.115.174.103 50.115.174.106 50.121.91.255 50.247.83.66 @@ -1780,32 +1784,39 @@ 58.240.147.97 58.241.78.55 58.242.91.219 -58.249.73.208 +58.249.22.24 58.249.75.128 +58.249.75.146 +58.249.77.141 58.249.80.36 -58.252.176.140 58.253.15.184 58.51.219.200 58.72.165.153 58.72.165.39 59.0.211.161 59.102.168.189 -59.126.26.220 59.151.202.3 59.151.214.4 -59.151.237.51 -59.151.246.125 59.173.135.51 59.175.63.177 59.23.114.97 59.26.181.228 59.30.12.254 -59.60.117.163 +59.50.23.23 +59.89.242.116 +59.92.217.215 +59.92.218.82 +59.93.21.140 +59.93.21.172 +59.94.182.212 +59.95.175.49 +59.97.170.146 60.13.61.12 60.209.122.57 60.209.216.23 60.209.233.94 60.211.6.112 +60.211.80.216 60.212.100.83 60.212.111.39 60.212.206.246 @@ -1813,31 +1824,30 @@ 60.212.220.167 60.212.254.178 60.213.83.55 +60.214.53.159 60.214.85.149 60.217.177.196 60.217.86.208 -60.220.159.240 -60.253.15.104 -60.253.39.88 60.253.4.72 60.253.51.127 60.253.60.174 60.253.8.81 -60.254.36.135 60.7.10.121 60.7.8.43 61.146.108.150 +61.163.131.67 61.179.91.194 61.247.224.66 +61.3.150.101 61.52.101.143 +61.52.186.186 61.52.241.252 61.52.57.40 61.52.9.166 +61.52.97.68 61.52.98.43 61.52.99.161 61.53.117.152 -61.53.249.58 -61.53.74.236 61.54.103.56 61.56.180.67 61.56.181.7 @@ -1869,7 +1879,6 @@ 66.108.199.144 66.57.55.210 66.74.7.197 -66.91.21.31 66.97.181.196 67.245.151.203 67.8.138.101 @@ -1931,6 +1940,7 @@ 74.64.139.223 74.75.165.81 75.127.141.52 +75.83.102.27 75.99.213.61 76.170.11.82 76.178.22.145 @@ -1940,14 +1950,12 @@ 76.84.134.33 76.89.107.69 76.95.12.137 -77.111.182.31 77.237.25.210 77.71.50.153 77.89.203.238 77st.net 78.138.98.134 78.145.224.45 -78.187.141.144 78.187.41.200 78.188.106.235 78.188.168.64 @@ -1968,7 +1976,6 @@ 80.107.89.207 80.19.101.218 80.211.181.77 -80.217.12.7 80.99.128.61 81.136.146.213 81.165.44.109 @@ -1985,7 +1992,6 @@ 81.92.36.96 82.103.108.72 82.135.196.130 -82.166.212.178 82.166.85.112 82.207.61.194 82.209.250.155 @@ -2036,14 +2042,17 @@ 85.105.208.25 85.105.224.141 85.105.241.2 -85.108.133.19 85.214.149.236 85.241.39.182 +85.250.147.134 85.64.181.50 85.74.215.180 85.97.130.227 86.35.43.220 +86.98.23.78 +87.117.11.46 87.172.19.130 +87.251.71.78 87du.vip 88.119.171.253 88.129.208.43 @@ -2070,7 +2079,6 @@ 8poieq.bn.files.1drv.com 90.152.144.139 91.132.197.39 -91.138.215.5 91.177.139.132 91.187.103.32 91.212.150.241 @@ -2085,6 +2093,7 @@ 92.54.237.237 92.83.62.139 92.85.18.138 +93.157.63.221 93.159.169.190 93.173.235.110 93.21.224.154 @@ -2098,13 +2107,13 @@ 94.136.69.199 94.143.53.34 94.154.17.170 +94.154.82.190 94.200.16.22 94.224.83.208 94.53.120.109 94.85.0.3 95.132.129.250 95.133.158.20 -95.154.20.231 95.158.19.130 95.170.113.227 95.170.201.34 @@ -2140,7 +2149,6 @@ addahealingmusic.com adithimedia.com adithimedia.memengers.com admin.erapor.smk-alasror.net -admin.gentbcn.org admin.grandoceanvilla.com admission.kmctartskuttippuram.org adventureexplorer.in @@ -2156,6 +2164,7 @@ aiecons.com aiqtest.com ajpharmaholding.com akdvidyalaya.com +al-wahd.com alasdemariposas.org alberts.diamondrelationscrm.us alemelektronik.com @@ -2194,7 +2203,6 @@ aps-sv.com artedibujoyarquitectura.com arwenyapi.com ask-regard.call-save.biz -asucssa.live atfile.com athenacapsg.com atlasconcreteworks.com @@ -2206,15 +2214,17 @@ australianpga.com.au automaticrefreshments.com avadhanagames.com aventuramotorhome.com +awumad01.top +awuqze02.top ayahuascasp.com.br ayamallah.com -aycconsultoriaempresarial.com azmeasurement.com azraktours.com b.r.uce.lee.b.es.t@zytrox.tk b2b.toptanakaryakit.com.tr backgrounds.pk badeggdesign.com +bakamla.go.id balealgodon.mx bangkok-orchids.com bangladeshunbound.com @@ -2235,7 +2245,6 @@ beor360.com bespokeweddings.ie bestcarenepal.com betone.co.kr -betycopaints.com beveragesmiami.solucioneslink.com bhavaniengineering.com bigmikesupplies.co.za @@ -2291,12 +2300,12 @@ canadianwork.cc capitalgroup-kw.com capoeiraventrelivre.com cashyinvestment.org +casiomaneflirt.cf catchpoolshetlands.co.uk cazyacustomfurniture.com cbn.hypervoizd.com ccauthority.net cdaonline.com.ar -cdn-10049480.file.myqcloud.com cec.asso.ac-amiens.fr cellas.sk cendekiabinaaksara.com @@ -2310,17 +2319,17 @@ chinhdropfile.myvnc.com chinhdropfile80.myvnc.com cible-energy.com cifeer.net +citiconstructioncorp.com citihits.lk citssolutions.co.za -citycapproperty.ru cityglobalgospel.com civi.istmejia.com cleanbydesignllc.com cloud.fc.co.mz cnc.tacobelllover.tk codsambal.com -colinde.pricesne.com colorpak.pl +columbia.aula-web.net community.reimclub.com competancy.indigoconsult.net conceptimagine.ro @@ -2330,9 +2339,11 @@ constructoralyon.com consulateins.solucioneslink.com contributeindustry.com copelandscapes.com +corwin-tommie06f.ru.com coulsongraphics.com count.mail.163.com.impactmedfoundation.com covid19.cyberschool.or.id +covid19vaccinations.hopto.org cr-sq.com craftech.nxtnet.ga crearechile.cl @@ -2395,6 +2406,7 @@ dl.1003b.56a.com dl.198424.com dl.installcdn-aws.com dl.packetstormsecurity.net +dl.pandasecur.com dl.rina-roleplay.com dnn.alibuf.com dns.alibuf.com @@ -2451,11 +2463,11 @@ endurotanzania.co.tz ennovate.elin.co.za equimination.ee erp.nanotechproautocare.com +esaja09.top escola.probommar.org.br eservices.immigration.gov.lk esnconsultants.com essentia.org.br -ethereality.info eubanks7.com europeanzonexxi.com exilum.com @@ -2473,7 +2485,7 @@ fineartgallerym.com fisconline.bar fisconline.casa fix-america-now.org -fixauto.illumetechnology.com +fkd.derpcity.ru flexypay.dsquaregroup.com flintspin.com flyingbuddhadesign.com @@ -2494,7 +2506,6 @@ fusionfiresolutions.com futbolpr.com futuregraphics.com.ar g.pinmonkey.xyz -gaditastour.com gametwogame.com garciadogshow.com garenanow.myvnc.com @@ -2524,7 +2535,6 @@ goldenasiacapital.com goldmen.in gpotecnosystems.com gracejukes.com -greataccesstoserver.com grupoinmare.com gruposelt.000webhostapp.com gs.monerorx.com @@ -2555,17 +2565,13 @@ hitstation.nl hmpmall.co.kr hoagietesting10.com hoayeuthuong-my.sharepoint.com -holmesservices.mobiledevsite.co homefindersolutions.com hometownchick.com -hongluosi.com hookedupboatclub.com hostingparacolombia.com hostzaa.com -houstonshutters.site hr2019.vrcom7.com hseda.com -hsmwebapp.com htownbars.com hubtech.co.za huellacero.cl @@ -2613,6 +2619,8 @@ isso.ps it123.ru italiandirezione.casa itc-demo.softgig.co.ke +itsrlytry.000webhostapp.com +jaishomo.info jamiekaylive.com jamshed.pk jansen-heesch.nl @@ -2640,11 +2648,11 @@ kalogirosfinance.com kaptaanchapal.com karer.by katanvetov.co.il +katelynn9506a.ru.com kensingtondriving.com ketofitnessexpert.com kevinjewelry.com.co keywatch.yourpageserver.com -kihn-delaney30gn.ru.com kingssa.co.za kjcpromo.com kleinendeli.co.za @@ -2652,7 +2660,6 @@ korrectconceptservices.com krisbadminton.com ktb.sch.id kubatoglubaklava.com.tr -kullumanalitours.com kumaralok.in kwanfromhongkong.com kz.sldov.ru @@ -2709,7 +2716,6 @@ mail.jeffsono.org maksi.feb.unib.ac.id malaya.tv malwarecoding.github.io -managed.oss-cn-beijing.aliyuncs.com managemysalon.in manantialesdelnorte.uy manhtien.net @@ -2752,6 +2758,7 @@ michimal2.000webhostapp.com microblading.mirliandias.com.br microcomm-group.com mikhailmotoringschool.com +mills-skyla30ec.com mingguanwms.com minuevavida.org mirror.mypage.sk @@ -2768,6 +2775,7 @@ monetization.business moninediy.com moreirawag.ac.ug motorcomunicacion.com +moumitas.com msacontabil.com.br mumgee.co.za muzimbiti.xigubo.co.mz @@ -2817,6 +2825,7 @@ nyasabigbullets.com nyeh2o.com.au obseques-conseils.com oecteam.com +ohe.ie ohsewgorgeous.co.uk oleholeh.memangbeda.website omaia.org @@ -2827,7 +2836,6 @@ omscoc.pappai.com onedigitalcard.granvizionnecorp.com onedrive.listifyapp.co online.creedglobal.in -open.rawntech.com open.warehousesaas.co.uk opolis.io optimus.com.sg @@ -2902,6 +2910,7 @@ prox.realunix.cc pujashoppe.in punchdialogues.com punjabdevelopersassociation.com.pk +pvcprinting.co.uk qadir.tickfa.ir qatarglobalconsulting.com qmsled.com @@ -2928,16 +2937,15 @@ readwrite26.nl readymmade.com recyclethesurplus.com redbats.co.in +redboxmultimedia.com redchillicrackers.com reifenquick.de -relaxindulge.co.nz renehavis.com.ua repatriacioncolombia.com res.uf1.cn reseller.digimitra.in reseller.itechbrasil.com resuco.net -revolet-sa.com rezkabum.ru rhema.com.sg richmondminerals.co.zm @@ -2952,6 +2960,7 @@ romanianpoints.com ronnietucker.co.uk roomsvc.servegate.kr roshnijewellery.com +rotronics.com.ph rsgym.net rubazar.pro rubycityvietnam.com @@ -2981,6 +2990,7 @@ scheff.com schoolbustracker.softgig.co.ke sculetus.nl secure-doc-reader.com +secure.activedirect.xyz segalsmetals.elin.co.za sellmyphonela.com selltechtoday.com @@ -2990,7 +3000,9 @@ serendibsourcing.com sericaasia.com servicemhkd.myvnc.com servicemhkd80.myvnc.com +serviciovirtual.com.ar sexologistpakistan.net +sgb.ac.ke sgessy.com.br shaheentbfoundation.com shahikhana.cstdevs.com @@ -3028,7 +3040,6 @@ sobariko.com sobethuacademy.com soft.110route.com soft.officelabo.net -sogecoenergy.com sohs.conceptechs.info solar.amazingtribe.lk somcorbera.cat @@ -3042,7 +3053,6 @@ spent.com.pl spetsesyachtcharter.gr spititourism.com spittinfire.com -springbedspetroleum.com src1.minibai.com sreenivasapaintingworks.com sriglobalit.com @@ -3053,16 +3063,23 @@ st.devcodin.com staging.apparelpunch.com starcountry.net static.3001.net +stdynbnbnewagedevixz.dns.army +stdynmxwllminoragest.dns.army +stdyunitedkesokokgst.dns.army +stdyworkfinetraingst.dns.army +stdyzgchgcloudgostxs.dns.army stiau.iuc.ac sticker.jewsjuice.com stiepancasetia.ac.id stlukesohag.com store.ericalgarin.com stott-thompson.co.uk +stratexec.co.za streetdemo.yourpageserver.com suboldesign.com sumerians.org sunaryem.com.tr +sunbrero.com.au sunmarkholidays.com support-4-free.com support.clz.kr @@ -3141,7 +3158,6 @@ topcell9.com toplevel.com.br topmask.co.za torresquinterocorp.com -towme.services toyotacollege.ac.th tpke.hu translaterjemah.com @@ -3168,7 +3184,6 @@ union.jctrip.cn unyazitelecom.com up.llw0.com upcbpta.com -used-jeans.fr useformoney.000webhostapp.com uss.ac.th uzzepay.com.br @@ -3177,7 +3192,6 @@ vbcargo.hu vcah.co.uk vectarts.com vegadelcasero.cl -velma-harber30ku.com vendas.lidiacarmeli.com.br veterinariadrpopui.com vfocus.net @@ -3193,7 +3207,6 @@ vivationdesign.com viveirodoiscorregos.com.br vksales.com vocalterra.com -vokasi.ub.ac.id vologroup.com.br voteyouramerica.dekitout.com vpts.co.za @@ -3214,6 +3227,7 @@ webpresario.com weinsteincounseling.com wfinance.com.br whcms.yourpageserver.com +whiteglovetailgate.com whiteresponse.com wi522012.ferozo.com wikalen.co.za @@ -3243,6 +3257,7 @@ yeichner.com yeq.i.u.j.ia.n.3@zytrox.tk ylfpremium.com yoast.yourpageserver.com +yp.hnggzyjy.cn yummyyogaudaipur.com yzkzixun.com ziyker4gaming@zytrox.tk @@ -3251,9 +3266,11 @@ zytrox.tk zz.690tx.com ||2.indexsinas.me:811/64.exe$all ||2.indexsinas.me:811/86.exe$all +||2.indexsinas.me:811/c64.exe$all ||amumufree.weebly.com/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe$all ||analogx.com/files/proxyi.exe$all ||bitbucket.org/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe$all +||bitbucket.org/clubhousedev/clubhouse/downloads/clubhousepc.exe$all ||bitbucket.org/dvdfv/anjj/downloads/jami.exe$all ||bitbucket.org/heyhoeee/heyhoename1/downloads/1234.exe$all ||bitbucket.org/jpavelski/chpock/downloads/4.exe$all @@ -3301,7 +3318,6 @@ zz.690tx.com ||bitbucket.org/tanake5518/fi/downloads/clientrevers.txt$all ||bitbucket.org/tanake5518/fi/downloads/dcrat.exe$all ||bitbucket.org/tanake5518/fi/downloads/dllservices.exe$all -||bitbucket.org/tanake5518/fi/downloads/dllservices2.exe$all ||bitbucket.org/tanake5518/fi/downloads/exe_morris.mcdermott.exe$all ||bitbucket.org/tanake5518/fi/downloads/hans.txt$all ||bitbucket.org/tanake5518/fi/downloads/hulu.txt$all @@ -3341,16 +3357,16 @@ zz.690tx.com ||bitbucket.org/teaserex/tease/downloads/b_kfmhkk172.bin$all ||bitbucket.org/teaserex/tease/downloads/macro_xmprohiq27.bin$all ||cd.textfiles.com/hmatrix/data/hack1226.exe$all -||cdn.discordapp.com/attachments/712408764354920490/829413679866839120/echelon_protected.exe$all ||cdn.discordapp.com/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq$all +||cdn.discordapp.com/attachments/775238059083038744/829993648186851338/pslmlyfnpzgsgitrwwvalcfunumfmac$all ||cdn.discordapp.com/attachments/816070119281131570/816070273254162442/all.txt$all ||cdn.discordapp.com/attachments/825372018244583454/826848185246023750/loaddd.exe$all ||cdn.discordapp.com/attachments/825372018244583454/826848348342059008/zeppelin.exe$all ||cdn.discordapp.com/attachments/825372018244583454/826848405258633277/build.exe$all +||cdn.discordapp.com/attachments/825372018244583454/830455061724528690/v1.exe$all ||cdn.discordapp.com/attachments/826198252025675816/826537386485612574/china.png$all ||cdn.discordapp.com/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin$all ||cdn.discordapp.com/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe$all -||cdn.discordapp.com/attachments/829721030112182363/829724335526510622/dcratbuild.exe$all ||chiptune.com/razor/rzr-winner_intro.zip$all ||cloudme.com/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz$all ||cloudme.com/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar$all @@ -3373,6 +3389,7 @@ zz.690tx.com ||drive.google.com/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv$all ||drive.google.com/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben$all ||drive.google.com/uc?export=download&id=1d0ij6qkgrf6irywv6ftk1m7p5l3weh3a$all +||drive.google.com/uc?export=download&id=1dzx_cflers_zntlrip3fhbxb5who03u0$all ||drive.google.com/uc?export=download&id=1gprlk2mcrl6law-zk5r0pjogaqrxwepd$all ||drive.google.com/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei$all ||drive.google.com/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr$all @@ -3399,6 +3416,7 @@ zz.690tx.com ||drive.google.com/uc?export=download&id=1voqnsh0cmxl5hty4zpc18pgnkud5rtvy$all ||drive.google.com/uc?export=download&id=1vy1nx5zefluh5ewihr-6pcndlyex7xcm$all ||drive.google.com/uc?export=download&id=1wpqa2nnnktbhzs4j0r-erosvgyaagi_a$all +||drive.google.com/uc?export=download&id=1xbp7hvw2ybwjrftbvdkjvwzrfuk4ope9$all ||drive.google.com/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e$all ||drive.google.com/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi$all ||drive.google.com/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58$all @@ -3427,12 +3445,12 @@ zz.690tx.com ||ia801802.us.archive.org/19/items/startup_20210219/startup.txt$all ||ie-best.net/online-timer-kvhxz/ilxl/$all ||indonesias.me:9998/64.exe$all +||indonesias.me:9998/c64.exe$all ||jcedu.org/ebook/cs17.exe$all ||jointings.org/eng/wp-content/plugins/featurific-for-wordpress/1$all ||jointings.org/eng/wp-content/plugins/featurific-for-wordpress/2$all ||jointings.org/eng/wp-content/plugins/featurific-for-wordpress/3$all ||karmakoincodes.weebly.com/uploads/3/2/8/8/3288864/karma_koin_codes.exe$all -||kautilyaclasses.com/ds/index.html$all ||kotakwarna.co.id/dg/etrac/nf4emwz/$all ||ksh.hu/docs/adatgyujtesek/elektra/csv_to_xml.exe$all ||kuaizip.com/down/affiliate/kuaizip_setup_10029.exe$all @@ -3461,6 +3479,7 @@ zz.690tx.com ||onedrive.live.com/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135$all ||onedrive.live.com/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732$all ||onedrive.live.com/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4$all +||onedrive.live.com/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc$all ||onedrive.live.com/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc$all ||onedrive.live.com/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0$all ||onedrive.live.com/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu$all @@ -3491,6 +3510,7 @@ zz.690tx.com ||onedrive.live.com/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw$all ||onedrive.live.com/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0$all ||onedrive.live.com/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a$all +||onedrive.live.com/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4$all ||onedrive.live.com/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo$all ||onedrive.live.com/download?cid=15d9646f4dbf9553&resid=15d9646f4dbf9553%21110&authkey=ag0eg1lha_lwgi0$all ||onedrive.live.com/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte$all @@ -3682,12 +3702,14 @@ zz.690tx.com ||onedrive.live.com/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8$all ||onedrive.live.com/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq$all ||onedrive.live.com/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug$all +||onedrive.live.com/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua$all ||onedrive.live.com/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe$all ||onedrive.live.com/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i$all ||onedrive.live.com/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa$all ||onedrive.live.com/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe$all ||onedrive.live.com/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m$all ||onedrive.live.com/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi$all +||onedrive.live.com/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21198&authkey=akq4jrbjm6spd9m$all ||onedrive.live.com/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi$all ||onedrive.live.com/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e$all ||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90$all @@ -4016,6 +4038,7 @@ zz.690tx.com ||users.skynet.be/crisanar/defis/jek_crackme1.7.zip$all ||vniel.co.kr/gnuboard/data/scan/amowvegfrt9ja/$all ||vniel.co.kr/gnuboard/data/scan/fu6jvxzzs46uqlp7l/$all +||vokasi.ub.ac.id/wuk/kuqyslbgavnwlmcuk0qalhxifzp4mgze8anlcewu1pa8fw4lfex0y/$all ||web.mit.edu/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc$all ||web.mit.edu/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc$all ||websound.ru/issues/136_140/flt_shovemydiscoupyourarse.exe$all @@ -4024,4 +4047,3 @@ zz.690tx.com ||websound.ru/issues/146_150/bc_memories_from_the_mcp.exe$all ||websound.ru/issues/151_155/tidex_-_short_stuff.exe$all ||wikileaks.org/syria-files/attach/222/222051_instruction.zip$all -||yp.hnggzyjy.cn/common/yz.vbs$all diff --git a/urlhaus-filter-rpz-online.conf b/urlhaus-filter-rpz-online.conf index 95f48289..1a97f7e3 100644 --- a/urlhaus-filter-rpz-online.conf +++ b/urlhaus-filter-rpz-online.conf @@ -1,12 +1,12 @@ ; Title: Online Malicious Domains RPZ Blocklist -; Updated: Mon, 12 Apr 2021 00:12:54 UTC +; Updated: Mon, 12 Apr 2021 12:13:00 UTC ; Expires: 1 day (update frequency) ; Homepage: https://gitlab.com/curben/urlhaus-filter ; License: https://gitlab.com/curben/urlhaus-filter#license ; Source: https://urlhaus.abuse.ch/api/ $TTL 30 -@ IN SOA rpz.curben.gitlab.io. hostmaster.rpz.curben.gitlab.io. 1618186386 86400 3600 604800 30 +@ IN SOA rpz.curben.gitlab.io. hostmaster.rpz.curben.gitlab.io. 1618229592 86400 3600 604800 30 NS localhost. 0-24bpautomentes.hu CNAME . @@ -38,7 +38,6 @@ addahealingmusic.com CNAME . adithimedia.com CNAME . adithimedia.memengers.com CNAME . admin.erapor.smk-alasror.net CNAME . -admin.gentbcn.org CNAME . admin.grandoceanvilla.com CNAME . admission.kmctartskuttippuram.org CNAME . adventureexplorer.in CNAME . @@ -54,6 +53,7 @@ aiecons.com CNAME . aiqtest.com CNAME . ajpharmaholding.com CNAME . akdvidyalaya.com CNAME . +al-wahd.com CNAME . alasdemariposas.org CNAME . alberts.diamondrelationscrm.us CNAME . alemelektronik.com CNAME . @@ -91,7 +91,6 @@ aps-sv.com CNAME . artedibujoyarquitectura.com CNAME . arwenyapi.com CNAME . ask-regard.call-save.biz CNAME . -asucssa.live CNAME . atfile.com CNAME . athenacapsg.com CNAME . atlasconcreteworks.com CNAME . @@ -103,15 +102,17 @@ australianpga.com.au CNAME . automaticrefreshments.com CNAME . avadhanagames.com CNAME . aventuramotorhome.com CNAME . +awumad01.top CNAME . +awuqze02.top CNAME . ayahuascasp.com.br CNAME . ayamallah.com CNAME . -aycconsultoriaempresarial.com CNAME . azmeasurement.com CNAME . azraktours.com CNAME . b.r.uce.lee.b.es.t@zytrox.tk CNAME . b2b.toptanakaryakit.com.tr CNAME . backgrounds.pk CNAME . badeggdesign.com CNAME . +bakamla.go.id CNAME . balealgodon.mx CNAME . bangkok-orchids.com CNAME . bangladeshunbound.com CNAME . @@ -132,7 +133,6 @@ beor360.com CNAME . bespokeweddings.ie CNAME . bestcarenepal.com CNAME . betone.co.kr CNAME . -betycopaints.com CNAME . beveragesmiami.solucioneslink.com CNAME . bhavaniengineering.com CNAME . bigmikesupplies.co.za CNAME . @@ -188,12 +188,12 @@ canadianwork.cc CNAME . capitalgroup-kw.com CNAME . capoeiraventrelivre.com CNAME . cashyinvestment.org CNAME . +casiomaneflirt.cf CNAME . catchpoolshetlands.co.uk CNAME . cazyacustomfurniture.com CNAME . cbn.hypervoizd.com CNAME . ccauthority.net CNAME . cdaonline.com.ar CNAME . -cdn-10049480.file.myqcloud.com CNAME . cec.asso.ac-amiens.fr CNAME . cellas.sk CNAME . cendekiabinaaksara.com CNAME . @@ -207,17 +207,17 @@ chinhdropfile.myvnc.com CNAME . chinhdropfile80.myvnc.com CNAME . cible-energy.com CNAME . cifeer.net CNAME . +citiconstructioncorp.com CNAME . citihits.lk CNAME . citssolutions.co.za CNAME . -citycapproperty.ru CNAME . cityglobalgospel.com CNAME . civi.istmejia.com CNAME . cleanbydesignllc.com CNAME . cloud.fc.co.mz CNAME . cnc.tacobelllover.tk CNAME . codsambal.com CNAME . -colinde.pricesne.com CNAME . colorpak.pl CNAME . +columbia.aula-web.net CNAME . community.reimclub.com CNAME . competancy.indigoconsult.net CNAME . conceptimagine.ro CNAME . @@ -227,9 +227,11 @@ constructoralyon.com CNAME . consulateins.solucioneslink.com CNAME . contributeindustry.com CNAME . copelandscapes.com CNAME . +corwin-tommie06f.ru.com CNAME . coulsongraphics.com CNAME . count.mail.163.com.impactmedfoundation.com CNAME . covid19.cyberschool.or.id CNAME . +covid19vaccinations.hopto.org CNAME . cr-sq.com CNAME . craftech.nxtnet.ga CNAME . crearechile.cl CNAME . @@ -292,6 +294,7 @@ dl.1003b.56a.com CNAME . dl.198424.com CNAME . dl.installcdn-aws.com CNAME . dl.packetstormsecurity.net CNAME . +dl.pandasecur.com CNAME . dl.rina-roleplay.com CNAME . dnn.alibuf.com CNAME . dns.alibuf.com CNAME . @@ -348,11 +351,11 @@ endurotanzania.co.tz CNAME . ennovate.elin.co.za CNAME . equimination.ee CNAME . erp.nanotechproautocare.com CNAME . +esaja09.top CNAME . escola.probommar.org.br CNAME . eservices.immigration.gov.lk CNAME . esnconsultants.com CNAME . essentia.org.br CNAME . -ethereality.info CNAME . eubanks7.com CNAME . europeanzonexxi.com CNAME . exilum.com CNAME . @@ -370,7 +373,7 @@ fineartgallerym.com CNAME . fisconline.bar CNAME . fisconline.casa CNAME . fix-america-now.org CNAME . -fixauto.illumetechnology.com CNAME . +fkd.derpcity.ru CNAME . flexypay.dsquaregroup.com CNAME . flintspin.com CNAME . flyingbuddhadesign.com CNAME . @@ -391,7 +394,6 @@ fusionfiresolutions.com CNAME . futbolpr.com CNAME . futuregraphics.com.ar CNAME . g.pinmonkey.xyz CNAME . -gaditastour.com CNAME . gametwogame.com CNAME . garciadogshow.com CNAME . garenanow.myvnc.com CNAME . @@ -421,7 +423,6 @@ goldenasiacapital.com CNAME . goldmen.in CNAME . gpotecnosystems.com CNAME . gracejukes.com CNAME . -greataccesstoserver.com CNAME . grupoinmare.com CNAME . gruposelt.000webhostapp.com CNAME . gs.monerorx.com CNAME . @@ -452,17 +453,13 @@ hitstation.nl CNAME . hmpmall.co.kr CNAME . hoagietesting10.com CNAME . hoayeuthuong-my.sharepoint.com CNAME . -holmesservices.mobiledevsite.co CNAME . homefindersolutions.com CNAME . hometownchick.com CNAME . -hongluosi.com CNAME . hookedupboatclub.com CNAME . hostingparacolombia.com CNAME . hostzaa.com CNAME . -houstonshutters.site CNAME . hr2019.vrcom7.com CNAME . hseda.com CNAME . -hsmwebapp.com CNAME . htownbars.com CNAME . hubtech.co.za CNAME . huellacero.cl CNAME . @@ -510,6 +507,8 @@ isso.ps CNAME . it123.ru CNAME . italiandirezione.casa CNAME . itc-demo.softgig.co.ke CNAME . +itsrlytry.000webhostapp.com CNAME . +jaishomo.info CNAME . jamiekaylive.com CNAME . jamshed.pk CNAME . jansen-heesch.nl CNAME . @@ -537,11 +536,11 @@ kalogirosfinance.com CNAME . kaptaanchapal.com CNAME . karer.by CNAME . katanvetov.co.il CNAME . +katelynn9506a.ru.com CNAME . kensingtondriving.com CNAME . ketofitnessexpert.com CNAME . kevinjewelry.com.co CNAME . keywatch.yourpageserver.com CNAME . -kihn-delaney30gn.ru.com CNAME . kingssa.co.za CNAME . kjcpromo.com CNAME . kleinendeli.co.za CNAME . @@ -549,7 +548,6 @@ korrectconceptservices.com CNAME . krisbadminton.com CNAME . ktb.sch.id CNAME . kubatoglubaklava.com.tr CNAME . -kullumanalitours.com CNAME . kumaralok.in CNAME . kwanfromhongkong.com CNAME . kz.sldov.ru CNAME . @@ -606,7 +604,6 @@ mail.jeffsono.org CNAME . maksi.feb.unib.ac.id CNAME . malaya.tv CNAME . malwarecoding.github.io CNAME . -managed.oss-cn-beijing.aliyuncs.com CNAME . managemysalon.in CNAME . manantialesdelnorte.uy CNAME . manhtien.net CNAME . @@ -649,6 +646,7 @@ michimal2.000webhostapp.com CNAME . microblading.mirliandias.com.br CNAME . microcomm-group.com CNAME . mikhailmotoringschool.com CNAME . +mills-skyla30ec.com CNAME . mingguanwms.com CNAME . minuevavida.org CNAME . mirror.mypage.sk CNAME . @@ -665,6 +663,7 @@ monetization.business CNAME . moninediy.com CNAME . moreirawag.ac.ug CNAME . motorcomunicacion.com CNAME . +moumitas.com CNAME . msacontabil.com.br CNAME . mumgee.co.za CNAME . muzimbiti.xigubo.co.mz CNAME . @@ -714,6 +713,7 @@ nyasabigbullets.com CNAME . nyeh2o.com.au CNAME . obseques-conseils.com CNAME . oecteam.com CNAME . +ohe.ie CNAME . ohsewgorgeous.co.uk CNAME . oleholeh.memangbeda.website CNAME . omaia.org CNAME . @@ -724,7 +724,6 @@ omscoc.pappai.com CNAME . onedigitalcard.granvizionnecorp.com CNAME . onedrive.listifyapp.co CNAME . online.creedglobal.in CNAME . -open.rawntech.com CNAME . open.warehousesaas.co.uk CNAME . opolis.io CNAME . optimus.com.sg CNAME . @@ -799,6 +798,7 @@ prox.realunix.cc CNAME . pujashoppe.in CNAME . punchdialogues.com CNAME . punjabdevelopersassociation.com.pk CNAME . +pvcprinting.co.uk CNAME . qadir.tickfa.ir CNAME . qatarglobalconsulting.com CNAME . qmsled.com CNAME . @@ -825,16 +825,15 @@ readwrite26.nl CNAME . readymmade.com CNAME . recyclethesurplus.com CNAME . redbats.co.in CNAME . +redboxmultimedia.com CNAME . redchillicrackers.com CNAME . reifenquick.de CNAME . -relaxindulge.co.nz CNAME . renehavis.com.ua CNAME . repatriacioncolombia.com CNAME . res.uf1.cn CNAME . reseller.digimitra.in CNAME . reseller.itechbrasil.com CNAME . resuco.net CNAME . -revolet-sa.com CNAME . rezkabum.ru CNAME . rhema.com.sg CNAME . richmondminerals.co.zm CNAME . @@ -849,6 +848,7 @@ romanianpoints.com CNAME . ronnietucker.co.uk CNAME . roomsvc.servegate.kr CNAME . roshnijewellery.com CNAME . +rotronics.com.ph CNAME . rsgym.net CNAME . rubazar.pro CNAME . rubycityvietnam.com CNAME . @@ -877,6 +877,7 @@ scheff.com CNAME . schoolbustracker.softgig.co.ke CNAME . sculetus.nl CNAME . secure-doc-reader.com CNAME . +secure.activedirect.xyz CNAME . segalsmetals.elin.co.za CNAME . sellmyphonela.com CNAME . selltechtoday.com CNAME . @@ -886,7 +887,9 @@ serendibsourcing.com CNAME . sericaasia.com CNAME . servicemhkd.myvnc.com CNAME . servicemhkd80.myvnc.com CNAME . +serviciovirtual.com.ar CNAME . sexologistpakistan.net CNAME . +sgb.ac.ke CNAME . sgessy.com.br CNAME . shaheentbfoundation.com CNAME . shahikhana.cstdevs.com CNAME . @@ -924,7 +927,6 @@ sobariko.com CNAME . sobethuacademy.com CNAME . soft.110route.com CNAME . soft.officelabo.net CNAME . -sogecoenergy.com CNAME . sohs.conceptechs.info CNAME . solar.amazingtribe.lk CNAME . somcorbera.cat CNAME . @@ -938,7 +940,6 @@ spent.com.pl CNAME . spetsesyachtcharter.gr CNAME . spititourism.com CNAME . spittinfire.com CNAME . -springbedspetroleum.com CNAME . src1.minibai.com CNAME . sreenivasapaintingworks.com CNAME . sriglobalit.com CNAME . @@ -949,16 +950,23 @@ st.devcodin.com CNAME . staging.apparelpunch.com CNAME . starcountry.net CNAME . static.3001.net CNAME . +stdynbnbnewagedevixz.dns.army CNAME . +stdynmxwllminoragest.dns.army CNAME . +stdyunitedkesokokgst.dns.army CNAME . +stdyworkfinetraingst.dns.army CNAME . +stdyzgchgcloudgostxs.dns.army CNAME . stiau.iuc.ac CNAME . sticker.jewsjuice.com CNAME . stiepancasetia.ac.id CNAME . stlukesohag.com CNAME . store.ericalgarin.com CNAME . stott-thompson.co.uk CNAME . +stratexec.co.za CNAME . streetdemo.yourpageserver.com CNAME . suboldesign.com CNAME . sumerians.org CNAME . sunaryem.com.tr CNAME . +sunbrero.com.au CNAME . sunmarkholidays.com CNAME . support-4-free.com CNAME . support.clz.kr CNAME . @@ -1037,7 +1045,6 @@ topcell9.com CNAME . toplevel.com.br CNAME . topmask.co.za CNAME . torresquinterocorp.com CNAME . -towme.services CNAME . toyotacollege.ac.th CNAME . tpke.hu CNAME . translaterjemah.com CNAME . @@ -1064,7 +1071,6 @@ union.jctrip.cn CNAME . unyazitelecom.com CNAME . up.llw0.com CNAME . upcbpta.com CNAME . -used-jeans.fr CNAME . useformoney.000webhostapp.com CNAME . uss.ac.th CNAME . uzzepay.com.br CNAME . @@ -1073,7 +1079,6 @@ vbcargo.hu CNAME . vcah.co.uk CNAME . vectarts.com CNAME . vegadelcasero.cl CNAME . -velma-harber30ku.com CNAME . vendas.lidiacarmeli.com.br CNAME . veterinariadrpopui.com CNAME . vfocus.net CNAME . @@ -1089,7 +1094,6 @@ vivationdesign.com CNAME . viveirodoiscorregos.com.br CNAME . vksales.com CNAME . vocalterra.com CNAME . -vokasi.ub.ac.id CNAME . vologroup.com.br CNAME . voteyouramerica.dekitout.com CNAME . vpts.co.za CNAME . @@ -1110,6 +1114,7 @@ webpresario.com CNAME . weinsteincounseling.com CNAME . wfinance.com.br CNAME . whcms.yourpageserver.com CNAME . +whiteglovetailgate.com CNAME . whiteresponse.com CNAME . wi522012.ferozo.com CNAME . wikalen.co.za CNAME . @@ -1139,6 +1144,7 @@ yeichner.com CNAME . yeq.i.u.j.ia.n.3@zytrox.tk CNAME . ylfpremium.com CNAME . yoast.yourpageserver.com CNAME . +yp.hnggzyjy.cn CNAME . yummyyogaudaipur.com CNAME . yzkzixun.com CNAME . ziyker4gaming@zytrox.tk CNAME . diff --git a/urlhaus-filter-rpz.conf b/urlhaus-filter-rpz.conf index ee39e477..b610a33b 100644 --- a/urlhaus-filter-rpz.conf +++ b/urlhaus-filter-rpz.conf @@ -1,12 +1,12 @@ ; Title: Malicious Domains RPZ Blocklist -; Updated: Mon, 12 Apr 2021 00:12:54 UTC +; Updated: Mon, 12 Apr 2021 12:13:00 UTC ; Expires: 1 day (update frequency) ; Homepage: https://gitlab.com/curben/urlhaus-filter ; License: https://gitlab.com/curben/urlhaus-filter#license ; Source: https://urlhaus.abuse.ch/api/ $TTL 30 -@ IN SOA rpz.curben.gitlab.io. hostmaster.rpz.curben.gitlab.io. 1618186386 86400 3600 604800 30 +@ IN SOA rpz.curben.gitlab.io. hostmaster.rpz.curben.gitlab.io. 1618229592 86400 3600 604800 30 NS localhost. 0-24bpautomentes.hu CNAME . @@ -1443,7 +1443,6 @@ $TTL 30 649924.nchsoftwarecom.com CNAME . 64x9bg.ch.files.1drv.com CNAME . 650x.com CNAME . -654tyfcdr4654fytfy.top CNAME . 65k2.com CNAME . 66-gifts.com CNAME . 662ekeep6.com CNAME . @@ -1481,7 +1480,6 @@ $TTL 30 6gue98ddw4220152.freebackup.site CNAME . 6hffgq.dm.files.1drv.com CNAME . 6hu.xyz CNAME . -6ip.us CNAME . 6iptv.com CNAME . 6itokam.com CNAME . 6kd743o1w.com CNAME . @@ -1874,7 +1872,6 @@ a.deadnig.ga CNAME . a.doko.moe CNAME . a.gg.fm CNAME . a.heritageandterre.com CNAME . -a.pomf.cat CNAME . a.pomf.se CNAME . a.pomf.space CNAME . a.pomf.su CNAME . @@ -6588,7 +6585,6 @@ anmingsi.com CNAME . anmocnhien.vn CNAME . anmolanwar.com CNAME . ann141.net CNAME . -anna.websaiting.ru CNAME . annaaluminium.annagroup.net CNAME . annabelle-hamande.be CNAME . annabphotography.co.uk CNAME . @@ -7103,6 +7099,7 @@ app.bigplan-alex.com CNAME . app.boxrcdn.com CNAME . app.bridgeimpex.org CNAME . app.calag.at CNAME . +app.casetabs.com CNAME . app.catholicchurch.co.in CNAME . app.choiphui.com CNAME . app.cloudindustry.net CNAME . @@ -9009,6 +9006,7 @@ atpcsm.be CNAME . atphitech.com CNAME . atpn.ir CNAME . atprofessional.org CNAME . +atpscan.global.hornetsecurity.com CNAME . atr.it CNAME . atradex.com CNAME . atragon.co.uk CNAME . @@ -9769,6 +9767,8 @@ awswx.xyz CNAME . awsxb.xyz CNAME . awsyscloud.com CNAME . awtinfostore.co.business CNAME . +awumad01.top CNAME . +awuqze02.top CNAME . ax-yogado.com CNAME . axalize.vn CNAME . axalta.grupojenrab.mx CNAME . @@ -11166,6 +11166,7 @@ bbfjjf8.com CNAME . bbfr.cba.pl CNAME . bbgiardinodoriente.it CNAME . bbgk.de CNAME . +bbgroup.com.vn CNAME . bbh-design.de CNAME . bbhdata.com CNAME . bbhs.org.ng CNAME . @@ -11605,7 +11606,6 @@ bekurov.org CNAME . bel-med-tour.ru CNAME . belabargelro.com CNAME . belair.btwstudio.ch CNAME . -belairinternet.com CNAME . belamater.com.br CNAME . belangel.by CNAME . belanja-berkah.xyz CNAME . @@ -11724,7 +11724,6 @@ belyi.ug CNAME . belz-development.de CNAME . belznerdesign.de CNAME . bem.fkep.unpad.ac.id CNAME . -bem.hukum.ub.ac.id CNAME . bem.unimal.ac.id CNAME . bemagazine.club CNAME . bemakeup.ru CNAME . @@ -12497,6 +12496,7 @@ bieres.lavachenoiresud.com CNAME . bierne-les-villages.fr CNAME . biese.eu CNAME . bietthubien.org CNAME . +bietthudep902.com CNAME . bietthulambach.com CNAME . bietthulienkegamuda.net CNAME . bietthumau.com CNAME . @@ -16392,7 +16392,6 @@ callonenergy.com CNAME . callpetercatering.com CNAME . callrealtyaz.com CNAME . callshaal.com CNAME . -callsmaster.com CNAME . calltoprimus.ru CNAME . callumstokes.com CNAME . calm-tech.africa CNAME . @@ -17652,7 +17651,6 @@ cdncomfortgroup.website CNAME . cdndownloadlp.club CNAME . cdnmultimedia.com CNAME . cdnpic.mgyun.com CNAME . -cdnrep.reimageplus.com CNAME . cdnxh.net CNAME . cdoconsult.com.br CNAME . cdolechon.com CNAME . @@ -18444,7 +18442,6 @@ cheekie2.neagoeandrei.com CNAME . cheematransxpressinc.com CNAME . cheerchile.cl CNAME . cheerfulgiversneverlack.com CNAME . -cheerfullydo.com CNAME . cheesecakery.com.br CNAME . cheetahridge.mediadevstaging.com CNAME . chef-solutions.dreamscape.co.in CNAME . @@ -19375,6 +19372,7 @@ clarrywillow.top CNAME . clarte-thailand.com CNAME . clashofclansgems.nl CNAME . clasificados.diaadianews.com CNAME . +clasificadosmaule.com CNAME . class.britishonline.co CNAME . class.snph.ir CNAME . classbrain.net CNAME . @@ -19672,6 +19670,7 @@ clntnjkstdycloudstcy.dns.army CNAME . cloakingtds.xyz CNAME . clock.noixun.com CNAME . clodflarechk.com CNAME . +clodura.ai CNAME . clone.affordable.cm CNAME . clone.system-standex.dk CNAME . cloned.in CNAME . @@ -19857,7 +19856,6 @@ cmeaststar.de CNAME . cmecobrancas.com CNAME . cmelik.com CNAME . cmessagers.com CNAME . -cmg.asia CNAME . cmg.ma CNAME . cmgroup.com.ua CNAME . cmhighschool.edu.bd CNAME . @@ -22396,7 +22394,6 @@ cuacuonsieure.com CNAME . cuadros.pe CNAME . cuahangphongthuy.net CNAME . cuahangstore.com CNAME . -cuahangvattu.com CNAME . cualtis.com CNAME . cuanhomxingfanhapkhau.com CNAME . cuasotinhoc.net CNAME . @@ -22825,6 +22822,7 @@ d.powerofwish.com CNAME . d.qiluwl.com CNAME . d.teamworx.ph CNAME . d.techmartbd.com CNAME . +d.top4top.io CNAME . d.top4top.net CNAME . d.ttr3p.com CNAME . d04.data39.helldata.com CNAME . @@ -24806,6 +24804,7 @@ deportetotal.mx CNAME . deposayim.ml CNAME . depositoclara.com.br CNAME . depot7.com CNAME . +depozituldegeneratoare.ro CNAME . depraetere.net CNAME . deprealty.ru CNAME . depressionted.com CNAME . @@ -26532,7 +26531,6 @@ dl-45538429.onedrives-en-live.com CNAME . dl-675423.store-downloads.com CNAME . dl-80076342.md-downloads.com CNAME . dl-97674424.md-downloads.com CNAME . -dl-gameplayer.dmm.com CNAME . dl-link.link CNAME . dl-link.live CNAME . dl-link.network CNAME . @@ -26555,9 +26553,9 @@ dl.ikiki.cn CNAME . dl.imht.ir CNAME . dl.installcdn-aws.com CNAME . dl.mqego.com CNAME . -dl.mydown.com CNAME . dl.ossdown.fun CNAME . dl.packetstormsecurity.net CNAME . +dl.pandasecur.com CNAME . dl.popupgrade.com CNAME . dl.repairlabshost.com CNAME . dl.rina-roleplay.com CNAME . @@ -26734,6 +26732,9 @@ dobrojutrodjevojke.com CNAME . dobroviz.com.ua CNAME . dobrovorot.su CNAME . dobsoncentral.com CNAME . +doc-0s-7c-docs.googleusercontent.com CNAME . +doc-10-0c-docs.googleusercontent.com CNAME . +doc-10-8s-docs.googleusercontent.com CNAME . doc-hub.healthycheapfast.com CNAME . doc-japan.com CNAME . doc.albaspizzaastoria.com CNAME . @@ -29008,6 +29009,7 @@ ec2-52-56-233-157.eu-west-2.compute.amazonaws.com CNAME . ec2-54-207-92-161.sa-east-1.compute.amazonaws.com CNAME . ec2-54-212-231-68.us-west-2.compute.amazonaws.com CNAME . ec2-54-94-215-87.sa-east-1.compute.amazonaws.com CNAME . +ec2euc1.boxcloud.com CNAME . ec2test.ga CNAME . ec3-design.com CNAME . ecadigital.com CNAME . @@ -31308,6 +31310,7 @@ es.thevoucherstop.com CNAME . esaarc.com CNAME . esacbd.com CNAME . esagarautomobiles.com CNAME . +esaja09.top CNAME . esanjobs.org CNAME . esar.weenets.com CNAME . esascom.com CNAME . @@ -37102,7 +37105,6 @@ genregis.com CNAME . genrjw.dm.files.1drv.com CNAME . genstaff.gov.kg CNAME . gentcreativa.com CNAME . -gentecoyol.com CNAME . gentesanluis.com CNAME . gentiane-salers.com CNAME . gentlechirocenter.com CNAME . @@ -39851,6 +39853,7 @@ gvou7g.by.files.1drv.com CNAME . gvpcdpgc.edu.in CNAME . gvpmacademy.co.za CNAME . gvsme.com CNAME . +gw.daelimcloud.com CNAME . gw.hitlin.com CNAME . gwangjuhotels.kr CNAME . gwavellc.com CNAME . @@ -42662,7 +42665,6 @@ hotelvip-bron.ru CNAME . hotelwaldblick.com CNAME . hotexpress.co CNAME . hotfacts.org CNAME . -hotgifts.online CNAME . hotilife.com CNAME . hotissue.xyz CNAME . hotkine.com CNAME . @@ -43040,7 +43042,6 @@ hukouec-ltd.com CNAME . hukuen-motokare.xyz CNAME . hukuki.site CNAME . hukukportal.com CNAME . -hukum.ub.ac.id CNAME . hukum.unwiku.ac.id CNAME . hulianwang114.com CNAME . huliot.in CNAME . @@ -43362,6 +43363,7 @@ i-sharecloud.com CNAME . i-supportcharity.com CNAME . i-vnsweyu.pl CNAME . i-voda.com CNAME . +i.fiery.me CNAME . i.fluffy.cc CNAME . i.funtourspt.eu CNAME . i.n.t.e.rloca.l.qs.j.y@jfas.top CNAME . @@ -46642,6 +46644,7 @@ itspread.com CNAME . itspsc.com.ua CNAME . itspueh.nl CNAME . itsquare.yrcreations.com CNAME . +itsrlytry.000webhostapp.com CNAME . itssprout.com CNAME . itstelecom.com.br CNAME . itsweezle.com CNAME . @@ -46841,6 +46844,7 @@ j-skill.ru CNAME . j-stage.jp CNAME . j-toputvoutfitters.com CNAME . j.kyryl.ru CNAME . +j.top4top.io CNAME . j11g9xecuxe43xu.xyz CNAME . j12z7407gwtzk.xyz CNAME . j13.biz CNAME . @@ -46973,6 +46977,7 @@ jaipurjungle.co.in CNAME . jaipurweddingphotography.com CNAME . jairathsnatural.ca CNAME . jairozapata.000webhostapp.com CNAME . +jaishomo.info CNAME . jaishritours.com CNAME . jaiswalsupplement.com CNAME . jajadomains.com CNAME . @@ -51001,7 +51006,6 @@ kodiakpro.ca CNAME . kodim0112sabang.com CNAME . kodingeko.com CNAME . kodip.nfile.net CNAME . -kodjdsjsdjf.tk CNAME . kodlacan.site CNAME . kodmuje.com CNAME . kodolios.000webhostapp.com CNAME . @@ -53641,6 +53645,7 @@ library.arihantmbainstitute.ac.in CNAME . library.cifor.org CNAME . library.dhl-xom.com CNAME . library.iainbengkulu.ac.id CNAME . +library.mju.ac.th CNAME . library.phibi.my.id CNAME . library.piet.co.in CNAME . library.strophicmusic.com CNAME . @@ -54327,7 +54332,6 @@ livechallenge.fr CNAME . livecigarevent.com CNAME . livecricketscorecard.info CNAME . livedaynews.com CNAME . -livedemo00.template-help.com CNAME . livedownload.in CNAME . livedrumtracks.com CNAME . livefarma.com CNAME . @@ -54360,7 +54364,6 @@ livesouvenir.com CNAME . livestreams.vn CNAME . livesuitesapartdaire.com CNAME . livesurgerycourse.ir CNAME . -liveswinburneeduau-my.sharepoint.com CNAME . liveswindow.casa CNAME . liveswindow.cyou CNAME . liveswindows.bar CNAME . @@ -55535,7 +55538,6 @@ luzbarbosa.com.br CNAME . luzconsulting.com.br CNAME . luzevida.com.br CNAME . luzfloral.com CNAME . -luzy.vn CNAME . luzzeri.com CNAME . lvajnczdy.cf CNAME . lvcfund.org.vn CNAME . @@ -58573,7 +58575,6 @@ mecflui.com.br CNAME . mecgwl.ac.in CNAME . mechanicaltools.club CNAME . mechanicsthatcometoyou.com CNAME . -mecharnise.ir CNAME . mechathrones.com CNAME . mechauto.co.za CNAME . mechdesign.com CNAME . @@ -59159,7 +59160,6 @@ menxhiqi.com CNAME . menziesadvisory-my.sharepoint.com CNAME . menzway.com CNAME . meogiambeo.com CNAME . -meohaybotui.com CNAME . meolamdephay.com CNAME . mepsgen.com CNAME . mera.ddns.net CNAME . @@ -59477,6 +59477,7 @@ mfmr.gov.sl CNAME . mfomjr.com CNAME . mfotovideo.ro CNAME . mfpburundi.bi CNAME . +mfpc.org.my CNAME . mfppanel.xyz CNAME . mfpvision.com CNAME . mfronza.com.br CNAME . @@ -64509,7 +64510,6 @@ nhadatphonglinh.com CNAME . nhadatquan2.xyz CNAME . nhadatthienthoi.com CNAME . nhadephungyen.com CNAME . -nhadepkientruc.net CNAME . nhahangdaihung.com CNAME . nhahanghaivuong.vn CNAME . nhahanglegiang.vn CNAME . @@ -64723,7 +64723,6 @@ nikanbearing.com CNAME . nikanpolimer.ir CNAME . nikastroi.ru CNAME . nikavkuchyni.sk CNAME . -nikayu.com CNAME . nikbox.ru CNAME . nikeshyadav.com CNAME . nikhil.webscript.co.in CNAME . @@ -67239,7 +67238,6 @@ optimusforce.nl CNAME . option47.us CNAME . optioncapitalgroup.ru CNAME . optionrp.com CNAME . -optionscity.com CNAME . optisaving.com CNAME . optitechsa.co.za CNAME . optocen.ru CNAME . @@ -67534,7 +67532,6 @@ osethmaayurveda.com CNAME . osezrayonner.ma CNAME . osgbforum.com CNAME . oshattorney.com CNAME . -oshi.at CNAME . oshodrycleaning.com CNAME . oshonafitness.com CNAME . oshop.es CNAME . @@ -71234,7 +71231,6 @@ posmaster.co.kr CNAME . posmicrosystems.com CNAME . posnxqmp.ru CNAME . pospeeps.com CNAME . -posqit.net CNAME . possessionnow.com CNAME . possible.re CNAME . possopagar.com.br CNAME . @@ -71870,7 +71866,6 @@ prishaartcreations.com CNAME . prisidmart.com CNAME . priskat.net CNAME . prism-photo.com CNAME . -prisma.fp.ub.ac.id CNAME . prismaxis.com CNAME . prismfox.com CNAME . prismware.ml CNAME . @@ -72462,6 +72457,7 @@ protech.binarybizz.com CNAME . protech.mn CNAME . protechcarpetcare.com CNAME . protechgroup1.com CNAME . +protect.mimecast-offshore.com CNAME . protectiadatelor.biz CNAME . protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org CNAME . protection.pecol.eu CNAME . @@ -72543,6 +72539,7 @@ proxima-solution.com CNAME . proxy-ipv4.com CNAME . proxy.2u0apcm6ylhdy7s.com CNAME . proxy.hueaudio.com CNAME . +proxy.qualtrics.com CNAME . proxygrnd.xyz CNAME . proxyholding.com CNAME . proxyresume.com CNAME . @@ -75056,6 +75053,7 @@ redlk.com CNAME . redlogisticsmaroc.com CNAME . redloop.io CNAME . redlotusevents.com CNAME . +redm1az1.000webhostapp.com CNAME . redmag.by CNAME . redmarcial.ossmarcial.com CNAME . redmediasigns.com CNAME . @@ -76227,6 +76225,7 @@ rkbicycle.com CNAME . rkcable.co.in CNAME . rkfplumbing.co.uk CNAME . rkinstitute.org CNAME . +rkkrstdygorgiousejbg.dns.army CNAME . rkkrstdygorgiousejds.dns.army CNAME . rkkrstdygorgiousejtw.dns.army CNAME . rklkpgcollege.com CNAME . @@ -76783,6 +76782,7 @@ rotiyes.co.id CNAME . rotoblast.org CNAME . rotor.olsztyn.pl CNAME . rotoscoop.com CNAME . +rotronics.com.ph CNAME . rott-mtr.de CNAME . rotterdammeetings.nl CNAME . rotulosalarcon.com CNAME . @@ -77196,7 +77196,6 @@ runmagazine.es CNAME . runmureed.com CNAME . runmyweb.com CNAME . runnected.kaiman.fr CNAME . -runnerbd.com CNAME . runnerschool.com CNAME . running-bike.com CNAME . runningcrewteam.com CNAME . @@ -78718,6 +78717,7 @@ savemodificationgloballyfromthepinaltypo.duckdns.org CNAME . savemyfile.3utilities.com CNAME . savemyseatnow.com CNAME . saveraahealthcare.com CNAME . +saveserpnow.com CNAME . saveserpresults.com CNAME . savestudio.com CNAME . savetax.idfcmf.com CNAME . @@ -79395,6 +79395,7 @@ secure-net.tech CNAME . secure-risk.namaskara.me CNAME . secure-snupa.com CNAME . secure.accounts.resourses.com CNAME . +secure.activedirect.xyz CNAME . secure.anchorssb.co CNAME . secure.app-amazon.com.recovery-account.amazon.com.alphatravelmongolia.com CNAME . secure.bodybuilderabs.net CNAME . @@ -80072,7 +80073,6 @@ service.atlink.ir CNAME . service.dawat.fr CNAME . service.drnjithendran.com CNAME . service.eftformotherissues.com CNAME . -service.ezsoftwareupdater.com CNAME . service.heritageimagingcenter.com CNAME . service.hybridhomesteam.com CNAME . service.idealfurnitureoutlet.com CNAME . @@ -80577,6 +80577,7 @@ shareallfilesthroughsecureexchangesystem.duckdns.org CNAME . sharebook.tk CNAME . sharechautari.com CNAME . shared-cnd.com CNAME . +shared.outlook.inky.com CNAME . shareddocuments.ml CNAME . shareddynamics.com CNAME . sharedeconomy.eu CNAME . @@ -84940,9 +84941,11 @@ stdymjventsluzcafoik.dns.army CNAME . stdymjventsluzcafsrp.dns.army CNAME . stdymorcmmylntwincdq.dns.army CNAME . stdymorcmmylntwinstr.dns.army CNAME . +stdynbnbnewagedevixz.dns.army CNAME . stdynbnbnewagedevsmn.dns.army CNAME . stdynbnbnewagedevxaz.dns.army CNAME . stdyneverwalkachinese2loneinlifekstgqm.ydns.eu CNAME . +stdynmxwllminoragest.dns.army CNAME . stdyperezluzcafeyzst.dns.navy CNAME . stdypmrimelimtwstogy.dns.army CNAME . stdypycsslwinnerscot.dns.army CNAME . @@ -84973,6 +84976,7 @@ stdytoprehtwoyertwfd.dns.army CNAME . stdytopreoneenversrw.dns.army CNAME . stdytopreoneenvervaj.dns.army CNAME . stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu CNAME . +stdyunitedkesokokgst.dns.army CNAME . stdyunitedkesokostdr.dns.army CNAME . stdyunitedkesokostri.dns.navy CNAME . stdyunitedkesokostxc.dns.army CNAME . @@ -84982,7 +84986,9 @@ stdyworkfineanotherrainbowlomoyentstbmd.duckdns.org CNAME . stdyworkfineanotherrainbowlomoyentwkgls.duckdns.org CNAME . stdyworkfinesanotherrainbowlomoyentstfcp.ydns.eu CNAME . stdyworkfinesanotherrainbowlomoyentstgot.ydns.eu CNAME . +stdyworkfinetraingst.dns.army CNAME . stdyzgchgcloudgostgt.dns.army CNAME . +stdyzgchgcloudgostxs.dns.army CNAME . steadyrestmanufacturers.com CNAME . steak.wpress.dk CNAME . steakhouse.com.ua CNAME . @@ -85542,6 +85548,7 @@ strend.net CNAME . strengthandvigour.com CNAME . strengthrer.com CNAME . strenover.ga CNAME . +stressing.pw CNAME . stressnada.com CNAME . stretchpilates.fit CNAME . strewn.org CNAME . @@ -86233,6 +86240,7 @@ supercrystal.am CNAME . supercutscissors.com CNAME . superdad.id CNAME . superdigitalguy.xyz CNAME . +superdomain1709.info CNAME . superdot.rs CNAME . superecruiters.com CNAME . superfacil.center CNAME . @@ -86336,7 +86344,6 @@ support.m2mservices.com CNAME . support.mdsol.com CNAME . support.nordenrecycling.com CNAME . support.nuvemit.com CNAME . -support.pubg.com CNAME . support.redbook.aero CNAME . support.revolus.xyz CNAME . support.servu.co.uk CNAME . @@ -86681,7 +86688,6 @@ swiat-ksiegowosci.pl CNAME . swicoservers.co.uk CNAME . swieradowbiega.pl CNAME . swifck.xmr.ac CNAME . -swift-cloud.com CNAME . swiftbusinesspay.com CNAME . swiftee.co.uk CNAME . swiftender.com CNAME . @@ -87526,7 +87532,6 @@ tarexfinal.trade CNAME . targas.de CNAME . targat-china.com CNAME . target-events.com CNAME . -target-support.online CNAME . target2cloud.com CNAME . targetbizbd.com CNAME . targetcm.net CNAME . @@ -89107,7 +89112,6 @@ thacci.com.br CNAME . thachastew.com CNAME . thachvietstone.com CNAME . thadathilfarmresort.com CNAME . -thaddeusarmstrong.com CNAME . thadinnoo.co CNAME . thagreymatter.com CNAME . thai-chana.asia CNAME . @@ -90829,7 +90833,6 @@ tlcc.com.gt CNAME . tlcid.org CNAME . tlckids-or.ga CNAME . tlcmoto.com CNAME . -tldrbox.top CNAME . tldrnet.top CNAME . tlextreme.com CNAME . tlfthelifefactory.com.au CNAME . @@ -92426,6 +92429,7 @@ ts-deals.me CNAME . ts.7rb.xyz CNAME . ts0ev73.com CNAME . tsal.com CNAME . +tsapparel.com.my CNAME . tsareva-garden.ru CNAME . tsatsi.co.za CNAME . tsauctions.com CNAME . @@ -92653,6 +92657,7 @@ tunnelpros.com CNAME . tunnelview.co.uk CNAME . tunuvo.com CNAME . tuobrasocial.com.ar CNAME . +tuoitrethainguyen.vn CNAME . tupibaje.com CNAME . tupperware.michaelroberge.ca CNAME . tur.000webhostapp.com CNAME . @@ -93799,7 +93804,6 @@ unlimit517.co.jp CNAME . unlimited.nu CNAME . unlimitedbags.club CNAME . unlimitedfreightco.com CNAME . -unlimitedimportandexport.com CNAME . unlock-king.com CNAME . unlock2.neagoeandrei.com CNAME . unlockall.neagoeandrei.com CNAME . @@ -94125,6 +94129,7 @@ url-update.com CNAME . url-validation-clients.com CNAME . url.246546.com CNAME . url.57569.fr.snd52.ch CNAME . +url2.mailanyone.net CNAME . url3.mailanyone.net CNAME . url5459.41southbar.com CNAME . url675.textilmallorca.com CNAME . @@ -94328,7 +94333,6 @@ utterstock.in CNAME . utting.org CNAME . utv.sakeronline.se CNAME . utv1.enliden.net CNAME . -uujian.cn CNAME . uumove.com CNAME . uurty87e8rt7rt.com CNAME . uutiset.helppokoti.fi CNAME . @@ -96302,7 +96306,6 @@ voin.staysafe.pk CNAME . voingani.it CNAME . voip96.ru CNAME . voipminic.com CNAME . -vokasi.ub.ac.id CNAME . vokzalrf.ru CNAME . vol.agency CNAME . vol2.pw CNAME . @@ -96930,7 +96933,6 @@ washnworks.com CNAME . washuis.nl CNAME . wasidora.com CNAME . wasilewski-online.de CNAME . -wasimjee.com CNAME . wasino.co.th CNAME . wasobd.net CNAME . waspha.com CNAME . @@ -98470,7 +98472,6 @@ woaldi2.com CNAME . woatinkwoo.com CNAME . woclawoffers.fun CNAME . wocomm.marketingmindz.com CNAME . -wodfitapparel.fr CNAME . wodmetaldom.pl CNAME . wodsuit.com CNAME . woelf.in CNAME . @@ -101099,7 +101100,9 @@ yoyoplease.com CNAME . yoyoso.nz CNAME . yoyoteacher.cn CNAME . yp.dcyazilim.com CNAME . +yp.hnggzyjy.cn CNAME . ypbb.or.id CNAME . +ypddf.org CNAME . ypicsdy.cf CNAME . ypko-55.gq CNAME . ypom.com.br CNAME . @@ -101258,7 +101261,6 @@ yusukelife.com CNAME . yuti.kr CNAME . yuvann.com CNAME . yuvikadvertisments.com CNAME . -yuwaraja.vokasi.ub.ac.id CNAME . yuweis.com CNAME . yuxigon.com CNAME . yuxuanknit.com CNAME . diff --git a/urlhaus-filter-snort2-online.rules b/urlhaus-filter-snort2-online.rules index 5d1bcb15..6004a13e 100644 --- a/urlhaus-filter-snort2-online.rules +++ b/urlhaus-filter-snort2-online.rules @@ -1,5 +1,5 @@ # Title: Online Malicious URL Snort2 Ruleset -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -39,38 +39,38 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000033; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000034; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000035; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000036; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000037; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000038; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000039; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000040; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000041; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000042; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000043; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000044; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000045; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000046; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000047; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000048; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000049; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100000050; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000051; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000052; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000053; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000054; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000055; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.247.221.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000056; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.247.221.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000057; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.250.159.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000058; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.65.166.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000059; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.82.104.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000060; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.12.184.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000061; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.12.51.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000062; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.8.77.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000063; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1008691.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100000064; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.129.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000065; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.130.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000066; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.131.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000067; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000036; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000037; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000038; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000039; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000040; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000041; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000042; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000043; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000044; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000045; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000046; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000047; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000048; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100000049; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000050; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000051; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000052; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000053; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000054; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.247.221.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000055; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.247.221.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000056; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.250.159.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000057; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.65.166.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000058; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.82.104.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000059; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.12.184.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000060; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.12.51.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000061; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.8.77.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000062; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1008691.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100000063; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.129.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000064; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.130.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000065; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.131.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000066; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.138.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000067; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.16.183.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000068; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.229.85.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000069; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.255.36.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000070; rev:1;) @@ -78,402 +78,402 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.218.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000072; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.76.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000073; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.75.157.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000074; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.130.115.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000075; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.141.240.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000076; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.113.99.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000077; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.136.82.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000078; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.16.145.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000079; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.204.168.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000080; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.217.215.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000081; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.219.152.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000082; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.224.200.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000083; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.224.200.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000084; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.227.118.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000085; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.237.21.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000086; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.238.228.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000087; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.249.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000088; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.4.117.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000089; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.47.104.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000090; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.99.91.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000075; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.99.94.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000076; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.130.115.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000077; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.141.240.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000078; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.113.99.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000079; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.136.82.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000080; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.16.145.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000081; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.204.168.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000082; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.217.215.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000083; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.219.152.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000084; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.224.200.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000085; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.224.200.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000086; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.227.118.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000087; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.237.21.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000088; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.238.228.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000089; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.249.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000090; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.79.112.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000091; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.98.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000092; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.81.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000092; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.240.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000093; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.241.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000094; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000095; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000096; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000097; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000098; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000099; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000100; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000101; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000102; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000103; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000104; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000105; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000106; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.168.44.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000107; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.184.75.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000108; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.206.93.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000109; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.33.52.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000110; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.61.86.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000111; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.1.111.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000112; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.172.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000113; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.193.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000114; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.105.33.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000115; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.104.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000116; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.141.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000117; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.249.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000118; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000119; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.23.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000120; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.24.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000121; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.61.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000122; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.197.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000123; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.33.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000124; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.181.136.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000125; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.194.242.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000126; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.219.185.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000127; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.220.119.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000128; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.221.96.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000129; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.201.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000130; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.250.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000131; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.239.155.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000132; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.249.194.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000133; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.104.151.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000134; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.124.90.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000135; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.233.196.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000136; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.235.7.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000137; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.86.85.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000138; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000139; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000140; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.127.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000141; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.57.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000142; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.99.37.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000143; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.14.58.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000144; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.182.102.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000145; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.182.126.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000146; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.187.229.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000147; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.124.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000148; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.175.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000149; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.251.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000150; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.251.10.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000151; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.213.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000152; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.208.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000153; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.209.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000154; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.223.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000155; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.225.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000156; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.235.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000157; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.4.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000158; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.88.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000159; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.88.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000160; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.119.245.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000161; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.125.67.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000162; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.86.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000163; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.172.57.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000164; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.182.237.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000165; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.171.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000166; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.177.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000167; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.23.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000168; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.230.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000169; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.27.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000170; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.49.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000171; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000172; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000173; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000174; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000175; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000176; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000177; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000178; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000179; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000180; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000181; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000182; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.108.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000183; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.133.222.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000184; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.124.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000185; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.233.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000186; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.210.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000187; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.96.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000188; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.187.91.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000189; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.214.127.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000190; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.187.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000191; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.236.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000192; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.239.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000193; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.43.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000194; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.162.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000195; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.180.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000196; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.230.168.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000197; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.232.0.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000198; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.141.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000199; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.144.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000200; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.75.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000201; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.99.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000202; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.143.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000203; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.190.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000204; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.227.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000205; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.39.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000206; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.239.101.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000207; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.240.216.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000208; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.12.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000209; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.8.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000210; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.126.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000211; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.162.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000212; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.100.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000213; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.16.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000214; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.191.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000215; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.214.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000216; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.240.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000217; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.82.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000218; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000219; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.63.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000220; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.109.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000221; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.118.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000222; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.102.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000223; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.218.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000224; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.128.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000225; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.221.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000226; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.6.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000227; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.8.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000228; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000229; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000230; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000231; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000232; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000233; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000234; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000235; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000236; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000237; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000238; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000239; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000240; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000241; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000242; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.125.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000243; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.127.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000244; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.80.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000245; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.81.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000246; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.82.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000247; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000248; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.85.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000249; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.87.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000250; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.88.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000251; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000252; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000253; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000254; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000255; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000256; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000257; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000258; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000259; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000260; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000261; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000262; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000263; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000264; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000265; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000266; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000267; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000268; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000269; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000270; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000271; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000272; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.35.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000273; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000274; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000275; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000276; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000277; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000278; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000279; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000280; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000281; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000282; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.0.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000283; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.177.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000284; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.211.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000285; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.216.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000286; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.240.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000287; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.224.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000288; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.227.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000289; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.65.53.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000290; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000291; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.175.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000292; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000293; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.226.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000294; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.215.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000295; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.146.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000296; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.224.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000297; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.93.29.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000298; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.11.95.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000299; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.118.249.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000300; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.122.238.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000301; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.13.241.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000302; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.58.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000303; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.78.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000304; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.230.86.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000305; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.184.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000306; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.211.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000307; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.254.169.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000308; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.128.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000309; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.149.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000310; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.154.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000311; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.180.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000312; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.191.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000313; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.61.204.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000314; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.65.10.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000315; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.153.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000316; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.192.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000317; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.89.43.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000318; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.199.204.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000319; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.199.253.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000320; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.201.201.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000321; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.224.203.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000322; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.30.54.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000323; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.35.254.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000324; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.79.172.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000325; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.165.216.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000326; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.171.204.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000327; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.42.47.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000328; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.140.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000329; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.77.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000330; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.106.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000331; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.53.203.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000332; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.241.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000333; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.156.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000334; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.131.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000335; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.133.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000336; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.155.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000337; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.178.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000338; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.182.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000339; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.182.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000340; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.111.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000341; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.132.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000342; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.203.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000343; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.214.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000344; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.233.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000345; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.252.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000346; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.110.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000347; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.73.3.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000348; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.75.217.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000349; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.88.133.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000350; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.92.174.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000351; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.97.139.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000352; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.124.219.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000353; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.206.164.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000354; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.211.100.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000355; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000356; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000357; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.210.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000358; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.243.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000359; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.201.205.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000360; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.251.59.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000361; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.26.124.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000362; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.113.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000363; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.53.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000364; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.86.105.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000365; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.101.7.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000366; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.104.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000367; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.157.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000368; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.7.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000369; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.32.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000370; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.5.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000371; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.72.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000372; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.12.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000373; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.128.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000374; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.208.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000375; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.209.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000376; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.214.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000377; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.88.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000378; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000379; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000380; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.165.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000381; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.221.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000382; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.63.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000383; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.65.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000384; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.42.125.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000385; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.43.180.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000386; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.218.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000387; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.50.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000388; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.74.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000389; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.91.41.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000390; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.179.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000391; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.183.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000392; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.239.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000393; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.14.143.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000394; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.147.213.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000395; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.18.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000396; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.218.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000397; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.107.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000398; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.241.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000399; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.27.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000400; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.68.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000401; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.97.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000402; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.26.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000403; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.177.147.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000404; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.248.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000405; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.43.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000406; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.58.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000407; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.18.38.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000408; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.106.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000409; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.119.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000410; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.182.97.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000411; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.172.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000412; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.15.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000413; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.195.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000414; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.245.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000415; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.137.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000416; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.227.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000417; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.187.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000418; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.215.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000419; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.240.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000420; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.255.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000421; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.204.30.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000422; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.250.129.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000423; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.105.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000424; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.131.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000425; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000426; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000427; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.148.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000428; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.155.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000429; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.166.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000430; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.96.38.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000431; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.132.113.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000432; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.15.69.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000433; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000434; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000435; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000436; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000437; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.207.39.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000438; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.25.204.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000439; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.70.108.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000440; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.0.255.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000441; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.1.54.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000442; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.142.222.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000443; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.150.213.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000444; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.151.248.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000445; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000446; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000447; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000448; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000449; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000450; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000451; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000452; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000453; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000454; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000455; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000456; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000457; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000458; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000459; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000460; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000461; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000462; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.99.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000463; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.66.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000464; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.93.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000465; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.57.123.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000466; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.8.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000467; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.7.75.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000468; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.83.79.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000469; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.172.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000470; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000096; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000097; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000098; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000099; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000100; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000101; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.97.184.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000102; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.184.75.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000103; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.206.93.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000104; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.33.52.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000105; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.61.86.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000106; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.1.111.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000107; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.172.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000108; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.193.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000109; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.105.33.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000110; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.104.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000111; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.141.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000112; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.156.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000113; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.249.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000114; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000115; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.23.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000116; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.24.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000117; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.61.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000118; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.197.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000119; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.33.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000120; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.181.136.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000121; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.194.242.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000122; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.219.185.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000123; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.220.119.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000124; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.221.96.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000125; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.201.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000126; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.250.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000127; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.239.155.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000128; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.249.194.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000129; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.124.90.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000130; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.233.196.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000131; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.235.7.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000132; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.248.58.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000133; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.86.85.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000134; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000135; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000136; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.127.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000137; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.57.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000138; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.99.37.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000139; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.14.58.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000140; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.182.102.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000141; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.182.126.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000142; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.187.229.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000143; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.124.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000144; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.175.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000145; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.251.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000146; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.251.10.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000147; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.213.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000148; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.145.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000149; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.208.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000150; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.221.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000151; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.235.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000152; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.249.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000153; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.4.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000154; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.89.10.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000155; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.88.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000156; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.119.245.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000157; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.125.67.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000158; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.86.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000159; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.172.57.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000160; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.182.237.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000161; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.171.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000162; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.177.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000163; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.23.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000164; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.230.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000165; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.27.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000166; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.49.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000167; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000168; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000169; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000170; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000171; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000172; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000173; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000174; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000175; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.108.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000176; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.133.222.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000177; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.124.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000178; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.233.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000179; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.210.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000180; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.96.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000181; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.187.91.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000182; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.214.127.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000183; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.187.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000184; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.236.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000185; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.239.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000186; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.43.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000187; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.162.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000188; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.180.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000189; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.230.168.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000190; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.232.0.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000191; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.141.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000192; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.143.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000193; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.190.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000194; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.39.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000195; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.239.101.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000196; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.240.216.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000197; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.12.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000198; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.8.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000199; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.126.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000200; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.162.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000201; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.100.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000202; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.16.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000203; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.191.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000204; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.214.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000205; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.240.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000206; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.82.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000207; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.109.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000208; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000209; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.63.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000210; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.109.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000211; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.118.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000212; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.102.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000213; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.218.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000214; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.128.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000215; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.221.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000216; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.6.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000217; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.8.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000218; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000219; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000220; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000221; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000222; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000223; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000224; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000225; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000226; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000227; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000228; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000229; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000230; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000231; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000232; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000233; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.125.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000234; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.127.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000235; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.80.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000236; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.81.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000237; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.82.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000238; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000239; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.85.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000240; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.87.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000241; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.88.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000242; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000243; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000244; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000245; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000246; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000247; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000248; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000249; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000250; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000251; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000252; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000253; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000254; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000255; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000256; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000257; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000258; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000259; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000260; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000261; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000262; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000263; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000264; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.35.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000265; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000266; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000267; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000268; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000269; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000270; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000271; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000272; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.0.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000273; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.177.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000274; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.216.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000275; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.224.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000276; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.227.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000277; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.65.53.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000278; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000279; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000280; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.175.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000281; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000282; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000283; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.226.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000284; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.215.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000285; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.146.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000286; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.224.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000287; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.9.155.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000288; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.93.29.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000289; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.11.95.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000290; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.118.249.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000291; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.122.238.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000292; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.13.241.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000293; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.58.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000294; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.78.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000295; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.194.131.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000296; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.194.135.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000297; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.226.42.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000298; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.230.86.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000299; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.184.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000300; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.211.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000301; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.254.169.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000302; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.128.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000303; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.136.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000304; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.144.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000305; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.149.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000306; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.191.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000307; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.61.204.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000308; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.65.10.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000309; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.123.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000310; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.228.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100000311; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.89.43.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000312; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.199.253.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000313; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.201.201.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000314; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.224.203.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000315; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.30.54.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000316; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.79.172.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000317; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.165.216.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000318; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.171.204.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000319; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.42.47.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000320; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.232.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000321; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.172.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000322; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.2.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000323; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.106.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000324; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.91.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000325; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.53.203.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000326; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.212.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000327; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.156.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000328; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.7.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000329; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.131.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000330; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.133.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000331; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.155.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000332; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.214.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000333; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.233.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000334; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.252.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000335; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.110.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000336; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.167.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000337; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.172.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000338; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.26.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000339; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.73.3.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000340; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.75.217.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000341; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.88.133.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000342; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.92.174.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000343; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.108.92.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000344; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.124.219.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000345; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.206.164.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000346; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.211.100.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000347; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.162.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000348; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000349; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000350; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.210.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000351; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.220.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000352; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.243.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000353; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.201.205.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000354; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.64.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000355; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.12.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000356; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.47.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000357; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.9.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000358; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.215.249.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000359; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.173.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000360; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.175.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000361; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.242.208.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000362; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.247.201.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000363; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.26.124.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000364; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.113.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000365; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.133.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000366; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.53.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000367; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.86.105.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000368; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.101.7.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000369; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.104.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000370; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.157.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000371; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.7.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000372; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.32.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000373; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.5.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000374; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.72.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000375; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.12.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000376; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.128.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000377; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.208.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000378; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.209.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000379; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.214.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000380; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.88.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000381; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000382; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000383; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.165.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000384; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.221.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000385; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.63.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000386; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.65.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000387; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.42.125.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000388; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.43.180.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000389; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.113.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000390; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.218.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000391; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.50.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000392; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.179.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000393; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.183.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000394; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.239.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000395; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.14.143.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000396; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.147.213.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000397; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.18.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000398; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.218.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000399; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.107.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000400; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.241.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000401; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.27.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000402; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.68.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000403; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.97.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000404; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.26.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000405; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.177.147.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000406; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.248.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000407; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.43.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000408; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.58.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000409; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.18.38.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000410; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.18.88.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100000411; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.106.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000412; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.119.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000413; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.182.97.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000414; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.172.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000415; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.15.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000416; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.195.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000417; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.245.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000418; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.137.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000419; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.227.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000420; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.187.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000421; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.215.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000422; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.240.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000423; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.255.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000424; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.204.30.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000425; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.250.129.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000426; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.131.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000427; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000428; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000429; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.148.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000430; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.155.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000431; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.206.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000432; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.96.38.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000433; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.52.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000434; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.132.113.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000435; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.15.69.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000436; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000437; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000438; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000439; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000440; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.207.39.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000441; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.25.204.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000442; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.70.108.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000443; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.0.255.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000444; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.1.54.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000445; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.142.222.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000446; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.150.213.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000447; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.151.248.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000448; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000449; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000450; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000451; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000452; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000453; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000454; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000455; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000456; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000457; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000458; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000459; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000460; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000461; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000462; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000463; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000464; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.99.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000465; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.66.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000466; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.93.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000467; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.8.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000468; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.7.75.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000469; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.83.79.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000470; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.114.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000471; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.96.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000472; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.121.44.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000473; rev:1;) @@ -494,26 +494,26 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.254.76.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000488; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.96.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000489; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.97.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000490; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.88.99.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000491; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.100.150.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000492; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.137.53.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000493; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.160.147.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000494; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.66.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000495; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.72.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000496; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.79.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000497; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.37.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000498; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.232.227.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000499; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.33.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000500; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.0.240.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000501; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.137.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000502; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.202.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000503; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000504; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.170.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000505; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000506; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.19.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000507; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.200.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000508; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.238.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000509; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.12.164.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000510; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.8.107.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000491; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.88.99.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000492; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.100.150.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000493; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.137.53.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000494; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.160.147.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000495; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.66.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000496; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.72.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000497; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.79.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000498; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.37.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000499; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.232.227.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000500; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.33.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000501; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.0.240.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000502; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.32.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000503; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.202.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000504; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000505; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.170.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000506; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000507; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.19.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000508; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.200.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000509; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.238.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000510; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.129.2.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000511; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.129.84.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000512; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.208.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000513; rev:1;) @@ -527,192 +527,192 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.14.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000521; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.20.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000522; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.246.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000523; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.236.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000524; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.8.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000525; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.183.16.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000526; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.191.164.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000527; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.101.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000528; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.53.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000529; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.235.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000530; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.35.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000531; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.52.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000532; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.60.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000533; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.112.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000534; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.184.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000535; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.212.29.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000536; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.213.225.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000537; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.130.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000538; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.152.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000539; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.116.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000540; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.184.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000541; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.103.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000542; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.181.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000543; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.79.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000544; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.11.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000545; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.148.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000546; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.184.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000547; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.28.217.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000548; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.204.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000549; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.251.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000550; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.250.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000551; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.9.193.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000552; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.9.85.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000553; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.221.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000554; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.76.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000555; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.130.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000556; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.104.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000557; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.131.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000558; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.151.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000559; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.24.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000560; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000561; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.42.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000562; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.54.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000563; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.132.110.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000564; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.135.34.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000565; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.136.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000566; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.236.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000567; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.160.126.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000568; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.65.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000569; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.165.123.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000570; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.187.111.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000571; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.199.56.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000572; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.230.174.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000573; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.254.210.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000574; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.5.112.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000575; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.5.92.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000576; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.6.0.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000577; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.67.89.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000578; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.80.46.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000579; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.93.94.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000580; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.95.10.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000581; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.128.28.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000582; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.142.93.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000583; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.191.113.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000584; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.36.222.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000585; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.1.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000586; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.146.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000587; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.3.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000588; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.82.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100000589; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.8.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000590; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.186.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100000591; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.66.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000592; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.244.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000593; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.74.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000594; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.93.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000595; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.95.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000524; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.236.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000525; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.8.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000526; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.183.16.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000527; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.191.164.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000528; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.101.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000529; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.53.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000530; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.235.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000531; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.35.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000532; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.52.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000533; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.60.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000534; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.112.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000535; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.184.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000536; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.212.29.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000537; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.213.225.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000538; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.130.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000539; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.152.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000540; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.116.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000541; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.184.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000542; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.103.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000543; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.181.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000544; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.79.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000545; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.11.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000546; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.148.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000547; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.184.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000548; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.28.217.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000549; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.242.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000550; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.47.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000551; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.148.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000552; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.189.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000553; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.9.36.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000554; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.221.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000555; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.76.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000556; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.130.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000557; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.104.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000558; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.131.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000559; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.151.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000560; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.24.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000561; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000562; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.42.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000563; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.54.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000564; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.132.110.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000565; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.135.34.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000566; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.136.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000567; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.236.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000568; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.160.126.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000569; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.65.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000570; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.165.123.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000571; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.187.111.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000572; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.199.56.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000573; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.230.174.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000574; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.254.210.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000575; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.5.112.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000576; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.5.92.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000577; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.6.0.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000578; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.67.89.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000579; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.80.46.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000580; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.93.94.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000581; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.95.10.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000582; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.128.28.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000583; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.142.93.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000584; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.191.113.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000585; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.36.222.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000586; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.1.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000587; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.146.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000588; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.3.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000589; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.14.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000590; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.82.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100000591; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.186.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100000592; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.66.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000593; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.244.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000594; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.74.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000595; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"126.39.155.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000596; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"128.116.133.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000597; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"13.114.247.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000598; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"130.255.159.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000599; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"134.119.186.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000600; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"135.148.36.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000601; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"138.99.204.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100000602; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.159.226.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000603; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.173.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000604; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.216.102.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000605; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.102.17.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000606; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.136.80.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000607; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000608; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000609; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.155.86.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000610; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.160.34.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000611; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.232.33.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000612; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.37.222.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000613; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.42.237.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000614; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.45.127.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000615; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.25.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000616; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.50.129.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000617; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.55.29.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000618; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"140.237.12.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000619; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.11.216.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000620; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.177.56.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000621; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"148.69.108.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000622; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000623; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000624; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.124.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000625; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14karatvisions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100000626; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"150.116.207.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000627; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.177.163.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000628; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.33.230.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000629; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.234.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100000630; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.152.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000631; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.135.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000632; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.159.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000633; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"156.234.211.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000634; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.101.165.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000635; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.174.213.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000636; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.51.125.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000637; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.224.74.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000638; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.65.199.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000639; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.191.165.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000640; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.194.28.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000641; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.209.98.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000642; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.200.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000643; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.206.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000644; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.53.206.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000645; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"167.114.172.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000646; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"170.81.238.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000647; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.121.255.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000648; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.247.155.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000649; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.250.131.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000650; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.162.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000651; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.150.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000652; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.105.36.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000653; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.114.244.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000654; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.186.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000655; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000656; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000657; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.81.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000658; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.93.194.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000659; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.167.85.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000660; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.169.46.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000661; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.19.58.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000662; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.233.85.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000663; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.235.209.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000664; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.25.113.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000665; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.95.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000666; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.97.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000667; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.119.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000668; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.92.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100000669; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.63.64.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000670; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.68.100.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000671; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.61.3.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000672; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.73.246.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000673; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.81.78.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000674; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.83.73.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000675; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.11.65.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000676; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.117.66.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000677; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.169.13.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000678; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.194.116.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000679; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.201.104.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000680; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.208.230.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000681; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.213.25.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000682; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.42.46.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000683; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"130.255.159.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000598; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"135.148.36.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000599; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"138.99.204.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100000600; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.159.226.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000601; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.173.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000602; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.216.102.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000603; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.136.80.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000604; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000605; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000606; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.155.86.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000607; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.160.34.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000608; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.232.33.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000609; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.37.222.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000610; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.42.237.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000611; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.45.127.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000612; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.25.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000613; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.50.129.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000614; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.55.29.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000615; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"140.237.12.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000616; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"141.105.65.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000617; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.11.216.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000618; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.177.56.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000619; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"143.198.120.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000620; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"148.69.108.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000621; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000622; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000623; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000624; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100000625; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000626; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.124.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000627; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14karatvisions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100000628; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"150.116.207.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000629; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.177.163.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000630; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.33.230.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000631; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.234.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100000632; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.152.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000633; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.135.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000634; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.159.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000635; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"156.234.211.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000636; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.101.165.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000637; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.174.213.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000638; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.51.125.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000639; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.224.74.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000640; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.65.199.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000641; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.191.165.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000642; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.194.28.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000643; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.209.98.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000644; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.245.221.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000645; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.206.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000646; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"167.114.172.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000647; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"170.81.238.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000648; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.121.255.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000649; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.247.155.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000650; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.250.131.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000651; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.162.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000652; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.150.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000653; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.105.36.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000654; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.114.244.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000655; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.186.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000656; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000657; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000658; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.81.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000659; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.93.194.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000660; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.167.85.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000661; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.169.46.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000662; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.19.58.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000663; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.233.85.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000664; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.235.209.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000665; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.25.113.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000666; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.95.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000667; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.97.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000668; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.119.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000669; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.92.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100000670; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.63.64.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000671; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.68.100.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000672; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.61.3.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000673; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.73.246.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000674; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.81.78.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000675; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.83.73.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000676; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.11.65.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000677; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.117.66.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000678; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.169.13.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000679; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.194.116.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000680; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.201.104.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000681; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.208.230.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000682; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.213.25.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000683; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000684; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000685; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100000686; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000687; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000688; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100000689; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000690; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000691; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000692; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000693; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000694; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.12.117.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000695; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000696; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000697; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.124.7.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000698; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.221.188.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000699; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.240.84.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000700; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.11.92.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100000701; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.131.226.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000702; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.54.82.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000703; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.124.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000704; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.134.185.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000705; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.150.174.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000706; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.151.143.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000707; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.165.122.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000708; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.17.171.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000709; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000690; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000691; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000692; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000693; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000694; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000695; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000696; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.12.117.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000697; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000698; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000699; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.124.7.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000700; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.221.188.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000701; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.240.84.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000702; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.131.226.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000703; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.54.82.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000704; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.124.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000705; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.134.185.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000706; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.150.174.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000707; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.151.143.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000708; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.165.122.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000709; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.0.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000710; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.0.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000711; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000712; rev:1;) @@ -721,359 +721,359 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000715; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000716; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000717; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000718; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000719; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000720; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000721; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000722; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000723; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000724; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000725; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000726; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100000727; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000728; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000729; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000730; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000731; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000732; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000733; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100000734; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000735; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000736; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000737; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000738; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000739; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000740; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000741; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000742; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000743; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000744; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000745; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000746; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000747; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000748; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000718; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000719; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000720; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000721; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000722; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000723; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000724; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000725; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000726; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000727; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000728; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000729; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000730; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100000731; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000732; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000733; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000734; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000735; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100000736; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000737; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000738; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000739; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000740; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000741; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000742; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000743; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000744; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000745; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000746; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000747; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000748; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000749; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000750; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000751; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000752; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000753; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000754; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000755; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000756; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000757; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000758; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000759; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000760; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000761; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000762; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000763; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000764; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000765; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000766; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000750; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000751; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000752; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000753; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000754; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000755; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000756; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000757; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000758; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000759; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000760; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000761; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000762; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000763; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000764; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000765; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000766; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000767; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100000768; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000769; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000770; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000771; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000772; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000773; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000774; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000775; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000776; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000777; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000769; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000770; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000771; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000772; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000773; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000774; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000775; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000776; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000777; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000778; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000779; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000780; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000781; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000781; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000782; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000783; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000784; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000785; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000786; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000787; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000788; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000789; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000790; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000791; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000785; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000786; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100000787; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000788; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000789; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000790; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100000791; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000792; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000793; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000794; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000795; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000796; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000797; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000798; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000799; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000800; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000801; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000802; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000803; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000804; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000805; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000806; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000807; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000808; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000809; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000810; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000811; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000812; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000794; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000795; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000796; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000797; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000798; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000799; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000800; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000801; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000802; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000803; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000804; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000805; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000806; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000807; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000808; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000809; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000810; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000811; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000812; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000813; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000814; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000815; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000816; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000817; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000818; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000819; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000820; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000821; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000822; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000815; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000816; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000817; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000818; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000819; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000820; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000821; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000822; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000823; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000824; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000825; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000826; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000827; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000828; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000829; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000830; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000825; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000826; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000827; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000828; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000829; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000830; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000831; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000832; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000833; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000834; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000833; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000834; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000835; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000836; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000837; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000838; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000839; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000840; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000841; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000842; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000843; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000844; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000845; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000846; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000847; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000848; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000849; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000850; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000851; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000852; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000853; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000854; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000855; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100000856; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000857; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000858; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000859; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000860; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000861; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000862; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000863; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000864; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000865; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000866; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000867; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000868; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000869; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000870; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000871; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000872; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000873; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000874; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000875; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000876; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000877; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000878; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000879; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100000880; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000881; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000882; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000883; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100000884; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000885; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000886; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000887; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000888; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000889; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000890; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000891; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000892; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000893; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000894; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000895; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000896; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000897; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000898; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000899; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000900; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100000901; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000902; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000903; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000904; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000905; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000906; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000907; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000908; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000909; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000910; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000911; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000912; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000913; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000914; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000915; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000916; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000917; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100000918; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000919; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000920; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000921; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000922; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000923; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000924; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000925; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000926; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000927; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000928; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000929; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000930; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000931; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000932; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000933; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000934; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000935; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000936; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000937; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000938; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000939; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000940; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000941; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000942; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000943; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000944; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000945; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000946; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000947; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000948; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000949; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000950; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000951; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000952; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000953; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000954; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000955; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000956; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000957; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000958; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000959; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000960; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000961; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000962; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000963; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000964; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000965; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000966; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000967; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000968; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000969; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000970; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000971; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000972; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000973; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.74.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000974; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000975; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000976; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000977; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000978; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000979; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000980; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000981; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000982; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000983; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000984; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000985; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000986; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000987; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000988; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000989; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000990; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000991; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000992; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000993; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.82.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000994; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.82.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000995; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000996; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000997; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000998; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000999; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001000; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001001; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001002; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001003; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001004; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001005; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001006; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001007; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001008; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001009; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001010; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001011; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001012; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001013; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001014; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001015; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001016; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001017; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001018; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001019; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001020; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001021; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001022; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001023; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001024; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001025; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001026; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001027; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001028; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001029; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001030; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001031; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100000836; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000837; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000838; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000839; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000840; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000841; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000842; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000843; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000844; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000845; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000846; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000847; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000848; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000849; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000850; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000851; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000852; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000853; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000854; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000855; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000856; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100000857; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000858; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000859; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000860; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000861; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000862; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000863; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000864; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000865; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000866; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000867; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000868; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000869; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000870; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000871; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000872; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000873; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000874; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000875; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000876; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000877; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000878; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000879; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000880; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000881; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000882; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100000883; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000884; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000885; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000886; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000887; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000888; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000889; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000890; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000891; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000892; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000893; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000894; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000895; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000896; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000897; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000898; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000899; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000900; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000901; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000902; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000903; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000904; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000905; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100000906; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000907; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000908; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000909; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000910; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000911; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000912; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000913; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000914; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000915; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000916; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000917; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000918; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000919; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100000920; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000921; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000922; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000923; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000924; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000925; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000926; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000927; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100000928; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000929; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000930; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000931; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000932; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000933; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000934; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000935; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000936; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000937; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000938; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000939; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000940; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000941; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000942; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000943; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000944; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000945; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000946; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000947; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000948; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000949; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000950; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000951; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000952; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000953; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000954; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000955; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000956; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000957; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000958; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000959; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000960; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000961; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000962; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000963; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000964; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000965; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000966; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100000967; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000968; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000969; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000970; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000971; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000972; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000973; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000974; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000975; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000976; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000977; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000978; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.74.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000979; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000980; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000981; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000982; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000983; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000984; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000985; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000986; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000987; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000988; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000989; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000990; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000991; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000992; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000993; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000994; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000995; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.82.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000996; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.82.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000997; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000998; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000999; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001000; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001001; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001002; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001003; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001004; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001005; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001006; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001007; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001008; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001009; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001010; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001011; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001012; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001013; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001014; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001015; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001016; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001017; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001018; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001019; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001020; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001021; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001022; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001023; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001024; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001025; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001026; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001027; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001028; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001029; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001030; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001031; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001032; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001033; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001034; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001035; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001036; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001034; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001035; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001036; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001037; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001038; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001039; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001040; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001041; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001042; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.19.183.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001043; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.205.101.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001044; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.21.164.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001045; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.217.8.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001046; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.22.117.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001047; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.222.252.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001048; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.34.183.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001049; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.48.235.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001050; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.95.136.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001051; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.159.58.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001052; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.225.152.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001053; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.43.176.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001054; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.43.176.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001055; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.60.84.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001056; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.99.210.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001057; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.108.21.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001058; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.114.60.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001059; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.174.205.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001060; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.175.236.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001061; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.105.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001062; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.110.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001063; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.165.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001064; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.214.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001065; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.34.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001066; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.104.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001067; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.180.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001068; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.242.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001069; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.218.5.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001070; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001039; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001040; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.19.183.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001041; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.205.101.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001042; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.21.164.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001043; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.217.8.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001044; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.22.117.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001045; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.222.252.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001046; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.34.183.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001047; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.48.235.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001048; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.95.136.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001049; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.159.58.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001050; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.225.152.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001051; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.43.176.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001052; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.43.176.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001053; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.60.84.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001054; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.99.210.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001055; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.108.21.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001056; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.114.60.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001057; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.174.205.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001058; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.175.236.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001059; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.105.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001060; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.110.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001061; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.165.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001062; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.214.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001063; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.34.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001064; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.104.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001065; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.180.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001066; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.242.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001067; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.5.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001068; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.218.5.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001069; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.248.80.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001070; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.111.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001071; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.53.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001072; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.94.170.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001073; rev:1;) @@ -1090,226 +1090,226 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.236.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001084; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.59.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001085; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.177.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001086; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.88.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001087; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.88.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001088; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.115.176.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001089; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.102.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001090; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.35.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001091; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.200.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001092; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001093; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.192.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001094; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.34.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001095; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.73.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001096; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.254.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001097; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.87.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001098; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.87.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001099; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.213.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001100; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.160.98.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001101; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.233.0.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001102; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.235.252.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001103; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.53.197.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001104; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.59.170.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001105; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.88.27.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001106; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001107; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.109.169.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001108; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.17.145.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001109; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.144.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001110; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.146.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001111; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.109.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001112; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.14.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001113; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.97.40.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001114; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.164.185.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001115; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.175.115.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001116; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.74.149.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001117; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.106.209.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001118; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.107.3.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001119; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.117.2.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001120; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.172.110.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001121; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.172.110.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001122; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.174.101.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001123; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.181.10.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001124; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001125; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001126; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001127; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001128; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.221.3.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001129; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.222.58.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001130; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.224.129.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001131; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.224.129.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001132; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.228.141.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001133; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.245.96.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001134; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.26.113.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001135; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.34.16.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001136; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.55.1.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001137; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.68.230.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001138; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.81.154.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001139; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.81.157.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001140; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001141; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001142; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001143; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001144; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001145; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001146; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.151.144.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001147; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.219.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001148; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001149; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001150; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001151; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.253.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001152; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.225.120.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001153; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.232.44.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001154; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.28.60.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001155; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.34.4.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001156; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.73.188.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001157; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.73.188.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001158; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.12.10.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001159; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.135.141.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001160; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.188.124.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001161; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.233.234.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001162; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.21.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001163; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.231.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001164; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.13.179.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001165; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.138.200.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001166; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.152.41.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001167; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.178.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001168; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.179.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001169; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.30.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001170; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.36.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001171; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.242.242.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001172; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.69.251.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001173; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.83.202.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001174; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"189.201.250.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001175; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"189.252.184.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001176; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.0.42.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001177; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.109.178.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001178; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.110.161.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001179; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.111.151.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001180; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.119.207.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001181; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.12.99.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001182; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001183; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001184; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001185; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001186; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001187; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001188; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.20.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001189; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.141.117.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001190; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.147.16.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001191; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.159.240.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001192; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.210.214.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001193; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.177.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001194; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.226.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001195; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.49.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001196; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.214.24.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001197; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.216.140.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001198; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.65.206.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001199; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.73.12.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001200; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.92.4.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001201; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001202; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001203; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.41.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001204; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"191.255.248.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001205; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.153.57.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001206; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.210.175.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001207; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.220.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001208; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.228.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001209; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.99.240.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001210; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.113.107.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001211; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.147.142.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001212; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.15.36.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001213; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.152.35.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001214; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.38.20.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001215; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.139.126.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001216; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.228.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001217; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.24.94.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001218; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.202.26.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001219; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.218.48.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001220; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001221; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.166.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001222; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.159.2.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001223; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.50.27.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001224; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.133.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001225; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.174.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001226; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.207.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001227; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.251.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001228; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.132.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001229; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1am.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100001230; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.239.22.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001231; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.36.231.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001232; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.37.149.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001233; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.37.203.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001234; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.111.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001235; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001236; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.125.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001237; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.92.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001238; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.56.8.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001239; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.57.122.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001240; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.57.122.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001241; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.83.152.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001242; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"20.185.42.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001243; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.105.167.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001244; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.111.189.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001245; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.194.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001246; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.2.161.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001247; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.29.105.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001248; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.30.132.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001249; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.170.46.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001250; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.184.163.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001251; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.187.102.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001252; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.200.254.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001253; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.203.221.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001254; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.107.233.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001255; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.111.131.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001256; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.166.217.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001257; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.182.125.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001258; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.29.95.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001259; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.4.124.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001260; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.44.228.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001261; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.113.4.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001087; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.194.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001088; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.102.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001089; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.29.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001090; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.200.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001091; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.23.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001092; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.48.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001093; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001094; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.192.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001095; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.34.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001096; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.200.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001097; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.205.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001098; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.254.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001099; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.109.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001100; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.126.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001101; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.87.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001102; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.87.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001103; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.207.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001104; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.80.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001105; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.160.98.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001106; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.233.0.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001107; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.235.252.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001108; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.53.197.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001109; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.88.27.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001110; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001111; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.109.169.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001112; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.141.61.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001113; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.17.145.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001114; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.144.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001115; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.49.86.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001116; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.14.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001117; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.97.40.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001118; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.164.185.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001119; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.175.115.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001120; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.74.149.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001121; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.106.209.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001122; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.117.2.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001123; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.117.21.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001124; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.132.53.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001125; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.172.110.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001126; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.172.110.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001127; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.174.101.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001128; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.181.10.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001129; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001130; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001131; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001132; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001133; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.221.3.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001134; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.222.58.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001135; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.224.129.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001136; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.224.129.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001137; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.228.141.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001138; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.245.96.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001139; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.26.113.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001140; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.34.16.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001141; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.38.142.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001142; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.55.1.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001143; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.68.230.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001144; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.81.154.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001145; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.81.157.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001146; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001147; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001148; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001149; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001150; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.151.144.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001151; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.219.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001152; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001153; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001154; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001155; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.253.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001156; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.225.120.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001157; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.232.44.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001158; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.28.60.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001159; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.34.4.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001160; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.73.188.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001161; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.12.10.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001162; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.135.141.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001163; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.188.124.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001164; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.233.234.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001165; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.21.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001166; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.231.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001167; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.13.179.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001168; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.138.200.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001169; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.152.41.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001170; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.178.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001171; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.179.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001172; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.199.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001173; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.30.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001174; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.36.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001175; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.45.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001176; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.242.242.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001177; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.69.251.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001178; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.83.202.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001179; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"189.171.22.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001180; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"189.175.214.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001181; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"189.252.184.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001182; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.0.42.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001183; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.109.178.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001184; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.110.161.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001185; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.111.151.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001186; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.119.207.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001187; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.12.99.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001188; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001189; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001190; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001191; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001192; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001193; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001194; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.20.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001195; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.147.16.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001196; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.159.240.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001197; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.210.214.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001198; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.177.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001199; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.226.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001200; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.49.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001201; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.214.24.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001202; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.216.140.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001203; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.65.206.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001204; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.73.12.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001205; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.92.4.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001206; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001207; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001208; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.41.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001209; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"191.255.248.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001210; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.210.175.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001211; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.185.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001212; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.220.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001213; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.228.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001214; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.99.221.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001215; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.99.240.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001216; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.113.107.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001217; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.147.142.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001218; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.152.35.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001219; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.38.20.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001220; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.139.126.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001221; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.228.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001222; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.24.94.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001223; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.5.3.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001224; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.202.26.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001225; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.218.48.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001226; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001227; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.166.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001228; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.159.2.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001229; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.50.27.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001230; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.133.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001231; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.213.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001232; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.251.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001233; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1am.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100001234; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.239.22.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001235; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.36.231.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001236; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.37.149.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001237; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.111.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001238; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001239; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.125.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001240; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.92.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001241; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.56.8.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001242; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.57.122.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001243; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.57.122.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001244; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.83.152.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001245; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"20.185.42.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001246; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.105.167.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001247; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.111.189.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001248; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.194.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001249; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.29.105.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001250; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.30.132.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001251; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.170.46.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001252; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.184.163.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001253; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.187.102.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001254; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.200.254.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001255; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.203.221.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001256; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.107.233.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001257; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.111.131.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001258; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.166.217.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001259; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.29.95.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001260; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.4.124.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001261; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.176.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001262; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.191.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001263; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.74.236.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001264; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.109.201.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001265; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.159.80.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001266; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.159.80.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001267; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.159.80.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001268; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.170.123.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001269; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.189.156.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001270; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.204.232.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001271; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.229.21.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001272; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.236.190.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001273; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.70.166.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001274; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.77.80.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001275; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.119.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001276; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.171.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001277; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.82.36.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001278; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.93.6.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001279; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"204.195.116.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001280; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.248.137.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001281; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.5.32.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001282; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.163.58.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001283; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.75.27.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001284; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001285; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001286; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.146.98.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001287; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.124.149.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001288; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.180.237.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001289; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.152.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001290; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.153.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001291; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.237.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001292; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.130.69.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001266; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.159.80.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001267; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.159.80.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001268; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.159.80.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001269; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.170.123.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001270; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.189.156.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001271; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.204.232.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001272; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.229.21.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001273; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.236.190.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001274; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.70.166.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001275; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.77.80.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001276; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.119.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001277; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.171.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001278; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.82.36.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001279; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.93.6.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001280; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"204.195.116.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001281; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.248.137.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001282; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.5.32.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001283; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.163.58.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001284; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.75.27.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001285; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001286; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001287; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.146.98.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001288; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.124.149.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001289; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.180.237.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001290; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.152.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001291; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.153.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001292; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.245.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001293; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.68.242.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001294; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.132.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001295; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.75.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001296; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.200.160.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001297; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.204.215.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001298; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.66.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001299; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.93.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001300; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.216.66.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001301; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.114.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001302; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.120.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001303; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.246.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001304; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.238.83.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001305; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.5.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001306; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.203.111.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001298; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.204.215.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001299; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.66.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001300; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.93.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001301; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.216.66.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001302; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.114.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001303; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.120.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001304; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.246.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001305; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.238.83.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001306; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.122.86.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001307; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.156.215.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001308; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.46.197.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001309; rev:1;) @@ -1319,7 +1319,7 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.14.173.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001313; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.190.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001314; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001315; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001316; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001316; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001317; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001318; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001319; rev:1;) @@ -1336,7 +1336,7 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001330; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001331; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001332; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001333; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001333; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001334; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001335; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.189.178.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001336; rev:1;) @@ -1356,21 +1356,21 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.2.40.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001350; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.234.165.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001351; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.238.246.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001352; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.32.118.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001353; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.207.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001354; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.227.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001355; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.68.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001356; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.81.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001357; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.56.93.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001358; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.59.116.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001359; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.79.103.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001360; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.93.102.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001361; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.93.102.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001362; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.207.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001353; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.227.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001354; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.68.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001355; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.81.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001356; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.56.93.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001357; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.59.116.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001358; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.79.103.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001359; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.93.102.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001360; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.93.102.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001361; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.113.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001362; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.127.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001363; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.137.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001364; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.73.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001365; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.136.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001366; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.139.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001367; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.226.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001364; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.136.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001365; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.14.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001366; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.178.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001367; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.37.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001368; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.241.6.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001369; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001370; rev:1;) @@ -1385,44 +1385,44 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.85.145.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001379; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"21robo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100001380; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.126.237.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001381; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.132.106.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001382; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.173.160.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001383; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.200.22.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001384; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.81.134.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001385; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.90.159.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001386; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.124.78.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001387; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.13.150.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001388; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.162.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001389; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.173.160.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001382; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.200.22.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001383; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.81.134.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001384; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.90.159.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001385; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.124.78.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001386; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.13.150.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001387; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.162.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001388; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.47.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001389; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.127.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001390; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.3.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001391; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.157.191.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001392; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.136.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001393; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.201.54.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001394; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.202.232.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001395; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.130.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001396; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.163.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001397; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.197.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001398; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.251.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001399; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.116.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001400; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.172.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001401; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.184.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001402; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.252.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001403; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.8.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001404; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.232.183.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001405; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.235.137.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001406; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.68.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001407; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.108.17.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001408; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.118.248.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001409; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.119.65.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001410; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.132.125.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001411; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.9.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001412; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.122.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001413; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.139.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001414; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.170.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001415; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.182.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001391; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.3.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001392; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.157.191.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001393; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.136.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001394; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.201.54.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001395; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.202.232.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001396; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.130.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001397; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.163.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001398; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.197.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001399; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.251.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001400; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.116.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001401; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.172.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001402; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.184.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001403; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.252.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001404; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.8.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001405; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.232.183.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001406; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.235.137.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001407; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.68.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001408; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.107.145.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001409; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.108.17.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001410; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.118.248.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001411; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.119.65.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001412; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.9.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001413; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.122.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001414; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.139.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001415; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.72.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001416; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.133.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001417; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.17.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001418; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.139.21.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001419; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.139.21.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001418; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.163.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001419; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.17.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001420; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.187.9.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001421; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.211.72.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001422; rev:1;) @@ -1445,9 +1445,9 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.24.213.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001439; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.149.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001440; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.21.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001441; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.92.213.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001442; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.94.190.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001443; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.95.122.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001444; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.94.190.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001442; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.95.122.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001443; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.95.122.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001444; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.103.74.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001445; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.11.141.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001446; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.119.158.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001447; rev:1;) @@ -1518,2510 +1518,2532 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.255.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001512; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.66.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001513; rev:1;) alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.84.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001514; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.214.37.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001515; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.139.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001516; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.190.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001517; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.212.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001518; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.253.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001519; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.71.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001520; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.98.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001521; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.144.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001522; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.225.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001523; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.227.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001524; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.234.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001525; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.191.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001526; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.135.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001527; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.132.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001528; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.151.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001529; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.160.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001530; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.176.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001531; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.83.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001532; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.20.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001533; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.249.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001534; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.83.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001535; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.85.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001536; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.221.239.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001537; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.221.242.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001538; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.76.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001539; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.223.242.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001540; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.129.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001541; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.154.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001542; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.212.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001543; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.58.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001544; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.40.120.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001545; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.40.73.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001546; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.36.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001547; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.45.90.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001548; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.44.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001549; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.0.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001550; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.11.51.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001551; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.13.23.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001552; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.124.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001553; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.146.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001554; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.179.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001555; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.184.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001556; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.191.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001557; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.194.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001558; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.216.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001559; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.219.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001560; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.24.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001561; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.30.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001562; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.65.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001563; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.79.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001564; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.94.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001565; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.179.201.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001566; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.195.84.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001567; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001568; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.28.7.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001569; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.30.119.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001570; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32.208.157.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001571; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32792.prolocksmithwinterpark.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100001572; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"34.122.44.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001573; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"34.126.93.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001574; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"35.184.169.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001575; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.108.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001576; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.248.83.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001577; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.250.203.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001578; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.157.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001579; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.18.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001580; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.51.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001581; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.255.90.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001582; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.32.28.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001583; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.160.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001584; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.34.150.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001585; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.65.216.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001586; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.105.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001587; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.133.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001588; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.139.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001589; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.89.18.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001590; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.91.89.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001591; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360.lcy2zzx.pw"; content:"Host"; http_header; classtype:trojan-activity; sid:100001592; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360down7.miiyun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100001593; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.222.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001594; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.233.60.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001595; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.179.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001596; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.180.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001597; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.44.238.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001598; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.116.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001599; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.14.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001600; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.245.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001601; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.98.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001602; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.114.137.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001603; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.115.0.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001604; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.117.31.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001605; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.162.104.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001606; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.162.98.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001607; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.164.112.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001608; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.196.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001609; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001610; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.125.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001611; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.146.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001612; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.206.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001613; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.171.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001614; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.249.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001615; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.60.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001616; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.167.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001617; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.67.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001618; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.10.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001619; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.163.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001620; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.168.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001621; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.203.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001622; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.215.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001623; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.194.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001624; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.78.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001625; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.113.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001626; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.114.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001627; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.150.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001628; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.123.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001629; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.166.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001630; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.218.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001631; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.91.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001632; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.93.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001633; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.127.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001634; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.18.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001635; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.191.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001636; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.205.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001637; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001638; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.36.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001639; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.37.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001640; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.251.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001641; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.27.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001642; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.29.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001643; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.70.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001644; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.83.185.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001645; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.83.94.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001646; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.115.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001647; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.85.54.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001648; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.211.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001649; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.234.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001650; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.78.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001651; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.93.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001652; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.96.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001653; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.143.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001654; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.233.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001655; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.67.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001656; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.72.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001657; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.145.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001658; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001659; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.63.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001660; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.90.86.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001661; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"40.88.2.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001662; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.139.209.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001663; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.165.130.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001664; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.190.63.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001665; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.193.192.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001666; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.219.185.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001667; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.226.60.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001668; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001669; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001670; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001671; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.19.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001672; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.19.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001673; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001674; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001675; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001676; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.202.101.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001677; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.202.101.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001678; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.176.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001679; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.40.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001680; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.60.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001681; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.161.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001682; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.212.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001683; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.238.141.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001684; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.56.15.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001685; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.61.99.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001686; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.82.217.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001687; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.230.207.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001688; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.241.106.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001689; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.252.8.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001690; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.203.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001691; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.135.134.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001692; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001693; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001694; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001695; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.224.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001696; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.141.84.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001697; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001698; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001699; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001700; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001701; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001702; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001703; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001704; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.109.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001705; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.110.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001706; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001707; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.22.209.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001708; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.229.53.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001709; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.27.253.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001710; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.51.104.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001711; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.85.90.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001712; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.9.148.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001713; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.92.108.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001714; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.95.169.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001715; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.95.169.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001716; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.95.169.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001717; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.172.75.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001718; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.182.173.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001719; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.20.63.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001720; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.214.27.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001721; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.214.35.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001722; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.236.65.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001723; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.24.130.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001724; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.241.120.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001725; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.243.179.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001726; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.249.33.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001727; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.25.242.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001728; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.118.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001729; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.86.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001730; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.97.76.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001731; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.145.152.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001732; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.151.23.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001733; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.157.97.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001734; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.16.131.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001735; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.21.202.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001736; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.46.231.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001737; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.162.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001738; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.87.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001739; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.143.43.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001740; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.156.35.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001741; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.158.201.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001742; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.158.201.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001743; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.20.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001744; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.21.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001745; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.174.182.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001746; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.170.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001747; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.178.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001748; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.179.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001749; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.14.122.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001750; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.188.62.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001751; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.95.226.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001752; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.115.174.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001753; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.121.91.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001754; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.247.83.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001755; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.252.47.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001756; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.89.77.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001757; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.114.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001758; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.180.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001759; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.114.246.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001760; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.162.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001761; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.174.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001762; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.125.191.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001763; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.126.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001764; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.141.122.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001765; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.166.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001766; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.200.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001767; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.218.67.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001768; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.22.212.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001769; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.226.129.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001770; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.230.89.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001771; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.237.125.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001772; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.238.42.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001773; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.240.147.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001774; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.241.78.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001775; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.242.91.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001776; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.73.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001777; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.75.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001778; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.80.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001779; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.252.176.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001780; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.253.15.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001781; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.51.219.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001782; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001783; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001784; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.0.211.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001785; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.102.168.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001786; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.126.26.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001787; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.202.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001788; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.214.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001789; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.237.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001790; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.246.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001791; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.173.135.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001792; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.175.63.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001793; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.23.114.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001794; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.26.181.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001795; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.30.12.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001796; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.60.117.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001797; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.13.61.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001798; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.122.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001799; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.216.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001800; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.233.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001801; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.6.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001802; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001803; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.111.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001804; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.206.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001805; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.218.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001806; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.220.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001807; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.254.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001808; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.83.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001809; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.214.85.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001810; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.177.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001811; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.86.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001812; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.220.159.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001813; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.15.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001814; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.39.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001815; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.4.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001816; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.51.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001817; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.60.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001818; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001819; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.254.36.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001820; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.10.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001821; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.8.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001822; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.146.108.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001823; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.91.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001824; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.247.224.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001825; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.101.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001826; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.241.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001827; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.57.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001828; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.9.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001829; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.98.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001830; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.99.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001831; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.117.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001832; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.249.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001833; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.74.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001834; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.103.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001835; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.180.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001836; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.181.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001837; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.57.96.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001838; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.170.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001839; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.73.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001840; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.61.218.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001841; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.65.172.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001842; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.0.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001843; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.104.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001844; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.110.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001845; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001846; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.255.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001847; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.45.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001848; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.98.144.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001849; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.1.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001850; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.141.73.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001851; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.131.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001852; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001853; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.31.126.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001854; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.149.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001855; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.43.207.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001856; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.90.165.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001857; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"63.245.122.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001858; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"64.233.154.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001859; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.125.128.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001860; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.26.155.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001861; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.35.61.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001862; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.108.199.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001863; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.57.55.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001864; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.74.7.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001865; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.91.21.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001866; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.97.181.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001867; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.245.151.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001868; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.8.138.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001869; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.83.49.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001870; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.84.138.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001871; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.148.103.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001872; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.174.182.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001873; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.175.107.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001874; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.188.144.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001875; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.204.88.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001876; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.119.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001877; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.78.33.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001878; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.115.37.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001879; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.120.237.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001880; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.123.245.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001881; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.124.231.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001882; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.127.214.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001883; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.146.232.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001884; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.165.173.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001885; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.196.158.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001886; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.222.157.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001887; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.229.0.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001888; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.63.73.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001889; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.115.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001890; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.227.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001891; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.76.240.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001892; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.115.31.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001893; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.118.240.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001894; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.167.10.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001895; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.236.190.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001896; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.25.5.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001897; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.93.129.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001898; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.127.148.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001899; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.146.190.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001900; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.204.63.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001901; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.34.191.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001902; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.40.234.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001903; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.106.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001904; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.2.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001905; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.235.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001906; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.47.133.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001907; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.71.60.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001908; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.85.106.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001909; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.17.22.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001910; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.180.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001911; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.200.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001912; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.202.249.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001913; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.214.69.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001914; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.229.230.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001915; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.31.40.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001916; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.112.123.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001917; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.204.216.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001918; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.31.139.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001919; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.70.164.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001920; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.101.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001921; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.108.224.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001922; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.195.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001923; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.199.84.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001924; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.64.139.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001925; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.75.165.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001926; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.127.141.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001927; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.99.213.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001928; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.170.11.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001929; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.178.22.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001930; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.217.92.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001931; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.250.199.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001932; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.254.129.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001933; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.84.134.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001934; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.89.107.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001935; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.95.12.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001936; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.111.182.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001937; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.237.25.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001938; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.50.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001939; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.89.203.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001940; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77st.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100001941; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.138.98.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001942; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.145.224.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001943; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.141.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001944; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.41.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001945; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.106.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001946; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.168.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001947; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.188.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001948; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.104.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001949; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.176.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001950; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.27.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001951; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.23.172.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001952; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.8.225.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001953; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.11.195.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001954; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.147.123.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001955; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.175.42.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001956; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.21.84.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001957; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.7.170.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001958; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.79.58.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001959; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.8.70.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001960; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.9.88.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001961; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.107.89.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001962; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.19.101.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001963; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.211.181.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001964; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.217.12.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001965; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.99.128.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001966; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.136.146.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001967; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.165.44.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001968; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.191.40.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001969; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.198.7.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001970; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.141.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001971; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.215.199.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001972; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.187.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001973; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.195.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001974; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.229.230.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001975; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.244.219.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001976; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.246.225.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001977; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.30.177.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001978; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.92.36.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001979; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.103.108.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001980; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.135.196.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001981; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.212.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001982; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.85.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001983; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.207.61.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001984; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.209.250.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001985; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.211.156.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001986; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.59.31.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001987; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.110.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001988; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.53.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001989; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.138.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001990; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.139.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001991; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.154.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001992; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.187.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001993; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.100.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001994; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.102.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001995; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.106.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001996; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.108.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001997; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.131.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001998; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.134.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001999; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.19.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002000; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.197.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002001; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.215.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002002; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.232.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002003; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.234.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002004; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.246.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002005; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.28.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002006; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.4.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002007; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.55.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002008; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.73.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002009; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002010; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.165.237.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002011; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.147.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100002012; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.218.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002013; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.242.253.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002014; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.252.9.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002015; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.210.219.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002016; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.50.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002017; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.95.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002018; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.238.24.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002019; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.247.83.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002020; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.254.39.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002021; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.33.111.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002022; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.40.127.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002023; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.42.20.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002024; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002025; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.11.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100002026; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.123.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002027; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.135.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002028; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.180.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002029; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.208.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002030; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.224.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002031; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.241.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002032; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.108.133.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002033; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.214.149.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002034; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.241.39.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002035; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.64.181.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002036; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.74.215.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002037; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.130.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002038; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"86.35.43.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002039; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.172.19.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002040; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87du.vip"; content:"Host"; http_header; classtype:trojan-activity; sid:100002041; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.119.171.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002042; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.129.208.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100002043; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.208.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002044; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.219.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100002045; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.218.17.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002046; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.225.222.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002047; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.247.96.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002048; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.51.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002049; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.249.13.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002050; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.249.244.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002051; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.204.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002052; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.226.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002053; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.240.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002054; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.254.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002055; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.122.183.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002056; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.136.197.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002057; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.22.152.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002058; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.237.84.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002059; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.248.112.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002060; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.29.213.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002061; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.85.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002062; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.87.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002063; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8poieq.bn.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002064; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"90.152.144.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002065; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.132.197.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002066; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.138.215.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002067; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.177.139.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002068; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.187.103.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002069; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.212.150.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002070; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.217.104.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100002071; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.233.112.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002072; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.234.60.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002073; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.244.169.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002074; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.92.16.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002075; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.114.191.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002076; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.241.78.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002077; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.27.246.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002078; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.54.237.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002079; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.83.62.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002080; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.85.18.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002081; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.159.169.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002082; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.173.235.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100002083; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.21.224.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002084; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.39.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100002085; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.39.79.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002086; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.137.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002087; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.182.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002088; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.206.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002089; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.57.43.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002090; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.73.99.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002091; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.136.69.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002092; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.143.53.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002093; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.17.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002094; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.200.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002095; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.224.83.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002096; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.53.120.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002097; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.85.0.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002098; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.132.129.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002099; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.133.158.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002100; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.154.20.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002101; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.158.19.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002102; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.113.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002103; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.201.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002104; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.60.146.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002105; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.66.196.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002106; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.9.111.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002107; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.9.120.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002108; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.239.73.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002109; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.47.147.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002110; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.68.140.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002111; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.96.199.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100002112; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.0.210.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002113; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.113.239.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002114; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.116.72.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002115; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.128.147.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002116; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.178.242.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100002117; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.30.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002118; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.150.245.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002119; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.33.195.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002120; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"a.stro.lo.gy.t.em.r@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002121; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aatreefelling.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002122; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abcd.bg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002123; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abissnet.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002124; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aboveandbelow.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002125; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absoftechworld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002126; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abyssos.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002127; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"academyshademani.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002128; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acbick.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002129; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"accesslinksgroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002130; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acellr.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002131; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acteon.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002132; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"addahealingmusic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002133; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002134; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.memengers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002135; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.erapor.smk-alasror.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002136; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.gentbcn.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002137; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.grandoceanvilla.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002138; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admission.kmctartskuttippuram.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002139; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adventureexplorer.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002140; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aeropilates.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002141; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afnan-amc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002142; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afrimedspecialist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002143; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agemn.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002144; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciadigitalwdys.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002145; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenda.gmelloinformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002146; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agentt.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002147; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agile8studio.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002148; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aiecons.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002149; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aiqtest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002150; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajpharmaholding.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002151; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"akdvidyalaya.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002152; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alasdemariposas.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002153; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alberts.diamondrelationscrm.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100002154; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alemelektronik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002155; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alena1971.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002156; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alexdubai.com.aldiabsteel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002157; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alka.institute"; content:"Host"; http_header; classtype:trojan-activity; sid:100002158; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"allforcreative.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002159; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alltheway.travel"; content:"Host"; http_header; classtype:trojan-activity; sid:100002160; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alpaylar.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002161; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alumni.hildred.ibbott@46.249.33.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002162; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"am-concepts.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100002163; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarresdeamorymaestroshechiceros.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002164; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarteargentina.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002165; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amos524.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002166; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ams.alvinasschools.org.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100002167; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anadelgbt.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002168; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anantam.net.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002169; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreelapeyre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002170; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andremaraisbeleggings.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002171; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002172; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002173; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreshconcejal.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002174; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelsdetour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002175; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anurontv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002176; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anysbergbiltong.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002177; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apartamentoscitta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002178; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api-ms.cobainaja.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002179; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002180; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apoolcondo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002181; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.adsensearticle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002182; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.explicitsurveys.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002183; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.prerana.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002184; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apps.saintsoporte.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002185; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aps-scribe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002186; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aps-sv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002187; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"artedibujoyarquitectura.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002188; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"arwenyapi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002189; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ask-regard.call-save.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002190; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"asucssa.live"; content:"Host"; http_header; classtype:trojan-activity; sid:100002191; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atfile.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002192; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"athenacapsg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002193; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atlasconcreteworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002194; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"attach.66rpg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002195; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atteuqpotentialunlimited.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002196; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"augustair.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002197; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aulist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002198; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"australianpga.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002199; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"automaticrefreshments.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002200; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"avadhanagames.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002201; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aventuramotorhome.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002202; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayahuascasp.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002203; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayamallah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002204; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aycconsultoriaempresarial.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002205; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azmeasurement.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002206; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azraktours.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002207; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"b.r.uce.lee.b.es.t@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002208; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"b2b.toptanakaryakit.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002209; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"backgrounds.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002210; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"badeggdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002211; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"balealgodon.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002212; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangkok-orchids.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002213; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangladeshunbound.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002214; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bary.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002215; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bash.givemexyz.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002216; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002217; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bavhome.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002218; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bbia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002219; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcmt.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002220; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcrg.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002221; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bdnextrend.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002222; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beanx88.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002223; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bearcatpumps.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002224; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beautincollagen.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100002225; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beautymomentsgt.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002226; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bekape.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002227; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beor360.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002228; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bespokeweddings.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100002229; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestcarenepal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002230; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betone.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002231; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betycopaints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002232; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beveragesmiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002233; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bhavaniengineering.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002234; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bigmikesupplies.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002235; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilbosaquet.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002236; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilhen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002237; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing.rahitechnosoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002238; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"binoy.stalphonsamissionva.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002239; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"biometrico.gpotecnosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002240; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bioskey.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002241; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birdi.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002242; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birminghamlink.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002243; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bizztradingbot.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002244; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bl4n3.zadns.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002245; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.callensaxen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002246; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.difusodesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002247; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.oyinblogs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002248; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.takbelit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002249; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bmlifestyle.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002250; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"boatpecas.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002251; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bodenstein.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002252; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bodylanguage.santulan.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002253; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"booksearch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002254; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bophelocare.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002255; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bounces.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002256; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"boutiqueofferte.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002257; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bpo.correct.go.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100002258; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bradleyinstitute.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002259; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brandtrust.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002260; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"braunfinancial.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002261; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brendanquine.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002262; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brideofmessiah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002263; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightaffiliatesales.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002264; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightmega.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002265; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightstarshop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002266; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"browardinsurancemiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002267; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bt2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002268; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"btdapi.robotake.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002269; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buigiaphat.com.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002270; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bullseyemedia.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002271; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"busandvanrentalmalaysia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002272; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buscascolegios.diit.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002273; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"business.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002274; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"business2.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002275; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c.ompact.i.o.np.d.yu@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002276; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c.oooooooooo.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002277; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c0140529.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002278; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"caballo.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002279; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cacaoprojects.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002280; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"calgaryautorepairservice.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002281; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"callbury.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002282; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"camminachetipassa.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100002283; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"canadianwork.cc"; content:"Host"; http_header; classtype:trojan-activity; sid:100002284; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capitalgroup-kw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002285; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capoeiraventrelivre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002286; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cashyinvestment.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002287; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"catchpoolshetlands.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002288; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cazyacustomfurniture.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002289; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cbn.hypervoizd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002290; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ccauthority.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002291; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cdaonline.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002292; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cdn-10049480.file.myqcloud.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002293; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cec.asso.ac-amiens.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002294; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cellas.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002295; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cendekiabinaaksara.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002296; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cfs5.tistory.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002297; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch.rmu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100002298; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"changematterscounselling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002299; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chardhamdodham.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002300; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chezalice.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002301; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"childselect.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002302; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002303; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002304; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cible-energy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002305; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cifeer.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002306; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citihits.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002307; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citssolutions.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002308; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citycapproperty.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002309; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cityglobalgospel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002310; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"civi.istmejia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002311; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cleanbydesignllc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002312; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cloud.fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002313; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cnc.tacobelllover.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002314; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"codsambal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002315; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colinde.pricesne.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002316; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colorpak.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002317; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"community.reimclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002318; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"competancy.indigoconsult.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002319; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"conceptimagine.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002320; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"config.cqhbkjzx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002321; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"connectcapital.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002322; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"constructoralyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002323; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"consulateins.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002324; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"contributeindustry.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002325; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"copelandscapes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002326; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"coulsongraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002327; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"count.mail.163.com.impactmedfoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002328; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"covid19.cyberschool.or.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002329; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr-sq.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002330; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"craftech.nxtnet.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002331; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crearechile.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002332; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"creationskateboards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002333; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crecerco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002334; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crittersbythebay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002335; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crm.notariavieitoyvelamazan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002336; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crmfarko.manivelasst.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002337; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crmroche.manivelasst.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002338; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crscorretordeimoveis.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002339; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cse-engineer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002340; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"csnserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002341; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cubescargoexpress.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002342; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"curasoles.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002343; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"currantmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002344; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cwa.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002345; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyclomove.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002346; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cynkon.kairoscs.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002347; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"czsl.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002348; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d.powerofwish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002349; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d9.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002350; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"da.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002351; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"danaevara.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002352; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dartoonpictures.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002353; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.cdevelop.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002354; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.over-blog-kiwi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002355; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datapolish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002356; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dating.khokhas.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002357; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datsom.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002358; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davethompson.me.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002359; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davidmcguinness.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002360; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dayspringdaisies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002361; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dd.qiyuea.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002362; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"de.gsearch.com.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002363; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"decifrar.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002364; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"deigratia2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002365; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dekovizyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002366; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo-cliente.mindcreative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002367; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo.glassforcars.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002368; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo6.hiites.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002369; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dent-estet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002370; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dental.xiaoxiao.media"; content:"Host"; http_header; classtype:trojan-activity; sid:100002371; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dentalalliance.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100002372; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"desertlandtrd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002373; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"designerliving.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002374; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"despertaresi.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002375; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"destinymc.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002376; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"detorre.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002377; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.sebpo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002378; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.watch-store.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002379; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dezcom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002380; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfcf.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002381; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"diamantenegro.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002382; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dienmayminhhung.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002383; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"digilib.dianhusada.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002384; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"digisails.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002385; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"disinfection-cleaning.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002386; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"djking.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002387; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.1003b.56a.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002388; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002389; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.installcdn-aws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002390; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.packetstormsecurity.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002391; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.rina-roleplay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002392; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dnn.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002393; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dns.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002394; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dockerupdate.anondns.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002395; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"docman.orientalservices.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002396; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dodsonimaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002397; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"doitunlimited.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002398; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dokan.blueberrytec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002399; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom.daf.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002400; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"doncedyhall.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002401; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donghobinhminh.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002402; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dongphuctop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002403; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosman.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002404; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dovberger.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002405; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.pcclear.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002406; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.udashi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002407; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.webbora.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002408; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down1.arpun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002409; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.caihong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002410; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.doumaibiji.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002411; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.exrnybuf.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002412; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.kaobeitu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002413; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.pdf00.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002414; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.rising.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002415; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.skycn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002416; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.zjsyawqj.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002417; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dragonsknot.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002418; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drbaby.com.sa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002419; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dream.pics"; content:"Host"; http_header; classtype:trojan-activity; sid:100002420; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drgroup.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002421; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drools-moved.46999.n3.nabble.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002422; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drsha.innovativesolutions.mobi"; content:"Host"; http_header; classtype:trojan-activity; sid:100002423; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsenterprize.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002424; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsspainting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002425; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"du-wizards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002426; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duque.guantanameratravel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002427; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dutapp.wisolve.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002428; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duvalcharter.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002429; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dw2.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002430; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dx.qqyewu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002431; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dzinestudio87.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002432; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-commerce.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002433; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002434; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eandgdesign.com.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100002435; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebruyatkin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002436; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"edu.saicraftsman.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002437; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"efficientegroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002438; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"elbauldenora.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002439; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"emaids.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002440; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"emaz.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002441; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"en.baoend.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002442; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enc-tech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002443; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"endurotanzania.co.tz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002444; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ennovate.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002445; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"equimination.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100002446; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"erp.nanotechproautocare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002447; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"escola.probommar.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002448; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eservices.immigration.gov.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002449; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"esnconsultants.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002450; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"essentia.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002451; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ethereality.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002452; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eubanks7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002453; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"europeanzonexxi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002454; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exilum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002455; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exitoalfaomega.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002456; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"extrovertoffers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002457; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"f1sol.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002458; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"familydentist.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100002459; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"faveraprojects.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002460; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002461; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"felicienne.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002462; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"files.martellexpress.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100002463; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"files6.uludagbilisim.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002464; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"final.makkahkmcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002465; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fineartgallerym.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002466; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fisconline.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002467; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fisconline.casa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002468; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fix-america-now.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002469; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fixauto.illumetechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002470; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flexypay.dsquaregroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002471; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flintspin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002472; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flyingbuddhadesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002473; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fmjplastering.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002474; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"follower.instantcashback.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002475; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foothills.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002476; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"footweardirect.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002477; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"forum.mdb.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002478; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fotoobjetivo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002479; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foundationrepairhoustontx.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002480; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foxeps.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002481; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freecnetdownload.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002482; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freisites.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002483; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ftp.n3twork30cm.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100002484; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fullelectronica.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002485; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"funletters.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002486; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fusionfiresolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002487; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"futbolpr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002488; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"futuregraphics.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002489; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"g.pinmonkey.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002490; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gaditastour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002491; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gametwogame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002492; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garciadogshow.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002493; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002494; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow4.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002495; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gastoudergonny.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002496; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gbbulls.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002497; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gcpc.co.id.chronoscurtain.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002498; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"generaldeviales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002499; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfmodd1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002500; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfold1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002501; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghettohub.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002502; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghislain.dartois.pagesperso-orange.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002503; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giadungg7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002504; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giddos.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002505; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giteletropical.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002506; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"glowinmedia.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002507; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmtransformationacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002508; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmvadmission.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002509; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnimelf.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002510; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnscrew.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002511; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gold.investforex.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002512; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcake.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002513; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002514; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002515; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"golden-memories-funerals.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002516; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldenasiacapital.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002517; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldmen.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002518; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gpotecnosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002519; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gracejukes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002520; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"greataccesstoserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002521; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupoinmare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002522; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gruposelt.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002523; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gs.monerorx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002524; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"guide-to-cell-phones.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002525; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gulfac-house.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002526; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gvpcdpgc.edu.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002527; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"h.epelcdn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002528; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"habbotips.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002529; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hagebakken.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100002530; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hamptonpartyoffive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002531; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hashmati.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002532; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hassanproduct.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002533; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hchfug.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002534; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hd11315.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002535; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hdkamera2003.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002536; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hds.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002537; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hellogorgeous.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002538; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"help.hizuko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002539; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"helpdeskserver.epelcdn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002540; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"herchinfitout.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002541; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hhaward.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002542; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandroadcoc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002543; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandslasvegas.atakdev.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002544; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hindi.factsriver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002545; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hiptool.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002546; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitpe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002547; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitstation.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002548; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hmpmall.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002549; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoagietesting10.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002550; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoayeuthuong-my.sharepoint.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002551; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"holmesservices.mobiledevsite.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002552; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"homefindersolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002553; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hometownchick.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002554; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hongluosi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002555; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hookedupboatclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002556; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostingparacolombia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002557; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostzaa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002558; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"houstonshutters.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100002559; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hr2019.vrcom7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002560; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hseda.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002561; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsmwebapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002562; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"htownbars.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002563; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hubtech.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002564; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"huellacero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002565; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hunchomusichub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002566; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hunggiang.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002567; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"husamiyahschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002568; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"i.n.t.e.rloca.l.qs.j.y@jfas.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100002569; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iabmixx2020.rayadigital.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100002570; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iam313.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002571; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"icon.shatangmu.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002572; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idea-secure-login.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002573; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idilsoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002574; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idj.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100002575; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idvindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002576; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ieclb.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002577; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ikexpert.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002578; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ilrafrica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002579; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"images.jermiau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002580; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"imbueautoworx.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002581; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"in-tune2016.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002582; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incrediblepixels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002583; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incredicole.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002584; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"indrasbikaner.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002585; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infair.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002586; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infovator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002587; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"initialnetworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002588; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inodesthetotaldesigners.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002589; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inrajahmundry.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002590; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"instantindialoan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002591; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intersel-idf.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002592; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intuitiveideas.com.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100002593; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inversiones.arrayanfinanciero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002594; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"invest.xpcorporative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002595; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ipmes.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100002596; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iremart.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002597; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iris101.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002598; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isaac.mikhailmotoringschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002599; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iscamenabe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002600; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isiphephelocon.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002601; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ismf.com.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100002602; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iso-dubai.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002603; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"israrulhaq.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100002604; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isrorg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002605; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isso.ps"; content:"Host"; http_header; classtype:trojan-activity; sid:100002606; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"it123.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002607; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"italiandirezione.casa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002608; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itc-demo.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002609; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamiekaylive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002610; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamshed.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002611; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jansen-heesch.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002612; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jathra.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002613; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jay.diamondrelationscrm.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100002614; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jebs.net.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002615; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jeffdahlke.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002616; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jfas.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100002617; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jhayesconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002618; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jiaoyuzixun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002619; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jing-da.com.tw"; content:"Host"; http_header; classtype:trojan-activity; sid:100002620; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jmtc.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002621; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jnanbharati.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002622; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jobs.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002623; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"joelbonissilver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002624; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"join.cl8movement.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002625; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"josegene.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002626; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jpwoodfordco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002627; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jumpmanualjacobhiller.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002628; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jupiter.toxsl.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002629; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"justinscott.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002630; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kadigital.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002631; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalawatihomes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002632; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalogirosfinance.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002633; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kaptaanchapal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002634; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"karer.by"; content:"Host"; http_header; classtype:trojan-activity; sid:100002635; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"katanvetov.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100002636; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kensingtondriving.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002637; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ketofitnessexpert.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002638; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kevinjewelry.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002639; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"keywatch.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002640; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kihn-delaney30gn.ru.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002641; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kingssa.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002642; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kjcpromo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002643; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kleinendeli.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002644; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"korrectconceptservices.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002645; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"krisbadminton.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002646; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ktb.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002647; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kubatoglubaklava.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002648; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kullumanalitours.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002649; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kumaralok.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002650; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kwanfromhongkong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002651; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kz.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002652; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"l.oc.atevur.c@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002653; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lacasadelosalebrijes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002654; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lameguard.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002655; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laodongnhat.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002656; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laravel.pointersoftwares.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002657; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lasermobilesounds.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002658; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lauratomismith.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002659; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lautarosanmiguel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002660; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lawforall.edu.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002661; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lawschoolideas.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002662; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lceventos.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002663; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ld.mediaget.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002664; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ldgcorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002665; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"learning.real-academy.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002666; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leasiacherise.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002667; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leczkregoslup.acelero.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002668; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"legend.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002669; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leluibuffet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002670; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lestesteux.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100002671; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.arihantmbainstitute.ac.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002672; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.uib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002673; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lidoraggiodisole.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100002674; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lifebeam.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002675; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lindnerelektroanlagen.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002676; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"linkintec.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002677; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"liquidaz.casa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002678; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"livetrack.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002679; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsindian.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002680; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lm.stagingarea.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002681; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmaancha.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100002682; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002683; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.login2.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002684; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"location-voitures.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100002685; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.trezor.com.stockfootagesindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002686; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"logotypfabriken.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100002687; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotix.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002688; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotusanddragonfly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002689; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.definerisco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002690; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.difusodesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002691; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ltc.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002692; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luckybrownie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002693; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luminouspneuma.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002694; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luxomodels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002695; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m-technics.kz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002696; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.estudiomoros.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002697; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"madicon.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002698; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"magianegramagiablancayamarres.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002699; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.bs-eiendomme.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002700; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.golimoapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002701; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.jeffsono.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002702; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maksi.feb.unib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002703; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malaya.tv"; content:"Host"; http_header; classtype:trojan-activity; sid:100002704; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malwarecoding.github.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100002705; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managed.oss-cn-beijing.aliyuncs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002706; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managemysalon.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002707; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manantialesdelnorte.uy"; content:"Host"; http_header; classtype:trojan-activity; sid:100002708; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manhtien.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002709; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marcapinyo.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002710; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mario-sunjic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002711; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariobrown.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002712; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariotessarollo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002713; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketinfosales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002714; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketing.enexusgroup.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002715; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marksidfgs.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002716; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"masjidhabeebiyarazviya.mysunni.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002717; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mastersofclientretention.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002718; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"materialescantu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002719; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"matruchhaya.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002720; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxtox.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002721; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbgrm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002722; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbjtimes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002723; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbsolutions.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100002724; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mdasa.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002725; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medevlb.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002726; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"media-server.skyinternet.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002727; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medianews.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100002728; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mediawaysnews.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002729; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medistaffconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002730; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meeweb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002731; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"megagynreformas.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002732; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"megamart.afnan-amc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002733; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mehainteriors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002734; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"merkathink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002735; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mertlog.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002736; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"metalin-cr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002737; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mettaanand.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002738; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meuoculosnanet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002739; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mfevr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002740; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002741; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002742; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"micalle.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002743; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michaelphilip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002744; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michimal2.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002745; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microblading.mirliandias.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002746; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microcomm-group.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002747; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mikhailmotoringschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002748; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mingguanwms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002749; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"minuevavida.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002750; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mirror.mypage.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002751; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mis.nbcc.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100002752; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"misterson.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002753; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mkontakt.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100002754; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mktf.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002755; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmdx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002756; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmogollon.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002757; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mncarteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002758; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modelhouseturkey.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002759; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modernmanna.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002760; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"monetization.business"; content:"Host"; http_header; classtype:trojan-activity; sid:100002761; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moninediy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002762; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moreirawag.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002763; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"motorcomunicacion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002764; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"msacontabil.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002765; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mumgee.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002766; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"muzimbiti.xigubo.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002767; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mvb.kz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002768; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mxpiqw.am.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002769; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mydatebook.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002770; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymlql.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002771; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myritz.vettickal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002772; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysalons.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002773; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myscape.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002774; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysura.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100002775; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"naeemacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002776; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"namnyak.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002777; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nap.mgsservers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002778; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"navayurveda.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002779; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nec-i.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002780; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nelitrianggraeni.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002781; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nerve.untergrund.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002782; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nettube.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002783; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"networkwheels.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002784; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newfuture.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002785; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newinfinitysynergy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002786; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newtreedesign.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002787; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newvisionopticallab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002788; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newxing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002789; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nextdigitalday.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002790; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ngdaycare.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002791; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nguyenkekhuyen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002792; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nhorangtreem.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002793; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nicolas.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002794; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nidhi.iexist.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002795; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nikanpolimer.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100002796; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilehouse.co.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002797; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilinkeji.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002798; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nimboohomes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002799; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"njtiledesigncenter.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002800; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nobius.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002801; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocalnoodle.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002802; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nomadicbees.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002803; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"northnodegroup.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002804; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"notamuzikaletleri.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002805; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ns1.the-widyantos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002806; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsb.org.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002807; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nurmarkaz.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002808; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nxtnet.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002809; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyasabigbullets.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002810; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyeh2o.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002811; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"obseques-conseils.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002812; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oecteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002813; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohsewgorgeous.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002814; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oleholeh.memangbeda.website"; content:"Host"; http_header; classtype:trojan-activity; sid:100002815; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002816; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaromatic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002817; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omega.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100002818; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oms.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002819; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omscoc.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002820; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedigitalcard.granvizionnecorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002821; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedrive.listifyapp.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002822; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"online.creedglobal.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002823; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"open.rawntech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002824; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"open.warehousesaas.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002825; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opolis.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100002826; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"optimus.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002827; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"order.bizpeed.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002828; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orientgatewayltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002829; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orion445.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002830; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orlina.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100002831; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oserve.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002832; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ot.weenets.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002833; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ozemag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002834; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p1.lingpao8.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002835; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p3.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002836; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p6.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002837; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pablobrothel.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002838; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacificgroup.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100002839; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacwebdesigns.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002840; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pagos.krayem.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002841; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"palochusvet.szm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002842; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"panslimiterd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002843; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parallel.rockvideos.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100002844; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parejasfelices.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002845; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parkhussion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002846; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pastorpaulocosta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002847; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.51lg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002848; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002849; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch3.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002850; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paths.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002851; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patriotsupremehemp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002852; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paulmercier.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002853; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payerrealty.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002854; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payments.atifsiddiqui.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100002855; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pcsoori.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002856; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pd.oceaniarp.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002857; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pemdodo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002858; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perfumeriamontes.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002859; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"periodiche.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002860; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpus.onlineman7-jombang.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002861; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpustekim.untirta.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002862; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pestoclean.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002863; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"petercollie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002864; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ph4s.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002865; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phasdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002866; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phenhuong.sanpham.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100002867; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phittc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002868; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"photo360.kubooking.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002869; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pink99.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002870; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"plasfan.ind.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002871; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"playground2.grupoaliadasca.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002872; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pmglance.startwriteup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002873; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pokojewewladyslawowie.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002874; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pole.com.vc"; content:"Host"; http_header; classtype:trojan-activity; sid:100002875; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pool.phxdir.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002876; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pooltablemoversdenver.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002877; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"posmicrosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002878; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"poulman.panagiotopoulos-tours.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002879; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ppdb.smk-ciptaskill.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002880; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestasicash.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002881; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestigehomeautomation.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002882; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"preview2.behalen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002883; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prishaartcreations.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002884; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"production.sparshims.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002885; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"programaoperadoronline.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002886; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"project.exquitec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002887; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promotoradescomplica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002888; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promoversdubai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002889; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002890; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002891; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosoc.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002892; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosyarmakassar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002893; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"provence.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002894; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prox.realunix.cc"; content:"Host"; http_header; classtype:trojan-activity; sid:100002895; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pujashoppe.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002896; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punchdialogues.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002897; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punjabdevelopersassociation.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002898; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qadir.tickfa.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100002899; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qatarglobalconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002900; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qmsled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002901; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qu.o.t.ev.v.n.r@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002902; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"quartier-midi.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100002903; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"querocar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002904; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rachmat-assuhaimi.my.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002905; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"radioafifense.deploys.live"; content:"Host"; http_header; classtype:trojan-activity; sid:100002906; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rainbowisp.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002907; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rajeshtailang.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002908; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakeshkhatri.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002909; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"raodigitalmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002910; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"raquelhelena.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002911; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rarlabarchiver.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100002912; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rasadbar.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100002913; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rashika.ascarvalho.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002914; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ratemyfenancialadvisor.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002915; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ravenproductionsltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002916; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ravo.net.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002917; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rc.ixiaoyang.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002918; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rcmesilva.charbelsales.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002919; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reacredit.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002920; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"readwrite26.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002921; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"readymmade.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002922; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"recyclethesurplus.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002923; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redbats.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002924; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redchillicrackers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002925; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reifenquick.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002926; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"relaxindulge.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002927; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"renehavis.com.ua"; content:"Host"; http_header; classtype:trojan-activity; sid:100002928; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"repatriacioncolombia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002929; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"res.uf1.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002930; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reseller.digimitra.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002931; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reseller.itechbrasil.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002932; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"resuco.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002933; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"revolet-sa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002934; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rezkabum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002935; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rhema.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002936; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richmondminerals.co.zm"; content:"Host"; http_header; classtype:trojan-activity; sid:100002937; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinaefoundation.org.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002938; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinkaisystem-ht.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002939; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"riverfox.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002940; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkcable.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002941; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkverify.securestudies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002942; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertmcardle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002943; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertsinclair.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002944; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"romanianpoints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002945; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ronnietucker.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002946; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roomsvc.servegate.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002947; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roshnijewellery.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002948; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rsgym.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002949; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubazar.pro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002950; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubycityvietnam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002951; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruisgood.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002952; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruwadalkuwait.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002953; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.51shijuan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002954; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.hu.d.es.h.d.u.e54.78.16247@46.249.33.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002955; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.thechinesemuslim.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002956; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sacredscentsonline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002957; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sadmahfuneralservices.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002958; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safcol-colors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002959; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safehubsecurity.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100002960; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safety.nanotechproautocare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002961; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sahathaikasetpan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002962; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sainzim.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002963; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"saisoftwareinc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002964; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"salecorner.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002965; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"salonsaifa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002966; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"samriddhijyotish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002967; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sandovalgraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002968; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"santyago.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002969; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sasystemsuk.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002970; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scarfaceindustries.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002971; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scglobal.co.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100002972; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schalke04rss.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002973; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scheff.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002974; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schoolbustracker.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002975; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sculetus.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002976; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-doc-reader.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002977; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"segalsmetals.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002978; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sellmyphonela.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002979; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"selltechtoday.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002980; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"senbiaojita.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002981; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sentierodelviandante.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100002982; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serendibsourcing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002983; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sericaasia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002984; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002985; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002986; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sexologistpakistan.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002987; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgessy.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002988; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shaheentbfoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002989; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shahikhana.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002990; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shahu66.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002991; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shalombaptistchapel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002992; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharkrigs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002993; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharpelevators.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002994; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shembefoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002995; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shidditourism.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002996; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shivakunwar.com.np"; content:"Host"; http_header; classtype:trojan-activity; sid:100002997; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shoblasaathitrust.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002998; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shomalhouse.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002999; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shooka-co.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003000; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shop.goldspot.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100003001; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shopsofe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003002; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sibernetix.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003003; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sige.brisainformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003004; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"signatureads.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003005; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siili.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003006; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simoneporzi.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100003007; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simorsint.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003008; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simplithy.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003009; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindicato1ucm.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003010; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindpol.tiejuris.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003011; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sipahielektrik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003012; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sistelligent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003013; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyflyfares.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003014; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyscan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003015; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"slot0.gamoruz.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003016; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarthouseforum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003017; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartzedu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003018; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smokesolutionindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003019; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smritiphotography.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003020; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobariko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003021; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobethuacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003022; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.110route.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003023; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.officelabo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003024; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sogecoenergy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003025; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sohs.conceptechs.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003026; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"solar.amazingtribe.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003027; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somcorbera.cat"; content:"Host"; http_header; classtype:trojan-activity; sid:100003028; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somir.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003029; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soralapps.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003030; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sota-france.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003031; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"space.proactint.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003032; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spaceframe.mobi.space-frame.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003033; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"special-key.cf"; content:"Host"; http_header; classtype:trojan-activity; sid:100003034; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spent.com.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003035; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spetsesyachtcharter.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003036; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spititourism.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003037; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spittinfire.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003038; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"springbedspetroleum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003039; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"src1.minibai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003040; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sreenivasapaintingworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003041; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sriglobalit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003042; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"srilankamovies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003043; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"srvmanos.no-ip.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003044; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ss.monita.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003045; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"st.devcodin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003046; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"staging.apparelpunch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003047; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"starcountry.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003048; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"static.3001.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003049; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stiau.iuc.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100003050; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sticker.jewsjuice.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003051; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stiepancasetia.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003052; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stlukesohag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003053; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"store.ericalgarin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003054; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stott-thompson.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003055; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"streetdemo.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003056; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"suboldesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003057; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sumerians.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003058; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunaryem.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003059; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunmarkholidays.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003060; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-4-free.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003061; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support.clz.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003062; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supportit.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100003063; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sw.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003064; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweaty.dk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003065; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweet-diet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003066; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swiftlogisticseg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003067; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swwbia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003068; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"syracusecoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003069; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sytraders.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003070; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.honker.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003071; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tadoo.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003072; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tafsantoursandtravels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003073; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tajushariya.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003074; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tallyinvoicecustomization.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003075; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taltus.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003076; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tapalkoedacoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003077; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tarravalleyfoods.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003078; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taurus.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003079; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tc.snpsresidential.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003080; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tcy.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003081; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tdsp.yngw518.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003082; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"techgms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003083; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teduae.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003084; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teleargentina.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003085; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"telescopelms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003086; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"temptmag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003087; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tencoconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003088; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teneth.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003089; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tentandoserfitness.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003090; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tessrobins.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003091; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.adventser.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003092; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.letraele.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100003093; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.lubrico.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003094; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.protocsconnectes.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003095; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003096; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.wanepghana.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003097; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.asistencia247.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003098; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.milenial.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003099; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100003100; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.basis-web.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003101; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.marrenconstruction.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100003102; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.clickitsolutionsmw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003103; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.thinkingcorp.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003104; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testnew.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003105; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teteaffiche.stephanebillon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003106; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tewoerd.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003107; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"textile.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003108; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tharringtonsponsorship.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003109; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecleaningladiespdx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003110; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecreativecafe.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003111; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thedesertship.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003112; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefamouscurrybazaar.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003113; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefuturelife.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003114; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thehighlightinterior.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003115; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thekassia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003116; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"themansionkasauli.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003117; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theprofinn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003118; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thesummitpc.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003119; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theurbantutors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003120; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thosewebbs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003121; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thriveink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003122; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tianangdep.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003123; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickfoods.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003124; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tidymasters.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003125; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"timegonebuy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003126; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tksb.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003127; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tlcc.com.gt"; content:"Host"; http_header; classtype:trojan-activity; sid:100003128; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"todoapp.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003129; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonydong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003130; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonyzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003131; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tooba.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100003132; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tools.reimclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003133; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topcell9.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003134; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toplevel.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003135; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topmask.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003136; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"torresquinterocorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003137; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"towme.services"; content:"Host"; http_header; classtype:trojan-activity; sid:100003138; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toyotacollege.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003139; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpke.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003140; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"translaterjemah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003141; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"travelwithmanta.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003142; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trendyshoes.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003143; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trezors.io.mahlongwa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003144; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trimestre.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003145; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"troki.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003146; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tropics.codeleek.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003147; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trudelfavreau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003148; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsd.jxwan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003149; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tulli.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003150; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tupperware.michaelroberge.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003151; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"turanggaresources.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003152; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uat.indianfilmzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003153; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ublretailerdemo.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003154; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uc-56.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003155; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uisusa.uisusa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003156; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ultimate-24.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003157; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"umwelt-kirchhof.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003158; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unicorpbrunei.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003159; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uniengrisb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003160; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"union.jctrip.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003161; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unyazitelecom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003162; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"up.llw0.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003163; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"upcbpta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003164; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"used-jeans.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003165; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"useformoney.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003166; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uss.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003167; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uzzepay.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003168; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vanzare.cabanabrazi2.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003169; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vbcargo.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003170; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vcah.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003171; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vectarts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003172; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vegadelcasero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003173; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"velma-harber30ku.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003174; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vendas.lidiacarmeli.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003175; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"veterinariadrpopui.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003176; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vfocus.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003177; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vienen.gblix.srv.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003178; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vilaart.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100003179; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villamarand.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003180; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villatera.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003181; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"violinstop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003182; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"virtuleverage.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003183; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visions.alnisamart.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003184; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visualhome.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003185; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vivationdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003186; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"viveirodoiscorregos.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003187; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vksales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003188; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vocalterra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003189; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vokasi.ub.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003190; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vologroup.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003191; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"voteyouramerica.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003192; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vpts.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003193; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vstsample.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003194; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vtube.fadlymotivator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003195; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vvsskmodinationalschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003196; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003197; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepliberia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003198; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepniger.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003199; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weareactum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003200; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.eng.ubu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003201; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geomegasoft.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003202; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.newinnovationtechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003203; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.smarts-works.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003204; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003205; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webgis.perumdasolo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003206; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webpresario.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003207; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weinsteincounseling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003208; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wfinance.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003209; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whcms.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003210; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteresponse.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003211; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wi522012.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003212; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wikalen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003213; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildnights.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003214; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildtrust.mediadevstaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003215; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"willow-nettica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003216; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wimbamusica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003217; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"windcomtechnologies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003218; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wishesconcierge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003219; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woezon.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100003220; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wolfgang-brodte.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003221; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woodsytech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003222; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wordpress.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003223; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wozata.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003224; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wp.readhere.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003225; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wpdemo.101clients.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003226; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"writtendeer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003227; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ws5588.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003228; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wyklej.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003229; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"x2vn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003230; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xia.beihaixue.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003231; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xixaoclothing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003232; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xk.996is.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003233; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--polimerbizmimarlk-rvc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003234; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ybom.urbanolab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003235; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yeichner.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003236; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yeq.i.u.j.ia.n.3@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003237; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ylfpremium.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003238; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yoast.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003239; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yummyyogaudaipur.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003240; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yzkzixun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003241; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ziyker4gaming@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003242; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zmedcoach.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003243; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003244; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zz.690tx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003245; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100003246; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/86.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100003247; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; http_uri; nocase; content:"amumufree.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003248; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/files/proxyi.exe"; http_uri; nocase; content:"analogx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003249; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003250; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dvdfv/anjj/downloads/jami.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003251; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/heyhoeee/heyhoename1/downloads/1234.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003252; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/4.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003253; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/6.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003254; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/labesoftware/update/downloads/boost-fps.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003255; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/labesoftware/update/downloads/install_plugin_x64_x86.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003256; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/labesoftware/update/downloads/vpn_free.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003257; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/clr.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003258; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/dianthus.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003259; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/n.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003260; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/newred.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003261; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/omar.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003262; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/serv.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003263; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/test.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003264; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updachrome.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003265; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatedata.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003266; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatev.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003267; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/work.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003268; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/component.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003269; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003270; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/regsvc.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003271; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/skygaming/updates/downloads/update.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003272; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/001.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003273; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1488.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003274; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1_cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003275; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003276; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1fc2d.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003277; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/26a5.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003278; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003279; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/abjects.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003280; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/attached.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003281; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/b7f2c.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003282; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/battletext.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003283; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003284; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003285; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003286; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_makros.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003287; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_silent.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003288; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_sup.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003289; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003290; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003291; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003292; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildss.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003293; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientnik.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003294; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientrevers.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003295; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dcrat.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003296; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003297; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003298; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003299; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hans.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003300; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hulu.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003301; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfive.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003302; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfour.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003303; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelone.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003304; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelthree.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003305; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/inteltwo.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003306; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003307; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/kleiman.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003308; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003309; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/notepadplus.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003310; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003311; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003312; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003313; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003314; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/putty.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003315; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/rockethcd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003316; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/scvhost900.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003317; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/sessionwin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003318; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/siliculose.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003319; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/statemobi.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003320; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003321; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003322; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stgedo.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003323; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/svcperf.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003324; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003325; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurjok.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003326; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurusbabac.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003327; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/telekiller.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003328; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateanddr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003329; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateandr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003330; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/vhajeja.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003331; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/word.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003332; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/www.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003333; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/xlsd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003334; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003335; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003336; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hmatrix/data/hack1226.exe"; http_uri; nocase; content:"cd.textfiles.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003337; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/712408764354920490/829413679866839120/echelon_protected.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003338; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003339; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/816070119281131570/816070273254162442/all.txt"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003340; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/826848185246023750/loaddd.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003341; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/826848348342059008/zeppelin.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003342; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/826848405258633277/build.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003343; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/826198252025675816/826537386485612574/china.png"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003344; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003345; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003346; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/829721030112182363/829724335526510622/dcratbuild.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003347; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/razor/rzr-winner_intro.zip"; http_uri; nocase; content:"chiptune.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003348; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003349; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003350; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/meteoradminz/hidden-tear/zip/master"; http_uri; nocase; content:"codeload.github.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003351; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; http_uri; nocase; content:"colfincas.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003352; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ktcghnmcwws43wzscphukbfnwtuaxidx&revid=0b8z0b7_i5sirk2xrtehmstg0vxvit3b4n3lmbdrdrjrodndrpq"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003353; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1qze6qzzh1uf7iaj4rqixttznx6u1--gc&revid=0b45wwmcofx7fuvnmdhpkt1d0k3rhzldyoffnuc83auzkslvrpq"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003354; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; http_uri; nocase; content:"drive.google.com.it-barcelona.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003355; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003356; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=11idvvx22jx_1lw-hxnpmlwuvjgdyp63g"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003357; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=12khl-unz2np4q54b2jgpwlsh6cuz0pss"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003358; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003359; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003360; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=16yyvhney9_-nygeipjqgnlcmwfoyiaxo"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003361; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=17pl-4i0otjbyxwrtrdagxxebirdh2wl8"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003362; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003363; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003364; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1br5iufkkmmfeipqo3ecviqykbcdgcnio"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003365; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1bwtwpqmeqdvctbcqcc2gil5xzjf28c0z"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003366; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003367; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003368; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1d0ij6qkgrf6irywv6ftk1m7p5l3weh3a"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003369; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1gprlk2mcrl6law-zk5r0pjogaqrxwepd"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003370; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003371; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003372; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1jdqcxydqvz3bjodp66ieiocbjcz8foi6"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003373; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1l5urks5wzib2zcb16bfsk76bjrdsejms"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003374; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ldxaekbcbzb-zfdix-ucj4rilobnbswx"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003375; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ljz-kmuibyiehba6blw37guu_yr799y0"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003376; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1lsv4sko083sywwjndgqnsh_6sgqodqtu"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003377; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003378; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003379; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003380; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1oek6vmzbv15nyho_uqcbk4_vaq1ezowv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003381; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ph-lri07dohowhmuczrrvjwrtsvmnu9s"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003382; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003383; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1r1flwyfwtyziyr47y5sk3q821r6_tgsl"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003384; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1r9f9irwhutxozsbp2h9erd_a7fa2pwko"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003385; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1s221a6wpx6i7nfrztnhh9priojtybuxq"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003386; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1sutnyikgc4qw-tbvnnvzm8uz9thch0vz"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003387; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003388; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1taubixyqiqdgfbhmc2rv_aitvkbqhzwz"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003389; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1tpd_qbnl_mtmhfsv4a-qtfsnuiimyoy6"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003390; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003391; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vjq92eqivh01yxmal20whl2es3ld6nxb"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003392; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1voqnsh0cmxl5hty4zpc18pgnkud5rtvy"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003393; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vy1nx5zefluh5ewihr-6pcndlyex7xcm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003394; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1wpqa2nnnktbhzs4j0r-erosvgyaagi_a"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003395; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003396; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003397; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003398; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003399; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ywkgalidldb32pio6ywmbyvdk7oar3yy"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003400; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003401; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003402; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/1zilg/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003403; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/qcgfmfvh/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003404; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/emclick.zip"; http_uri; nocase; content:"e-mudhra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003405; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe"; http_uri; nocase; content:"evertkok.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003406; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe"; http_uri; nocase; content:"evertkok.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003407; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003408; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003409; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/x/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003410; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003411; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003412; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003413; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003414; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; http_uri; nocase; content:"file.elecfans.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003415; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003416; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003417; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; http_uri; nocase; content:"gist.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003418; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; http_uri; nocase; content:"hqdecig.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003419; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/suy/"; http_uri; nocase; content:"hsecaravans.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003420; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/19/items/startup_20210219/startup.txt"; http_uri; nocase; content:"ia801802.us.archive.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003421; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/online-timer-kvhxz/ilxl/"; http_uri; nocase; content:"ie-best.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003422; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100003423; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ebook/cs17.exe"; http_uri; nocase; content:"jcedu.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003424; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003425; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003426; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003427; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; http_uri; nocase; content:"karmakoincodes.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003428; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ds/index.html"; http_uri; nocase; content:"kautilyaclasses.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003429; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dg/etrac/nf4emwz/"; http_uri; nocase; content:"kotakwarna.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003430; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe"; http_uri; nocase; content:"ksh.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003431; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/down/affiliate/kuaizip_setup_10029.exe"; http_uri; nocase; content:"kuaizip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003432; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/linuxforensicscode.zip"; http_uri; nocase; content:"linuxforensicsbook.com.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003433; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dl8.exe"; http_uri; nocase; content:"lojavirtual.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100003434; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dl8v2.exe"; http_uri; nocase; content:"lojavirtual.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100003435; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/k/big5/1giof6/"; http_uri; nocase; content:"minpic.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003436; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-contentbak/t9m/"; http_uri; nocase; content:"morrobaydrugandgift.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003437; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; http_uri; nocase; content:"my.cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003438; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/aacenc.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003439; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/doxillionsetup.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003440; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/4/1/6/6/4166984/keygen.exe"; http_uri; nocase; content:"newyarlfm.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003441; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; http_uri; nocase; content:"nhipcauytevietnhat.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003442; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; http_uri; nocase; content:"note.youdao.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003443; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; http_uri; nocase; content:"oldschoolvalue.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003444; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20cid=ba02d68febf523dc&resid=ba02d68febf523dc!1431&authkey=afbifi7o9ywbjpm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003445; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20cid=ba02d68febf523dc&resid=ba02d68febf523dc%211431&authkey=afbifi7o9ywbjpm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003446; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003447; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003448; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003449; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003450; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003451; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003452; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003453; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003454; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003455; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003456; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003457; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003458; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003459; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003460; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003461; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003462; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003463; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003464; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003465; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003466; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003467; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003468; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003469; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003470; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003471; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003472; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003473; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d!184&authkey=ackbiiarirejcam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003474; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d%21184&authkey=ackbiiarirejcam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003475; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003476; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003477; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003478; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003479; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0!1667&authkey=an8otd7jzc7xgho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003480; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0%211667&authkey=an8otd7jzc7xgho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003481; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003482; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003483; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003484; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003485; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003486; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003487; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003488; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=15d9646f4dbf9553&resid=15d9646f4dbf9553%21110&authkey=ag0eg1lha_lwgi0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003489; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003490; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003491; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003492; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003493; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003494; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003495; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003496; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003497; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003498; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003499; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003500; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003501; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003502; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003503; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003504; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003505; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003506; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba!112&authkey=afjxmbcllibdbvo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003507; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba!114&authkey=adecqvkvvvadznc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003508; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba%21112&authkey=afjxmbcllibdbvo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003509; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba%21114&authkey=adecqvkvvvadznc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003510; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=216ef243e34992b8&resid=216ef243e34992b8!330&authkey=apiugomnim7heom"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003511; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=216ef243e34992b8&resid=216ef243e34992b8%21330&authkey=apiugomnim7heom"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003512; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=23423a594eafc2de&resid=23423a594eafc2de%21130&authkey=aeh1dm0c-5hp44a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003513; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003514; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003515; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003516; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003517; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003518; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003519; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003520; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003521; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003522; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b!287&authkey=advpfy_0ry8upmi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003523; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b!288&authkey=aembucxemjjo3bk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003524; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b%21287&authkey=advpfy_0ry8upmi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003525; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b%21288&authkey=aembucxemjjo3bk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003526; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003527; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003528; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003529; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003530; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003531; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003532; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003533; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003534; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003535; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003536; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003537; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003538; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3004cdd743a543f5&resid=3004cdd743a543f5%21170&authkey=ao8vz-4rkwuiyn8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003539; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003540; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003541; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003542; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003543; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003544; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003545; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1!223&authkey=aajr842bzum0yg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003546; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003547; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003548; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003549; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003550; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003551; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003552; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003553; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003554; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003555; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003556; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003557; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003558; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003559; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003560; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003561; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003562; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003563; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003564; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3ee68228c34c236d&resid=3ee68228c34c236d%21129&authkey=apll6hu3-xetzxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003565; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003566; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003567; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003568; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003569; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003570; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003571; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003572; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003573; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003574; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003575; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21141&authkey=aazwaw2xjms24o0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003576; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21145&authkey=aaenjqj018fjmc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003577; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003578; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003579; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003580; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003581; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003582; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003583; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003584; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003585; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003586; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003587; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003588; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003589; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003590; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003591; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003592; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003593; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003594; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003595; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003596; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003597; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003598; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003599; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003600; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003601; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003602; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003603; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003604; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003605; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003606; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003607; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003608; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003609; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003610; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003611; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003612; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003613; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003614; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003615; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003616; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003617; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003618; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003619; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003620; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003621; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003622; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003623; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003624; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003625; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003626; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003627; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003628; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003629; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003630; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003631; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003632; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003633; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003634; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003635; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003636; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003637; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003638; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003639; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003640; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003641; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003642; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003643; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003644; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003645; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003646; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003647; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003648; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003649; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003650; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003651; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003652; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003653; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003654; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003655; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003656; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003657; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003658; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003659; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003660; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003661; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003662; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003663; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003664; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003665; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003666; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003667; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003668; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003669; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003670; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003671; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003672; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003673; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003674; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003675; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003676; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003677; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003678; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003679; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003680; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003681; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003682; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003683; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003684; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003685; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003686; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003687; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003688; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003689; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003690; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003691; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003692; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003693; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003694; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003695; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003696; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003697; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003698; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003699; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003700; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003701; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003702; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003703; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003704; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003705; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003706; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003707; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003708; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003709; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003710; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003711; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003712; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003713; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003714; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003715; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003716; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003717; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003718; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003719; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003720; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003721; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003722; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003723; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003724; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003725; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003726; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003727; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003728; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003729; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003730; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003731; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003732; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003733; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003734; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003735; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003736; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003737; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003738; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003739; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=855b20b0e8399717&resid=855b20b0e8399717%21110&authkey=afhxx21ztsd7hbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003740; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003741; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003742; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003743; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003744; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003745; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003746; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003747; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003748; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003749; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003750; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003751; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003752; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003753; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003754; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003755; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!112&authkey=af43qpcgl0t2f5o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003756; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003757; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003758; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003759; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003760; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003761; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003762; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003763; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003764; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003765; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003766; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003767; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003768; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003769; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003770; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003771; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003772; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003773; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003774; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003775; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003776; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003777; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003778; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003779; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003780; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003781; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003782; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003783; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003784; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003785; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003786; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003787; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003788; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003789; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003790; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21256&authkey=aapnly5qifymcvw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003791; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003792; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003793; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003794; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003795; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003796; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003797; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003798; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003799; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003800; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818!129&authkey=aesewk3cf5vbrxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003801; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818%21129&authkey=aesewk3cf5vbrxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003802; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003803; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5!2423&authkey=aoiqjwenlzfiqe0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003804; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212417&authkey=aa2zjoxjz1c83ns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003805; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212418&authkey=akjeumqon_fyj9c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003806; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212423&authkey=aoiqjwenlzfiqe0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003807; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003808; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003809; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003810; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003811; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003812; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003813; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003814; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003815; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003816; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003817; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003818; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003819; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003820; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003821; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003822; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003823; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003824; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003825; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003826; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003827; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003828; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003829; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003830; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003831; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003832; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003833; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ba02d68febf523dc&resid=ba02d68febf523dc%211431&authkey=afbifi7o9ywbjpm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003834; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1047&authkey=aod6jbxyicq2v4g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003835; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211047&authkey=aod6jbxyicq2v4g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003836; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003837; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003838; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003839; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003840; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003841; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003842; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c29fdbf45b3d2671&resid=c29fdbf45b3d2671%21608&authkey=aafwhzmybg1czta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003843; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003844; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003845; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003846; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003847; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003848; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003849; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003850; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003851; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003852; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003853; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003854; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003855; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003856; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003857; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003858; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003859; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003860; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003861; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003862; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003863; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003864; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003865; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003866; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003867; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003868; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003869; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003870; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!357&authkey=alw3vqqxz6myrle"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003871; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!362&authkey=alycl9izrvfl7oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003872; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21354&authkey=aa_ukeour7rex1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003873; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21355&authkey=aajjwf_sm4xdqdk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003874; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21357&authkey=alw3vqqxz6myrle"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003875; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21362&authkey=alycl9izrvfl7oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003876; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003877; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003878; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003879; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003880; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003881; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003882; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003883; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003884; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003885; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003886; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003887; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003888; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003889; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003890; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003891; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d4d413b6e7cf7088&resid=d4d413b6e7cf7088%211271&authkey=akz65bxpgvdxjb8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003892; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003893; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003894; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003895; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003896; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003897; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003898; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003899; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003900; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003901; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003902; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003903; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003904; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003905; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003906; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003907; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003908; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003909; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003910; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003911; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003912; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003913; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2!107&authkey=af-bicrg1c6vgck"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003914; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2%21107&authkey=af-bicrg1c6vgck"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003915; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003916; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003917; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003918; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003919; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003920; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003921; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003922; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003923; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003924; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003925; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003926; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003927; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003928; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003929; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003930; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003931; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003932; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003933; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003934; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003935; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003936; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003937; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003938; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003939; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003940; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003941; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003942; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003943; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003944; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003945; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003946; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003947; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003948; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003949; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003950; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003951; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003952; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003953; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003954; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003955; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003956; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003957; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003958; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003959; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003960; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003961; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003962; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003963; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003964; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21848&authkey=ag1_e421v-t5r9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003965; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003966; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003967; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003968; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003969; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003970; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003971; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003972; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003973; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003974; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003975; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003976; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/77jhk0iw"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003977; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/89hkc7wb"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003978; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/yqvsvlvq"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003979; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/llc/mwcacs65xienqdp/"; http_uri; nocase; content:"pierreconsulting.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003980; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skoda22.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003981; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003982; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; http_uri; nocase; content:"qjbutterflyevents.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003983; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003984; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003985; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003986; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003987; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003988; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003989; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/myqseeaccount/one/main/one.htm"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003990; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003991; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003992; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003993; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tennc/webshell/master/other/small_shell.txt"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003994; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; http_uri; nocase; content:"res.yeshen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003995; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/q05z91"; http_uri; nocase; content:"sendspace.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003996; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ey4lpx8rx.zip"; http_uri; nocase; content:"shribharatvatika.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003997; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003998; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003999; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004000; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004001; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004002; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004003; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004004; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004005; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004006; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004007; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004008; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a-nurse-ss8d9/z/"; http_uri; nocase; content:"technologydistilled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004009; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/crisanar/defis/jek_crackme1.7.zip"; http_uri; nocase; content:"users.skynet.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100004010; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/amowvegfrt9ja/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004011; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004012; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004013; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004014; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004015; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb%5efr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004016; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb^fr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004017; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004018; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/151_155/tidex_-_short_stuff.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004019; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/syria-files/attach/222/222051_instruction.zip"; http_uri; nocase; content:"wikileaks.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004020; rev:1;) -alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/common/yz.vbs"; http_uri; nocase; content:"yp.hnggzyjy.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004021; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.139.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001515; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.212.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001516; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.253.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001517; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.71.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001518; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.98.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001519; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.144.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001520; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.225.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001521; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.227.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001522; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.234.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001523; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.191.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001524; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.135.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001525; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.132.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001526; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.160.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001527; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.176.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001528; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.83.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001529; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.20.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001530; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.249.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001531; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.83.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001532; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.85.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001533; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.221.239.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001534; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.221.242.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001535; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.76.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001536; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.223.242.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001537; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.129.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001538; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.154.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001539; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.212.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001540; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.58.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001541; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.40.79.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001542; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.36.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001543; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.0.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001544; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.11.51.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001545; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.13.23.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001546; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.124.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001547; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.146.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001548; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.16.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001549; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.179.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001550; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.184.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001551; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.191.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001552; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.194.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001553; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.216.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001554; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.219.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001555; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.24.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001556; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.30.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001557; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.65.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001558; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.79.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001559; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.94.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001560; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.179.201.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001561; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.195.84.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001562; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001563; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.28.7.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001564; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.30.119.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001565; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32.208.157.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001566; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32792.prolocksmithwinterpark.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100001567; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"34.122.44.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001568; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"34.126.93.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001569; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"35.184.169.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001570; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.108.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001571; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.248.83.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001572; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.250.203.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001573; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.157.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001574; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.18.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001575; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.51.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001576; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.255.90.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001577; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.32.28.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001578; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.160.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001579; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.34.150.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001580; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.65.216.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001581; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.105.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001582; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.133.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001583; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.139.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001584; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.89.18.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001585; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.91.89.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001586; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360.lcy2zzx.pw"; content:"Host"; http_header; classtype:trojan-activity; sid:100001587; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360down7.miiyun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100001588; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.222.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001589; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.233.60.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001590; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.179.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001591; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.180.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001592; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.44.238.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001593; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.116.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001594; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.14.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001595; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.245.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001596; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.98.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001597; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.114.137.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001598; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.117.31.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001599; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.162.104.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001600; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.162.98.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001601; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.164.112.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001602; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.196.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001603; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001604; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.125.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001605; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.146.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001606; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.206.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001607; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.171.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001608; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.249.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001609; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.60.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001610; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.167.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001611; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.67.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001612; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.10.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001613; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.163.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001614; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.168.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001615; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.203.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001616; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.215.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001617; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.194.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001618; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.78.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001619; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.113.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001620; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.114.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001621; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.150.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001622; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.123.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001623; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.166.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001624; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.218.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001625; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.91.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001626; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.93.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001627; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.127.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001628; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.18.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001629; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.191.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001630; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.205.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001631; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001632; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.36.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001633; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.37.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001634; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.251.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001635; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.27.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001636; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.29.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001637; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.70.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001638; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.83.185.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001639; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.83.94.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001640; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.115.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001641; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.85.54.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001642; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.211.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001643; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.234.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001644; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.78.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001645; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.93.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001646; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.96.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001647; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.143.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001648; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.233.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001649; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.67.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001650; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.72.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001651; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.145.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001652; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001653; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.63.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001654; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.90.86.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001655; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"40.88.2.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001656; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.139.209.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001657; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.165.130.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001658; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.193.192.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001659; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.219.185.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001660; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.226.60.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001661; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.72.203.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001662; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.76.157.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001663; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001664; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001665; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001666; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001667; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001668; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001669; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001670; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.202.101.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001671; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.202.101.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001672; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.171.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001673; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.176.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001674; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.254.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001675; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.4.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001676; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.222.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001677; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.225.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001678; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.40.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001679; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.143.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001680; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.233.97.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001681; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.84.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001682; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.161.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001683; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.212.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001684; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.237.114.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001685; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.238.141.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001686; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.61.99.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001687; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.82.217.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001688; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.230.207.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001689; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.241.106.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001690; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.252.8.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001691; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.203.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001692; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.135.134.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001693; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001694; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001695; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001696; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.224.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001697; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.141.84.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001698; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001699; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001700; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001701; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001702; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001703; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001704; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.15.143.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001705; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001706; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.109.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001707; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.110.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001708; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001709; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.22.209.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001710; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.229.53.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001711; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.27.253.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001712; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.51.104.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001713; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.77.9.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001714; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.85.90.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001715; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.9.148.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001716; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.92.108.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001717; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.95.169.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001718; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.95.169.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001719; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.95.169.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001720; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.172.75.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001721; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.182.173.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001722; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.20.63.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001723; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.214.27.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001724; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.214.35.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001725; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.236.65.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001726; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.24.130.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001727; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.241.120.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001728; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.243.179.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001729; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.249.33.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001730; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.25.242.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001731; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.118.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001732; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.86.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001733; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.97.76.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001734; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.136.96.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001735; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.145.152.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001736; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.157.97.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001737; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.16.131.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001738; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.21.202.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001739; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.46.231.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001740; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.162.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001741; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.87.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001742; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.143.43.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001743; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.156.35.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001744; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.158.201.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001745; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.158.201.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001746; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.20.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001747; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.21.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001748; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.174.182.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001749; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.170.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001750; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.178.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001751; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.179.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001752; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.14.122.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001753; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.188.62.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001754; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.95.226.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001755; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.115.174.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001756; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.115.174.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001757; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.121.91.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001758; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.247.83.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001759; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.252.47.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001760; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.89.77.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001761; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.114.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001762; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.180.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001763; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.114.246.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001764; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.162.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001765; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.174.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001766; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.125.191.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001767; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.126.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001768; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.141.122.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001769; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.166.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001770; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.200.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001771; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.218.67.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001772; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.22.212.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001773; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.226.129.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001774; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.230.89.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001775; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.237.125.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001776; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.238.42.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001777; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.240.147.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001778; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.241.78.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001779; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.242.91.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001780; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.22.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001781; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.75.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001782; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.75.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001783; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.77.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001784; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.80.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001785; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.253.15.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001786; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.51.219.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001787; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001788; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001789; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.0.211.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001790; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.102.168.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001791; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.202.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001792; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.214.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001793; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.173.135.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001794; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.175.63.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001795; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.23.114.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001796; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.26.181.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001797; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.30.12.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001798; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.50.23.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001799; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.89.242.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001800; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.217.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001801; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.218.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001802; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.21.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001803; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.21.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001804; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.94.182.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001805; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.95.175.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001806; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.170.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001807; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.13.61.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001808; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.122.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001809; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.216.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001810; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.233.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001811; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.6.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001812; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.80.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001813; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001814; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.111.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001815; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.206.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001816; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.218.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001817; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.220.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001818; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.254.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001819; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.83.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001820; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.214.53.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001821; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.214.85.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001822; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.177.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001823; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.86.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001824; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.4.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001825; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.51.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001826; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.60.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001827; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001828; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.10.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001829; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.8.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001830; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.146.108.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001831; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.163.131.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001832; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.91.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001833; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.247.224.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001834; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.150.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001835; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.101.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001836; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.186.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001837; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.241.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001838; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.57.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001839; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.9.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001840; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.97.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001841; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.98.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001842; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.99.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001843; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.117.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001844; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.103.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001845; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.180.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001846; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.181.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001847; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.57.96.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001848; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.170.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001849; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.73.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001850; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.61.218.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001851; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.65.172.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001852; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.0.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001853; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.104.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001854; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.110.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001855; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001856; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.255.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001857; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.45.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001858; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.98.144.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001859; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.1.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001860; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.141.73.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001861; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.131.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001862; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001863; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.31.126.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001864; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.149.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001865; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.43.207.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001866; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.90.165.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001867; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"63.245.122.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001868; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"64.233.154.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001869; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.125.128.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001870; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.26.155.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001871; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.35.61.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001872; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.108.199.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001873; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.57.55.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001874; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.74.7.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001875; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.97.181.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001876; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.245.151.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001877; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.8.138.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001878; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.83.49.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001879; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.84.138.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001880; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.148.103.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001881; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.174.182.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001882; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.175.107.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001883; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.188.144.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001884; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.204.88.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001885; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.119.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001886; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.78.33.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001887; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.115.37.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001888; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.120.237.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001889; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.123.245.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001890; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.124.231.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001891; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.127.214.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001892; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.146.232.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001893; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.165.173.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001894; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.196.158.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001895; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.222.157.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001896; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.229.0.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001897; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.63.73.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001898; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.115.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001899; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.227.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001900; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.76.240.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001901; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.115.31.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001902; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.118.240.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001903; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.167.10.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001904; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.236.190.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001905; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.25.5.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001906; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.93.129.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001907; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.127.148.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001908; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.146.190.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001909; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.204.63.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001910; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.34.191.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001911; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.40.234.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001912; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.106.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001913; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.2.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001914; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.235.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001915; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.47.133.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001916; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.71.60.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001917; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.85.106.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001918; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.17.22.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001919; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.180.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001920; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.200.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001921; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.202.249.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001922; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.214.69.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001923; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.229.230.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001924; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.31.40.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001925; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.112.123.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001926; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.204.216.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001927; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.31.139.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001928; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.70.164.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001929; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.101.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001930; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.108.224.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001931; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.195.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001932; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.199.84.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001933; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.64.139.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001934; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.75.165.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001935; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.127.141.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001936; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.83.102.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001937; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.99.213.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001938; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.170.11.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001939; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.178.22.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001940; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.217.92.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001941; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.250.199.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001942; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.254.129.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001943; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.84.134.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001944; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.89.107.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001945; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.95.12.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001946; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.237.25.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001947; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.50.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001948; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.89.203.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001949; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77st.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100001950; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.138.98.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001951; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.145.224.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001952; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.41.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001953; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.106.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001954; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.168.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001955; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.188.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001956; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.104.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001957; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.176.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001958; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.27.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001959; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.23.172.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001960; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.8.225.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001961; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.11.195.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001962; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.147.123.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001963; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.175.42.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001964; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.21.84.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001965; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.7.170.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001966; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.79.58.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001967; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.8.70.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001968; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.9.88.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001969; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.107.89.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001970; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.19.101.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001971; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.211.181.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001972; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.99.128.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001973; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.136.146.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001974; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.165.44.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001975; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.191.40.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001976; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.198.7.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001977; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.141.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001978; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.215.199.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001979; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.187.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001980; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.195.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001981; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.229.230.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001982; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.244.219.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001983; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.246.225.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001984; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.30.177.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001985; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.92.36.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001986; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.103.108.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001987; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.135.196.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001988; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.85.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001989; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.207.61.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001990; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.209.250.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001991; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.211.156.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001992; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.59.31.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001993; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.110.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001994; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.53.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001995; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.138.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001996; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.139.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001997; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.154.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001998; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.187.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001999; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.100.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002000; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.102.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002001; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.106.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002002; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.108.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002003; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.131.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100002004; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.134.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002005; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.19.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002006; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.197.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002007; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.215.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002008; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.232.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002009; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.234.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002010; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.246.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002011; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.28.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002012; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.4.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002013; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.55.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002014; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.73.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002015; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002016; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.165.237.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002017; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.147.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100002018; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.218.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002019; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.242.253.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002020; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.252.9.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002021; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.210.219.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002022; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.50.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002023; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.95.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002024; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.238.24.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002025; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.247.83.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002026; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.254.39.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002027; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.33.111.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002028; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.40.127.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002029; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.42.20.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002030; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002031; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.11.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100002032; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.123.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002033; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.135.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002034; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.180.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002035; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.208.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002036; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.224.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002037; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.241.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002038; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.214.149.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002039; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.241.39.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002040; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.250.147.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002041; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.64.181.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002042; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.74.215.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002043; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.130.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002044; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"86.35.43.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002045; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"86.98.23.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100002046; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.117.11.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002047; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.172.19.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002048; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.251.71.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100002049; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87du.vip"; content:"Host"; http_header; classtype:trojan-activity; sid:100002050; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.119.171.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002051; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.129.208.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100002052; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.208.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002053; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.219.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100002054; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.218.17.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002055; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.225.222.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002056; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.247.96.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002057; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.51.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002058; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.249.13.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002059; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.249.244.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002060; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.204.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002061; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.226.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002062; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.240.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002063; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.254.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002064; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.122.183.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002065; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.136.197.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002066; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.22.152.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002067; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.237.84.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002068; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.248.112.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002069; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.29.213.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002070; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.85.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002071; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.87.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002072; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8poieq.bn.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002073; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"90.152.144.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002074; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.132.197.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002075; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.177.139.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002076; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.187.103.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002077; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.212.150.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002078; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.217.104.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100002079; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.233.112.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002080; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.234.60.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002081; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.244.169.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002082; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.92.16.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002083; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.114.191.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002084; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.241.78.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002085; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.27.246.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002086; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.54.237.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002087; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.83.62.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002088; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.85.18.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002089; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.157.63.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002090; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.159.169.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002091; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.173.235.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100002092; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.21.224.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002093; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.39.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100002094; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.39.79.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002095; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.137.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002096; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.182.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002097; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.206.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002098; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.57.43.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002099; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.73.99.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002100; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.136.69.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002101; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.143.53.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002102; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.17.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002103; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.82.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002104; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.200.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002105; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.224.83.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002106; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.53.120.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002107; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.85.0.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002108; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.132.129.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002109; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.133.158.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002110; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.158.19.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002111; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.113.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002112; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.201.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002113; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.60.146.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002114; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.66.196.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002115; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.9.111.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002116; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.9.120.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002117; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.239.73.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002118; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.47.147.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002119; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.68.140.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002120; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.96.199.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100002121; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.0.210.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002122; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.113.239.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002123; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.116.72.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002124; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.128.147.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002125; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.178.242.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100002126; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.30.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002127; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.150.245.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002128; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.33.195.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002129; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"a.stro.lo.gy.t.em.r@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002130; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aatreefelling.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002131; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abcd.bg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002132; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abissnet.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002133; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aboveandbelow.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002134; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absoftechworld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002135; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abyssos.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002136; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"academyshademani.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002137; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acbick.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002138; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"accesslinksgroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002139; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acellr.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002140; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acteon.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002141; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"addahealingmusic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002142; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002143; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.memengers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002144; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.erapor.smk-alasror.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002145; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.grandoceanvilla.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002146; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admission.kmctartskuttippuram.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002147; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adventureexplorer.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002148; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aeropilates.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002149; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afnan-amc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002150; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afrimedspecialist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002151; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agemn.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002152; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciadigitalwdys.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002153; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenda.gmelloinformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002154; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agentt.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002155; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agile8studio.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002156; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aiecons.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002157; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aiqtest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002158; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajpharmaholding.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002159; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"akdvidyalaya.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002160; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"al-wahd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002161; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alasdemariposas.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002162; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alberts.diamondrelationscrm.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100002163; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alemelektronik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002164; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alena1971.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002165; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alexdubai.com.aldiabsteel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002166; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alka.institute"; content:"Host"; http_header; classtype:trojan-activity; sid:100002167; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"allforcreative.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002168; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alltheway.travel"; content:"Host"; http_header; classtype:trojan-activity; sid:100002169; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alpaylar.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002170; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alumni.hildred.ibbott@46.249.33.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002171; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"am-concepts.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100002172; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarresdeamorymaestroshechiceros.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002173; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarteargentina.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002174; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amos524.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002175; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ams.alvinasschools.org.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100002176; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anadelgbt.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002177; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anantam.net.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002178; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreelapeyre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002179; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andremaraisbeleggings.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002180; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002181; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002182; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreshconcejal.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002183; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelsdetour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002184; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anurontv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002185; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anysbergbiltong.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002186; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apartamentoscitta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002187; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api-ms.cobainaja.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002188; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002189; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apoolcondo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002190; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.adsensearticle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002191; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.explicitsurveys.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002192; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.prerana.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002193; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apps.saintsoporte.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002194; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aps-scribe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002195; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aps-sv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002196; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"artedibujoyarquitectura.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002197; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"arwenyapi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002198; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ask-regard.call-save.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002199; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atfile.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002200; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"athenacapsg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002201; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atlasconcreteworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002202; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"attach.66rpg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002203; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atteuqpotentialunlimited.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002204; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"augustair.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002205; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aulist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002206; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"australianpga.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002207; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"automaticrefreshments.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002208; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"avadhanagames.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002209; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aventuramotorhome.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002210; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"awumad01.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100002211; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"awuqze02.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100002212; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayahuascasp.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002213; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayamallah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002214; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azmeasurement.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002215; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azraktours.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002216; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"b.r.uce.lee.b.es.t@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002217; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"b2b.toptanakaryakit.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002218; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"backgrounds.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002219; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"badeggdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002220; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bakamla.go.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002221; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"balealgodon.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002222; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangkok-orchids.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002223; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangladeshunbound.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002224; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bary.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002225; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bash.givemexyz.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002226; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002227; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bavhome.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002228; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bbia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002229; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcmt.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002230; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcrg.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002231; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bdnextrend.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002232; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beanx88.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002233; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bearcatpumps.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002234; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beautincollagen.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100002235; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beautymomentsgt.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002236; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bekape.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002237; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beor360.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002238; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bespokeweddings.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100002239; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestcarenepal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002240; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betone.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002241; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beveragesmiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002242; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bhavaniengineering.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002243; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bigmikesupplies.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002244; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilbosaquet.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002245; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilhen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002246; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing.rahitechnosoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002247; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"binoy.stalphonsamissionva.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002248; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"biometrico.gpotecnosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002249; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bioskey.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002250; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birdi.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002251; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birminghamlink.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002252; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bizztradingbot.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002253; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bl4n3.zadns.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002254; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.callensaxen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002255; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.difusodesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002256; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.oyinblogs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002257; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.takbelit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002258; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bmlifestyle.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002259; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"boatpecas.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002260; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bodenstein.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002261; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bodylanguage.santulan.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002262; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"booksearch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002263; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bophelocare.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002264; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bounces.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002265; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"boutiqueofferte.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002266; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bpo.correct.go.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100002267; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bradleyinstitute.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002268; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brandtrust.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002269; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"braunfinancial.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002270; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brendanquine.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002271; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brideofmessiah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002272; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightaffiliatesales.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002273; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightmega.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002274; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightstarshop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002275; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"browardinsurancemiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002276; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bt2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002277; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"btdapi.robotake.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002278; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buigiaphat.com.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002279; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bullseyemedia.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002280; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"busandvanrentalmalaysia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002281; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buscascolegios.diit.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002282; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"business.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002283; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"business2.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002284; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c.ompact.i.o.np.d.yu@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002285; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c.oooooooooo.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002286; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c0140529.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002287; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"caballo.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002288; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cacaoprojects.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002289; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"calgaryautorepairservice.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002290; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"callbury.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002291; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"camminachetipassa.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100002292; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"canadianwork.cc"; content:"Host"; http_header; classtype:trojan-activity; sid:100002293; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capitalgroup-kw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002294; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capoeiraventrelivre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002295; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cashyinvestment.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002296; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"casiomaneflirt.cf"; content:"Host"; http_header; classtype:trojan-activity; sid:100002297; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"catchpoolshetlands.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002298; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cazyacustomfurniture.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002299; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cbn.hypervoizd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002300; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ccauthority.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002301; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cdaonline.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002302; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cec.asso.ac-amiens.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002303; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cellas.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002304; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cendekiabinaaksara.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002305; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cfs5.tistory.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002306; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch.rmu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100002307; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"changematterscounselling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002308; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chardhamdodham.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002309; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chezalice.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002310; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"childselect.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002311; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002312; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002313; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cible-energy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002314; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cifeer.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002315; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citiconstructioncorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002316; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citihits.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002317; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citssolutions.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002318; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cityglobalgospel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002319; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"civi.istmejia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002320; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cleanbydesignllc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002321; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cloud.fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002322; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cnc.tacobelllover.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002323; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"codsambal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002324; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colorpak.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002325; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"columbia.aula-web.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002326; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"community.reimclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002327; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"competancy.indigoconsult.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002328; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"conceptimagine.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002329; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"config.cqhbkjzx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002330; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"connectcapital.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002331; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"constructoralyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002332; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"consulateins.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002333; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"contributeindustry.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002334; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"copelandscapes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002335; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"corwin-tommie06f.ru.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002336; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"coulsongraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002337; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"count.mail.163.com.impactmedfoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002338; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"covid19.cyberschool.or.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002339; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"covid19vaccinations.hopto.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002340; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr-sq.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002341; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"craftech.nxtnet.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002342; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crearechile.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002343; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"creationskateboards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002344; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crecerco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002345; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crittersbythebay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002346; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crm.notariavieitoyvelamazan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002347; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crmfarko.manivelasst.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002348; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crmroche.manivelasst.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002349; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crscorretordeimoveis.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002350; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cse-engineer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002351; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"csnserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002352; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cubescargoexpress.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002353; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"curasoles.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002354; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"currantmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002355; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cwa.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002356; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyclomove.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002357; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cynkon.kairoscs.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002358; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"czsl.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002359; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d.powerofwish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002360; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d9.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002361; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"da.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002362; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"danaevara.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002363; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dartoonpictures.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002364; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.cdevelop.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002365; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.over-blog-kiwi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002366; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datapolish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002367; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dating.khokhas.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002368; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datsom.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002369; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davethompson.me.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002370; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davidmcguinness.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002371; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dayspringdaisies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002372; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dd.qiyuea.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002373; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"de.gsearch.com.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002374; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"decifrar.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002375; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"deigratia2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002376; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dekovizyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002377; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo-cliente.mindcreative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002378; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo.glassforcars.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002379; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo6.hiites.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002380; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dent-estet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002381; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dental.xiaoxiao.media"; content:"Host"; http_header; classtype:trojan-activity; sid:100002382; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dentalalliance.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100002383; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"desertlandtrd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002384; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"designerliving.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002385; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"despertaresi.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002386; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"destinymc.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002387; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"detorre.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002388; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.sebpo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002389; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.watch-store.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002390; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dezcom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002391; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfcf.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002392; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"diamantenegro.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002393; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dienmayminhhung.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002394; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"digilib.dianhusada.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002395; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"digisails.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002396; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"disinfection-cleaning.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002397; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"djking.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002398; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.1003b.56a.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002399; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002400; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.installcdn-aws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002401; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.packetstormsecurity.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002402; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.pandasecur.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002403; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.rina-roleplay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002404; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dnn.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002405; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dns.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002406; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dockerupdate.anondns.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002407; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"docman.orientalservices.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002408; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dodsonimaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002409; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"doitunlimited.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002410; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dokan.blueberrytec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002411; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom.daf.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002412; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"doncedyhall.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002413; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donghobinhminh.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002414; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dongphuctop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002415; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosman.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002416; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dovberger.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002417; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.pcclear.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002418; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.udashi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002419; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.webbora.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002420; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down1.arpun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002421; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.caihong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002422; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.doumaibiji.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002423; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.exrnybuf.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002424; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.kaobeitu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002425; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.pdf00.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002426; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.rising.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002427; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.skycn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002428; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.zjsyawqj.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002429; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dragonsknot.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002430; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drbaby.com.sa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002431; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dream.pics"; content:"Host"; http_header; classtype:trojan-activity; sid:100002432; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drgroup.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002433; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drools-moved.46999.n3.nabble.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002434; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drsha.innovativesolutions.mobi"; content:"Host"; http_header; classtype:trojan-activity; sid:100002435; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsenterprize.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002436; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsspainting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002437; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"du-wizards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002438; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duque.guantanameratravel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002439; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dutapp.wisolve.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002440; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duvalcharter.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002441; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dw2.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002442; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dx.qqyewu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002443; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dzinestudio87.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002444; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-commerce.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002445; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002446; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eandgdesign.com.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100002447; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebruyatkin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002448; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"edu.saicraftsman.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002449; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"efficientegroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002450; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"elbauldenora.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002451; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"emaids.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002452; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"emaz.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002453; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"en.baoend.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002454; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enc-tech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002455; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"endurotanzania.co.tz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002456; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ennovate.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002457; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"equimination.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100002458; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"erp.nanotechproautocare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002459; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"esaja09.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100002460; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"escola.probommar.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002461; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eservices.immigration.gov.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002462; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"esnconsultants.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002463; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"essentia.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002464; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eubanks7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002465; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"europeanzonexxi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002466; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exilum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002467; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exitoalfaomega.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002468; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"extrovertoffers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002469; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"f1sol.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002470; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"familydentist.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100002471; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"faveraprojects.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002472; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002473; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"felicienne.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002474; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"files.martellexpress.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100002475; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"files6.uludagbilisim.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002476; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"final.makkahkmcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002477; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fineartgallerym.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002478; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fisconline.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002479; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fisconline.casa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002480; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fix-america-now.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002481; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fkd.derpcity.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002482; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flexypay.dsquaregroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002483; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flintspin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002484; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flyingbuddhadesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002485; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fmjplastering.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002486; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"follower.instantcashback.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002487; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foothills.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002488; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"footweardirect.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002489; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"forum.mdb.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002490; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fotoobjetivo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002491; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foundationrepairhoustontx.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002492; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foxeps.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002493; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freecnetdownload.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002494; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freisites.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002495; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ftp.n3twork30cm.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100002496; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fullelectronica.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002497; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"funletters.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002498; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fusionfiresolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002499; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"futbolpr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002500; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"futuregraphics.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002501; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"g.pinmonkey.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002502; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gametwogame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002503; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garciadogshow.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002504; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002505; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow4.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002506; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gastoudergonny.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002507; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gbbulls.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002508; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gcpc.co.id.chronoscurtain.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002509; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"generaldeviales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002510; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfmodd1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002511; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfold1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002512; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghettohub.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002513; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghislain.dartois.pagesperso-orange.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002514; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giadungg7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002515; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giddos.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002516; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giteletropical.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002517; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"glowinmedia.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002518; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmtransformationacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002519; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmvadmission.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002520; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnimelf.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002521; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnscrew.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002522; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gold.investforex.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002523; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcake.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002524; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002525; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002526; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"golden-memories-funerals.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002527; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldenasiacapital.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002528; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldmen.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002529; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gpotecnosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002530; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gracejukes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002531; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupoinmare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002532; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gruposelt.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002533; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gs.monerorx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002534; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"guide-to-cell-phones.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002535; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gulfac-house.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002536; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gvpcdpgc.edu.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002537; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"h.epelcdn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002538; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"habbotips.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002539; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hagebakken.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100002540; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hamptonpartyoffive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002541; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hashmati.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002542; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hassanproduct.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002543; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hchfug.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002544; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hd11315.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002545; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hdkamera2003.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002546; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hds.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002547; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hellogorgeous.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002548; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"help.hizuko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002549; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"helpdeskserver.epelcdn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002550; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"herchinfitout.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002551; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hhaward.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002552; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandroadcoc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002553; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandslasvegas.atakdev.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002554; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hindi.factsriver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002555; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hiptool.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002556; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitpe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002557; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitstation.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002558; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hmpmall.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002559; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoagietesting10.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002560; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoayeuthuong-my.sharepoint.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002561; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"homefindersolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002562; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hometownchick.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002563; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hookedupboatclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002564; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostingparacolombia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002565; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostzaa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002566; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hr2019.vrcom7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002567; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hseda.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002568; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"htownbars.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002569; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hubtech.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002570; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"huellacero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002571; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hunchomusichub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002572; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hunggiang.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002573; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"husamiyahschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002574; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"i.n.t.e.rloca.l.qs.j.y@jfas.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100002575; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iabmixx2020.rayadigital.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100002576; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iam313.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002577; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"icon.shatangmu.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002578; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idea-secure-login.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002579; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idilsoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002580; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idj.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100002581; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idvindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002582; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ieclb.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002583; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ikexpert.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002584; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ilrafrica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002585; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"images.jermiau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002586; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"imbueautoworx.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002587; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"in-tune2016.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002588; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incrediblepixels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002589; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incredicole.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002590; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"indrasbikaner.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002591; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infair.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002592; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infovator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002593; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"initialnetworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002594; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inodesthetotaldesigners.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002595; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inrajahmundry.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002596; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"instantindialoan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002597; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intersel-idf.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002598; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intuitiveideas.com.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100002599; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inversiones.arrayanfinanciero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002600; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"invest.xpcorporative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002601; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ipmes.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100002602; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iremart.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002603; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iris101.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002604; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isaac.mikhailmotoringschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002605; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iscamenabe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002606; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isiphephelocon.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002607; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ismf.com.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100002608; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iso-dubai.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002609; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"israrulhaq.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100002610; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isrorg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002611; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isso.ps"; content:"Host"; http_header; classtype:trojan-activity; sid:100002612; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"it123.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002613; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"italiandirezione.casa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002614; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itc-demo.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002615; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itsrlytry.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002616; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jaishomo.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002617; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamiekaylive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002618; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamshed.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002619; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jansen-heesch.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002620; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jathra.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002621; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jay.diamondrelationscrm.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100002622; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jebs.net.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002623; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jeffdahlke.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002624; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jfas.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100002625; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jhayesconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002626; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jiaoyuzixun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002627; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jing-da.com.tw"; content:"Host"; http_header; classtype:trojan-activity; sid:100002628; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jmtc.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002629; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jnanbharati.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002630; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jobs.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002631; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"joelbonissilver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002632; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"join.cl8movement.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002633; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"josegene.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002634; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jpwoodfordco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002635; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jumpmanualjacobhiller.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002636; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jupiter.toxsl.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002637; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"justinscott.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002638; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kadigital.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002639; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalawatihomes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002640; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalogirosfinance.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002641; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kaptaanchapal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002642; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"karer.by"; content:"Host"; http_header; classtype:trojan-activity; sid:100002643; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"katanvetov.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100002644; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"katelynn9506a.ru.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002645; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kensingtondriving.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002646; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ketofitnessexpert.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002647; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kevinjewelry.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002648; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"keywatch.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002649; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kingssa.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002650; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kjcpromo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002651; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kleinendeli.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002652; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"korrectconceptservices.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002653; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"krisbadminton.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002654; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ktb.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002655; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kubatoglubaklava.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002656; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kumaralok.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002657; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kwanfromhongkong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002658; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kz.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002659; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"l.oc.atevur.c@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002660; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lacasadelosalebrijes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002661; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lameguard.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002662; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laodongnhat.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002663; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laravel.pointersoftwares.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002664; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lasermobilesounds.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002665; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lauratomismith.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002666; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lautarosanmiguel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002667; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lawforall.edu.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002668; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lawschoolideas.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002669; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lceventos.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002670; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ld.mediaget.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002671; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ldgcorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002672; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"learning.real-academy.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002673; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leasiacherise.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002674; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leczkregoslup.acelero.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002675; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"legend.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100002676; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leluibuffet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002677; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lestesteux.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100002678; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.arihantmbainstitute.ac.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002679; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.uib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002680; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lidoraggiodisole.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100002681; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lifebeam.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002682; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lindnerelektroanlagen.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002683; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"linkintec.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002684; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"liquidaz.casa"; content:"Host"; http_header; classtype:trojan-activity; sid:100002685; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"livetrack.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002686; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsindian.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002687; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lm.stagingarea.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002688; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmaancha.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100002689; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002690; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.login2.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002691; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"location-voitures.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100002692; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.trezor.com.stockfootagesindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002693; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"logotypfabriken.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100002694; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotix.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002695; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotusanddragonfly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002696; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.definerisco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002697; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.difusodesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002698; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ltc.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002699; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luckybrownie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002700; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luminouspneuma.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002701; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luxomodels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002702; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m-technics.kz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002703; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.estudiomoros.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002704; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"madicon.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002705; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"magianegramagiablancayamarres.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002706; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.bs-eiendomme.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002707; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.golimoapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002708; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.jeffsono.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002709; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maksi.feb.unib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002710; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malaya.tv"; content:"Host"; http_header; classtype:trojan-activity; sid:100002711; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malwarecoding.github.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100002712; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managemysalon.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002713; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manantialesdelnorte.uy"; content:"Host"; http_header; classtype:trojan-activity; sid:100002714; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manhtien.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002715; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marcapinyo.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002716; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mario-sunjic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002717; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariobrown.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002718; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariotessarollo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002719; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketinfosales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002720; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketing.enexusgroup.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002721; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marksidfgs.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002722; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"masjidhabeebiyarazviya.mysunni.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002723; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mastersofclientretention.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002724; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"materialescantu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002725; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"matruchhaya.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002726; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxtox.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002727; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbgrm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002728; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbjtimes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002729; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbsolutions.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100002730; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mdasa.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002731; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medevlb.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002732; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"media-server.skyinternet.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002733; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medianews.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100002734; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mediawaysnews.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002735; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medistaffconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002736; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meeweb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002737; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"megagynreformas.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002738; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"megamart.afnan-amc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002739; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mehainteriors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002740; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"merkathink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002741; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mertlog.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002742; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"metalin-cr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002743; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mettaanand.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002744; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meuoculosnanet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002745; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mfevr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002746; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002747; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002748; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"micalle.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002749; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michaelphilip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002750; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michimal2.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002751; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microblading.mirliandias.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002752; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microcomm-group.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002753; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mikhailmotoringschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002754; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mills-skyla30ec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002755; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mingguanwms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002756; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"minuevavida.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002757; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mirror.mypage.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002758; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mis.nbcc.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100002759; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"misterson.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002760; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mkontakt.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100002761; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mktf.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002762; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmdx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002763; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmogollon.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002764; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mncarteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002765; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modelhouseturkey.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002766; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modernmanna.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002767; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"monetization.business"; content:"Host"; http_header; classtype:trojan-activity; sid:100002768; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moninediy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002769; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moreirawag.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002770; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"motorcomunicacion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002771; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moumitas.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002772; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"msacontabil.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002773; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mumgee.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002774; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"muzimbiti.xigubo.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002775; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mvb.kz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002776; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mxpiqw.am.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002777; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mydatebook.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002778; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymlql.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002779; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myritz.vettickal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002780; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysalons.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002781; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myscape.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002782; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysura.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100002783; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"naeemacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002784; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"namnyak.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002785; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nap.mgsservers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002786; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"navayurveda.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002787; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nec-i.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002788; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nelitrianggraeni.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002789; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nerve.untergrund.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002790; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nettube.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002791; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"networkwheels.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002792; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newfuture.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002793; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newinfinitysynergy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002794; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newtreedesign.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002795; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newvisionopticallab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002796; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newxing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002797; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nextdigitalday.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002798; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ngdaycare.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002799; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nguyenkekhuyen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002800; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nhorangtreem.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002801; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nicolas.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002802; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nidhi.iexist.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002803; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nikanpolimer.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100002804; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilehouse.co.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100002805; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilinkeji.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002806; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nimboohomes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002807; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"njtiledesigncenter.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002808; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nobius.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002809; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocalnoodle.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002810; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nomadicbees.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002811; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"northnodegroup.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002812; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"notamuzikaletleri.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002813; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ns1.the-widyantos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002814; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsb.org.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002815; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nurmarkaz.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002816; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nxtnet.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100002817; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyasabigbullets.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002818; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyeh2o.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002819; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"obseques-conseils.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002820; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oecteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002821; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohe.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100002822; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohsewgorgeous.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002823; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oleholeh.memangbeda.website"; content:"Host"; http_header; classtype:trojan-activity; sid:100002824; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002825; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaromatic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002826; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omega.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100002827; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oms.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002828; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omscoc.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002829; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedigitalcard.granvizionnecorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002830; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedrive.listifyapp.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100002831; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"online.creedglobal.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002832; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"open.warehousesaas.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002833; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opolis.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100002834; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"optimus.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002835; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"order.bizpeed.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002836; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orientgatewayltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002837; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orion445.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002838; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orlina.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100002839; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oserve.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002840; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ot.weenets.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002841; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ozemag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002842; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p1.lingpao8.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002843; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p3.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002844; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p6.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002845; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pablobrothel.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002846; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacificgroup.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100002847; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacwebdesigns.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002848; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pagos.krayem.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100002849; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"palochusvet.szm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002850; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"panslimiterd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002851; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parallel.rockvideos.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100002852; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parejasfelices.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002853; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parkhussion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002854; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pastorpaulocosta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002855; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.51lg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002856; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002857; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch3.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002858; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paths.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002859; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patriotsupremehemp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002860; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paulmercier.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002861; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payerrealty.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002862; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payments.atifsiddiqui.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100002863; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pcsoori.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002864; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pd.oceaniarp.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002865; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pemdodo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002866; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perfumeriamontes.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100002867; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"periodiche.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002868; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpus.onlineman7-jombang.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002869; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpustekim.untirta.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002870; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pestoclean.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002871; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"petercollie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002872; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ph4s.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002873; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phasdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002874; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phenhuong.sanpham.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100002875; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phittc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002876; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"photo360.kubooking.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002877; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pink99.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002878; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"plasfan.ind.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002879; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"playground2.grupoaliadasca.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002880; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pmglance.startwriteup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002881; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pokojewewladyslawowie.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002882; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pole.com.vc"; content:"Host"; http_header; classtype:trojan-activity; sid:100002883; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pool.phxdir.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002884; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pooltablemoversdenver.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002885; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"posmicrosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002886; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"poulman.panagiotopoulos-tours.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002887; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ppdb.smk-ciptaskill.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002888; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestasicash.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002889; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestigehomeautomation.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002890; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"preview2.behalen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002891; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prishaartcreations.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002892; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"production.sparshims.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002893; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"programaoperadoronline.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002894; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"project.exquitec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002895; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promotoradescomplica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002896; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promoversdubai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002897; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002898; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002899; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosoc.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002900; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosyarmakassar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002901; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"provence.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002902; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prox.realunix.cc"; content:"Host"; http_header; classtype:trojan-activity; sid:100002903; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pujashoppe.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002904; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punchdialogues.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002905; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punjabdevelopersassociation.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002906; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pvcprinting.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002907; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qadir.tickfa.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100002908; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qatarglobalconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002909; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qmsled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002910; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qu.o.t.ev.v.n.r@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002911; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"quartier-midi.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100002912; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"querocar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002913; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rachmat-assuhaimi.my.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100002914; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"radioafifense.deploys.live"; content:"Host"; http_header; classtype:trojan-activity; sid:100002915; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rainbowisp.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100002916; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rajeshtailang.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002917; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakeshkhatri.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002918; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"raodigitalmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002919; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"raquelhelena.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002920; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rarlabarchiver.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100002921; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rasadbar.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100002922; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rashika.ascarvalho.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002923; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ratemyfenancialadvisor.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002924; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ravenproductionsltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002925; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ravo.net.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100002926; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rc.ixiaoyang.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002927; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rcmesilva.charbelsales.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002928; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reacredit.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100002929; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"readwrite26.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002930; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"readymmade.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002931; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"recyclethesurplus.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002932; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redbats.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002933; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redboxmultimedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002934; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redchillicrackers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002935; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reifenquick.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002936; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"renehavis.com.ua"; content:"Host"; http_header; classtype:trojan-activity; sid:100002937; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"repatriacioncolombia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002938; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"res.uf1.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002939; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reseller.digimitra.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002940; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reseller.itechbrasil.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002941; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"resuco.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002942; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rezkabum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002943; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rhema.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100002944; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richmondminerals.co.zm"; content:"Host"; http_header; classtype:trojan-activity; sid:100002945; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinaefoundation.org.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002946; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinkaisystem-ht.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002947; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"riverfox.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002948; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkcable.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100002949; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkverify.securestudies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002950; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertmcardle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002951; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertsinclair.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002952; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"romanianpoints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002953; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ronnietucker.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100002954; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roomsvc.servegate.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100002955; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roshnijewellery.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002956; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rotronics.com.ph"; content:"Host"; http_header; classtype:trojan-activity; sid:100002957; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rsgym.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002958; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubazar.pro"; content:"Host"; http_header; classtype:trojan-activity; sid:100002959; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubycityvietnam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002960; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruisgood.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100002961; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruwadalkuwait.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002962; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.51shijuan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002963; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.hu.d.es.h.d.u.e54.78.16247@46.249.33.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002964; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.thechinesemuslim.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002965; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sacredscentsonline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002966; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sadmahfuneralservices.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002967; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safcol-colors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002968; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safehubsecurity.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100002969; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safety.nanotechproautocare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002970; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sahathaikasetpan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002971; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sainzim.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002972; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"saisoftwareinc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002973; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"salecorner.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002974; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"salonsaifa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002975; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"samriddhijyotish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002976; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sandovalgraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002977; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"santyago.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100002978; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sasystemsuk.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002979; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scarfaceindustries.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002980; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scglobal.co.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100002981; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schalke04rss.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100002982; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scheff.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002983; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schoolbustracker.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002984; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sculetus.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002985; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-doc-reader.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002986; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.activedirect.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002987; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"segalsmetals.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100002988; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sellmyphonela.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002989; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"selltechtoday.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002990; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"senbiaojita.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002991; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sentierodelviandante.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100002992; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serendibsourcing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002993; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sericaasia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002994; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002995; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002996; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviciovirtual.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100002997; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sexologistpakistan.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100002998; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgb.ac.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100002999; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgessy.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003000; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shaheentbfoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003001; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shahikhana.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003002; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shahu66.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003003; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shalombaptistchapel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003004; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharkrigs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003005; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharpelevators.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003006; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shembefoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003007; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shidditourism.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003008; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shivakunwar.com.np"; content:"Host"; http_header; classtype:trojan-activity; sid:100003009; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shoblasaathitrust.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003010; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shomalhouse.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003011; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shooka-co.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003012; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shop.goldspot.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100003013; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shopsofe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003014; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sibernetix.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003015; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sige.brisainformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003016; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"signatureads.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003017; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siili.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003018; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simoneporzi.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100003019; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simorsint.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003020; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simplithy.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003021; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindicato1ucm.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003022; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindpol.tiejuris.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003023; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sipahielektrik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003024; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sistelligent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003025; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyflyfares.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003026; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyscan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003027; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"slot0.gamoruz.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003028; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarthouseforum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003029; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartzedu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003030; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smokesolutionindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003031; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smritiphotography.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003032; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobariko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003033; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobethuacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003034; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.110route.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003035; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.officelabo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003036; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sohs.conceptechs.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003037; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"solar.amazingtribe.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003038; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somcorbera.cat"; content:"Host"; http_header; classtype:trojan-activity; sid:100003039; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somir.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003040; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soralapps.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003041; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sota-france.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003042; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"space.proactint.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003043; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spaceframe.mobi.space-frame.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003044; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"special-key.cf"; content:"Host"; http_header; classtype:trojan-activity; sid:100003045; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spent.com.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003046; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spetsesyachtcharter.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003047; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spititourism.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003048; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spittinfire.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003049; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"src1.minibai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003050; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sreenivasapaintingworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003051; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sriglobalit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003052; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"srilankamovies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003053; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"srvmanos.no-ip.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003054; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ss.monita.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003055; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"st.devcodin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003056; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"staging.apparelpunch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003057; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"starcountry.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003058; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"static.3001.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003059; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stdynbnbnewagedevixz.dns.army"; content:"Host"; http_header; classtype:trojan-activity; sid:100003060; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stdynmxwllminoragest.dns.army"; content:"Host"; http_header; classtype:trojan-activity; sid:100003061; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stdyunitedkesokokgst.dns.army"; content:"Host"; http_header; classtype:trojan-activity; sid:100003062; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stdyworkfinetraingst.dns.army"; content:"Host"; http_header; classtype:trojan-activity; sid:100003063; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stdyzgchgcloudgostxs.dns.army"; content:"Host"; http_header; classtype:trojan-activity; sid:100003064; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stiau.iuc.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100003065; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sticker.jewsjuice.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003066; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stiepancasetia.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003067; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stlukesohag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003068; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"store.ericalgarin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003069; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stott-thompson.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003070; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stratexec.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003071; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"streetdemo.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003072; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"suboldesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003073; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sumerians.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003074; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunaryem.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003075; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunbrero.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003076; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunmarkholidays.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003077; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-4-free.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003078; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support.clz.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003079; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supportit.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100003080; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sw.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003081; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweaty.dk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003082; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweet-diet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003083; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swiftlogisticseg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003084; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swwbia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003085; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"syracusecoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003086; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sytraders.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003087; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.honker.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003088; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tadoo.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003089; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tafsantoursandtravels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003090; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tajushariya.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003091; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tallyinvoicecustomization.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003092; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taltus.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003093; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tapalkoedacoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003094; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tarravalleyfoods.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003095; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taurus.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003096; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tc.snpsresidential.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003097; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tcy.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003098; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tdsp.yngw518.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003099; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"techgms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003100; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teduae.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003101; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teleargentina.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003102; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"telescopelms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003103; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"temptmag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003104; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tencoconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003105; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teneth.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003106; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tentandoserfitness.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003107; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tessrobins.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003108; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.adventser.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003109; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.letraele.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100003110; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.lubrico.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003111; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.protocsconnectes.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003112; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003113; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.wanepghana.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003114; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.asistencia247.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003115; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.milenial.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003116; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100003117; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.basis-web.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003118; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.marrenconstruction.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100003119; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.clickitsolutionsmw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003120; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.thinkingcorp.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003121; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testnew.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003122; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teteaffiche.stephanebillon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003123; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tewoerd.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003124; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"textile.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003125; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tharringtonsponsorship.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003126; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecleaningladiespdx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003127; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecreativecafe.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003128; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thedesertship.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003129; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefamouscurrybazaar.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003130; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefuturelife.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003131; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thehighlightinterior.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003132; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thekassia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003133; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"themansionkasauli.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003134; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theprofinn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003135; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thesummitpc.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003136; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theurbantutors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003137; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thosewebbs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003138; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thriveink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003139; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tianangdep.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003140; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickfoods.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003141; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tidymasters.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003142; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"timegonebuy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003143; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tksb.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003144; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tlcc.com.gt"; content:"Host"; http_header; classtype:trojan-activity; sid:100003145; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"todoapp.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003146; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonydong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003147; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonyzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003148; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tooba.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100003149; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tools.reimclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003150; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topcell9.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003151; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toplevel.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003152; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topmask.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003153; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"torresquinterocorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003154; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toyotacollege.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003155; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpke.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003156; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"translaterjemah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003157; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"travelwithmanta.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003158; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trendyshoes.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003159; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trezors.io.mahlongwa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003160; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trimestre.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003161; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"troki.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003162; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tropics.codeleek.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003163; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trudelfavreau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003164; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsd.jxwan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003165; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tulli.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003166; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tupperware.michaelroberge.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003167; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"turanggaresources.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003168; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uat.indianfilmzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003169; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ublretailerdemo.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003170; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uc-56.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003171; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uisusa.uisusa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003172; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ultimate-24.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003173; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"umwelt-kirchhof.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003174; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unicorpbrunei.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003175; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uniengrisb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003176; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"union.jctrip.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003177; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unyazitelecom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003178; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"up.llw0.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003179; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"upcbpta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003180; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"useformoney.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003181; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uss.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003182; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uzzepay.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003183; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vanzare.cabanabrazi2.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003184; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vbcargo.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003185; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vcah.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003186; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vectarts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003187; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vegadelcasero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003188; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vendas.lidiacarmeli.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003189; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"veterinariadrpopui.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003190; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vfocus.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003191; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vienen.gblix.srv.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003192; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vilaart.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100003193; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villamarand.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003194; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villatera.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003195; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"violinstop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003196; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"virtuleverage.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003197; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visions.alnisamart.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003198; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visualhome.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003199; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vivationdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003200; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"viveirodoiscorregos.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003201; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vksales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003202; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vocalterra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003203; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vologroup.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003204; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"voteyouramerica.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003205; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vpts.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003206; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vstsample.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003207; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vtube.fadlymotivator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003208; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vvsskmodinationalschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003209; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003210; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepliberia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003211; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepniger.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003212; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weareactum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003213; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.eng.ubu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003214; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geomegasoft.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003215; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.newinnovationtechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003216; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.smarts-works.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003217; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003218; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webgis.perumdasolo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003219; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webpresario.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003220; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weinsteincounseling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003221; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wfinance.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003222; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whcms.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003223; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteglovetailgate.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003224; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteresponse.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003225; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wi522012.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003226; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wikalen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003227; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildnights.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003228; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildtrust.mediadevstaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003229; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"willow-nettica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003230; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wimbamusica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003231; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"windcomtechnologies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003232; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wishesconcierge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003233; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woezon.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100003234; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wolfgang-brodte.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003235; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woodsytech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003236; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wordpress.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003237; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wozata.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003238; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wp.readhere.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003239; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wpdemo.101clients.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003240; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"writtendeer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003241; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ws5588.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003242; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wyklej.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003243; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"x2vn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003244; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xia.beihaixue.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003245; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xixaoclothing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003246; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xk.996is.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003247; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--polimerbizmimarlk-rvc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003248; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ybom.urbanolab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003249; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yeichner.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003250; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yeq.i.u.j.ia.n.3@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003251; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ylfpremium.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003252; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yoast.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003253; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yp.hnggzyjy.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003254; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yummyyogaudaipur.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003255; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yzkzixun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003256; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ziyker4gaming@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003257; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zmedcoach.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003258; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003259; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zz.690tx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003260; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100003261; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/86.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100003262; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100003263; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; http_uri; nocase; content:"amumufree.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003264; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/files/proxyi.exe"; http_uri; nocase; content:"analogx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003265; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003266; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/clubhousedev/clubhouse/downloads/clubhousepc.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003267; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dvdfv/anjj/downloads/jami.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003268; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/heyhoeee/heyhoename1/downloads/1234.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003269; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/4.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003270; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/6.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003271; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/labesoftware/update/downloads/boost-fps.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003272; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/labesoftware/update/downloads/install_plugin_x64_x86.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003273; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/labesoftware/update/downloads/vpn_free.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003274; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/clr.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003275; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/dianthus.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003276; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/n.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003277; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/newred.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003278; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/omar.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003279; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/serv.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003280; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/test.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003281; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updachrome.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003282; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatedata.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003283; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatev.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003284; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/work.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003285; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/component.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003286; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003287; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/regsvc.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003288; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/skygaming/updates/downloads/update.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003289; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/001.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003290; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1488.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003291; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1_cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003292; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003293; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1fc2d.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003294; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/26a5.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003295; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003296; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/abjects.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003297; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/attached.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003298; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/b7f2c.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003299; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/battletext.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003300; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003301; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003302; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003303; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_makros.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003304; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_silent.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003305; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_sup.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003306; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003307; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003308; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003309; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildss.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003310; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientnik.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003311; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientrevers.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003312; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dcrat.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003313; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003314; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003315; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hans.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003316; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hulu.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003317; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfive.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003318; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfour.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003319; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelone.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003320; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelthree.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003321; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/inteltwo.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003322; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003323; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/kleiman.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003324; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003325; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/notepadplus.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003326; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003327; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003328; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003329; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003330; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/putty.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003331; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/rockethcd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003332; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/scvhost900.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003333; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/sessionwin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003334; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/siliculose.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003335; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/statemobi.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003336; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003337; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003338; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stgedo.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003339; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/svcperf.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003340; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003341; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurjok.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003342; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurusbabac.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003343; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/telekiller.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003344; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateanddr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003345; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateandr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003346; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/vhajeja.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003347; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/word.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003348; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/www.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003349; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/xlsd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003350; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003351; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003352; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hmatrix/data/hack1226.exe"; http_uri; nocase; content:"cd.textfiles.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003353; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003354; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/775238059083038744/829993648186851338/pslmlyfnpzgsgitrwwvalcfunumfmac"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003355; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/816070119281131570/816070273254162442/all.txt"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003356; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/826848185246023750/loaddd.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003357; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/826848348342059008/zeppelin.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003358; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/826848405258633277/build.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003359; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/825372018244583454/830455061724528690/v1.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003360; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/826198252025675816/826537386485612574/china.png"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003361; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003362; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003363; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/razor/rzr-winner_intro.zip"; http_uri; nocase; content:"chiptune.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003364; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003365; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003366; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/meteoradminz/hidden-tear/zip/master"; http_uri; nocase; content:"codeload.github.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003367; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; http_uri; nocase; content:"colfincas.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003368; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ktcghnmcwws43wzscphukbfnwtuaxidx&revid=0b8z0b7_i5sirk2xrtehmstg0vxvit3b4n3lmbdrdrjrodndrpq"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003369; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1qze6qzzh1uf7iaj4rqixttznx6u1--gc&revid=0b45wwmcofx7fuvnmdhpkt1d0k3rhzldyoffnuc83auzkslvrpq"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003370; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; http_uri; nocase; content:"drive.google.com.it-barcelona.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003371; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003372; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=11idvvx22jx_1lw-hxnpmlwuvjgdyp63g"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003373; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=12khl-unz2np4q54b2jgpwlsh6cuz0pss"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003374; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003375; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003376; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=16yyvhney9_-nygeipjqgnlcmwfoyiaxo"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003377; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=17pl-4i0otjbyxwrtrdagxxebirdh2wl8"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003378; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003379; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003380; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1br5iufkkmmfeipqo3ecviqykbcdgcnio"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003381; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1bwtwpqmeqdvctbcqcc2gil5xzjf28c0z"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003382; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003383; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003384; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1d0ij6qkgrf6irywv6ftk1m7p5l3weh3a"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003385; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1dzx_cflers_zntlrip3fhbxb5who03u0"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003386; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1gprlk2mcrl6law-zk5r0pjogaqrxwepd"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003387; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003388; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003389; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1jdqcxydqvz3bjodp66ieiocbjcz8foi6"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003390; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1l5urks5wzib2zcb16bfsk76bjrdsejms"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003391; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ldxaekbcbzb-zfdix-ucj4rilobnbswx"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003392; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ljz-kmuibyiehba6blw37guu_yr799y0"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003393; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1lsv4sko083sywwjndgqnsh_6sgqodqtu"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003394; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003395; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003396; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003397; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1oek6vmzbv15nyho_uqcbk4_vaq1ezowv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003398; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ph-lri07dohowhmuczrrvjwrtsvmnu9s"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003399; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003400; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1r1flwyfwtyziyr47y5sk3q821r6_tgsl"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003401; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1r9f9irwhutxozsbp2h9erd_a7fa2pwko"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003402; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1s221a6wpx6i7nfrztnhh9priojtybuxq"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003403; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1sutnyikgc4qw-tbvnnvzm8uz9thch0vz"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003404; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003405; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1taubixyqiqdgfbhmc2rv_aitvkbqhzwz"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003406; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1tpd_qbnl_mtmhfsv4a-qtfsnuiimyoy6"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003407; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003408; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vjq92eqivh01yxmal20whl2es3ld6nxb"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003409; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1voqnsh0cmxl5hty4zpc18pgnkud5rtvy"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003410; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vy1nx5zefluh5ewihr-6pcndlyex7xcm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003411; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1wpqa2nnnktbhzs4j0r-erosvgyaagi_a"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003412; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xbp7hvw2ybwjrftbvdkjvwzrfuk4ope9"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003413; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003414; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003415; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003416; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003417; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ywkgalidldb32pio6ywmbyvdk7oar3yy"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003418; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003419; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003420; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/1zilg/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003421; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/qcgfmfvh/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003422; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/emclick.zip"; http_uri; nocase; content:"e-mudhra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003423; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe"; http_uri; nocase; content:"evertkok.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003424; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe"; http_uri; nocase; content:"evertkok.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003425; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003426; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003427; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/x/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003428; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003429; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003430; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003431; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100003432; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; http_uri; nocase; content:"file.elecfans.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003433; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003434; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003435; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; http_uri; nocase; content:"gist.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003436; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; http_uri; nocase; content:"hqdecig.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003437; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/suy/"; http_uri; nocase; content:"hsecaravans.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003438; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/19/items/startup_20210219/startup.txt"; http_uri; nocase; content:"ia801802.us.archive.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003439; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/online-timer-kvhxz/ilxl/"; http_uri; nocase; content:"ie-best.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003440; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100003441; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100003442; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ebook/cs17.exe"; http_uri; nocase; content:"jcedu.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003443; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003444; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003445; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003446; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; http_uri; nocase; content:"karmakoincodes.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003447; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dg/etrac/nf4emwz/"; http_uri; nocase; content:"kotakwarna.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003448; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe"; http_uri; nocase; content:"ksh.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003449; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/down/affiliate/kuaizip_setup_10029.exe"; http_uri; nocase; content:"kuaizip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003450; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/linuxforensicscode.zip"; http_uri; nocase; content:"linuxforensicsbook.com.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003451; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dl8.exe"; http_uri; nocase; content:"lojavirtual.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100003452; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dl8v2.exe"; http_uri; nocase; content:"lojavirtual.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100003453; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/k/big5/1giof6/"; http_uri; nocase; content:"minpic.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100003454; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-contentbak/t9m/"; http_uri; nocase; content:"morrobaydrugandgift.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003455; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; http_uri; nocase; content:"my.cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003456; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/aacenc.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003457; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/doxillionsetup.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003458; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/4/1/6/6/4166984/keygen.exe"; http_uri; nocase; content:"newyarlfm.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003459; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; http_uri; nocase; content:"nhipcauytevietnhat.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003460; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; http_uri; nocase; content:"note.youdao.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003461; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; http_uri; nocase; content:"oldschoolvalue.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003462; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20cid=ba02d68febf523dc&resid=ba02d68febf523dc!1431&authkey=afbifi7o9ywbjpm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003463; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?%20cid=ba02d68febf523dc&resid=ba02d68febf523dc%211431&authkey=afbifi7o9ywbjpm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003464; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003465; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003466; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003467; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003468; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003469; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003470; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003471; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003472; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003473; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003474; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003475; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003476; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003477; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003478; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003479; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003480; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003481; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003482; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003483; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003484; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003485; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003486; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003487; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003488; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003489; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003490; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003491; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003492; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d!184&authkey=ackbiiarirejcam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003493; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d%21184&authkey=ackbiiarirejcam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003494; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003495; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003496; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003497; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003498; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0!1667&authkey=an8otd7jzc7xgho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003499; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0%211667&authkey=an8otd7jzc7xgho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003500; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003501; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003502; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003503; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003504; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003505; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003506; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003507; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003508; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=15d9646f4dbf9553&resid=15d9646f4dbf9553%21110&authkey=ag0eg1lha_lwgi0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003509; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003510; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003511; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003512; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003513; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003514; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003515; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003516; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003517; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003518; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003519; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003520; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003521; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003522; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003523; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003524; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003525; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003526; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba!112&authkey=afjxmbcllibdbvo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003527; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba!114&authkey=adecqvkvvvadznc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003528; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba%21112&authkey=afjxmbcllibdbvo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003529; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba%21114&authkey=adecqvkvvvadznc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003530; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=216ef243e34992b8&resid=216ef243e34992b8!330&authkey=apiugomnim7heom"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003531; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=216ef243e34992b8&resid=216ef243e34992b8%21330&authkey=apiugomnim7heom"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003532; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=23423a594eafc2de&resid=23423a594eafc2de%21130&authkey=aeh1dm0c-5hp44a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003533; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003534; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003535; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003536; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003537; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003538; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003539; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003540; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003541; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003542; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b!287&authkey=advpfy_0ry8upmi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003543; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b!288&authkey=aembucxemjjo3bk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003544; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b%21287&authkey=advpfy_0ry8upmi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003545; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b%21288&authkey=aembucxemjjo3bk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003546; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003547; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003548; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003549; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003550; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003551; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003552; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003553; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003554; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003555; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003556; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003557; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003558; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3004cdd743a543f5&resid=3004cdd743a543f5%21170&authkey=ao8vz-4rkwuiyn8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003559; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003560; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003561; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003562; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003563; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003564; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003565; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1!223&authkey=aajr842bzum0yg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003566; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003567; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003568; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003569; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003570; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003571; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003572; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003573; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003574; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003575; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003576; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003577; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003578; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003579; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003580; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003581; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003582; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003583; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003584; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3ee68228c34c236d&resid=3ee68228c34c236d%21129&authkey=apll6hu3-xetzxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003585; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003586; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003587; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003588; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003589; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003590; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003591; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003592; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003593; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003594; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003595; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21141&authkey=aazwaw2xjms24o0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003596; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21145&authkey=aaenjqj018fjmc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003597; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003598; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003599; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003600; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003601; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003602; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003603; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003604; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003605; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003606; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003607; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003608; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003609; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003610; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003611; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003612; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003613; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003614; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003615; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003616; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003617; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003618; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003619; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003620; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003621; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003622; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003623; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003624; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003625; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003626; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003627; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003628; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003629; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003630; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003631; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003632; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003633; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003634; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003635; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003636; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003637; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003638; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003639; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003640; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003641; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003642; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003643; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003644; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003645; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003646; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003647; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003648; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003649; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003650; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003651; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003652; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003653; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003654; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003655; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003656; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003657; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003658; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003659; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003660; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003661; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003662; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003663; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003664; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003665; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003666; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003667; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003668; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003669; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003670; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003671; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003672; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003673; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003674; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003675; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003676; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003677; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003678; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003679; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003680; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003681; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003682; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003683; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003684; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003685; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003686; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003687; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003688; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003689; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003690; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003691; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003692; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003693; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003694; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003695; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003696; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003697; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003698; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003699; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003700; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003701; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003702; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003703; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003704; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003705; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21198&authkey=akq4jrbjm6spd9m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003706; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003707; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003708; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003709; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003710; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003711; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003712; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003713; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003714; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003715; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003716; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003717; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003718; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003719; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003720; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003721; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003722; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003723; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003724; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003725; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003726; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003727; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003728; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003729; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003730; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003731; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003732; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003733; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003734; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003735; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003736; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003737; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003738; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003739; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003740; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003741; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003742; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003743; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003744; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003745; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003746; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003747; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003748; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003749; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003750; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003751; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003752; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003753; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003754; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003755; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003756; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003757; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003758; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003759; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003760; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003761; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=855b20b0e8399717&resid=855b20b0e8399717%21110&authkey=afhxx21ztsd7hbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003762; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003763; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003764; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003765; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003766; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003767; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003768; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003769; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003770; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003771; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003772; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003773; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003774; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003775; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003776; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003777; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!112&authkey=af43qpcgl0t2f5o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003778; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003779; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003780; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003781; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003782; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003783; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003784; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003785; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003786; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003787; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003788; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003789; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003790; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003791; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003792; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003793; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003794; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003795; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003796; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003797; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003798; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003799; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003800; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003801; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003802; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003803; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003804; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003805; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003806; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003807; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003808; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003809; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003810; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003811; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003812; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21256&authkey=aapnly5qifymcvw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003813; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003814; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003815; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003816; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003817; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003818; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003819; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003820; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003821; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003822; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818!129&authkey=aesewk3cf5vbrxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003823; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818%21129&authkey=aesewk3cf5vbrxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003824; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003825; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5!2423&authkey=aoiqjwenlzfiqe0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003826; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212417&authkey=aa2zjoxjz1c83ns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003827; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212418&authkey=akjeumqon_fyj9c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003828; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212423&authkey=aoiqjwenlzfiqe0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003829; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003830; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003831; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003832; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003833; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003834; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003835; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003836; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003837; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003838; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003839; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003840; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003841; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003842; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003843; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003844; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003845; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003846; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003847; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003848; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003849; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003850; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003851; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003852; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003853; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003854; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003855; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ba02d68febf523dc&resid=ba02d68febf523dc%211431&authkey=afbifi7o9ywbjpm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003856; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1047&authkey=aod6jbxyicq2v4g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003857; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211047&authkey=aod6jbxyicq2v4g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003858; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003859; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003860; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003861; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003862; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003863; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003864; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c29fdbf45b3d2671&resid=c29fdbf45b3d2671%21608&authkey=aafwhzmybg1czta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003865; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003866; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003867; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003868; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003869; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003870; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003871; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003872; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003873; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003874; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003875; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003876; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003877; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003878; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003879; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003880; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003881; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003882; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003883; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003884; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003885; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003886; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003887; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003888; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003889; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003890; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003891; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003892; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!357&authkey=alw3vqqxz6myrle"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003893; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!362&authkey=alycl9izrvfl7oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003894; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21354&authkey=aa_ukeour7rex1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003895; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21355&authkey=aajjwf_sm4xdqdk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003896; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21357&authkey=alw3vqqxz6myrle"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003897; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21362&authkey=alycl9izrvfl7oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003898; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003899; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003900; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003901; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003902; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003903; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003904; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003905; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003906; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003907; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003908; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003909; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003910; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003911; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003912; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003913; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d4d413b6e7cf7088&resid=d4d413b6e7cf7088%211271&authkey=akz65bxpgvdxjb8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003914; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003915; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003916; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003917; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003918; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003919; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003920; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003921; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003922; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003923; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003924; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003925; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003926; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003927; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003928; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003929; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003930; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003931; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003932; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003933; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003934; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003935; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2!107&authkey=af-bicrg1c6vgck"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003936; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2%21107&authkey=af-bicrg1c6vgck"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003937; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003938; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003939; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003940; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003941; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003942; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003943; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003944; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003945; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003946; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003947; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003948; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003949; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003950; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003951; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003952; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003953; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003954; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003955; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003956; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003957; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003958; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003959; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003960; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003961; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003962; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003963; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003964; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003965; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003966; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003967; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003968; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003969; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003970; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003971; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003972; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003973; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003974; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003975; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003976; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003977; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003978; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003979; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003980; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003981; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003982; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003983; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003984; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003985; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003986; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21848&authkey=ag1_e421v-t5r9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003987; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003988; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003989; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003990; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003991; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003992; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003993; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003994; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003995; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003996; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003997; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003998; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/77jhk0iw"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003999; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/89hkc7wb"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004000; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/yqvsvlvq"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004001; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/llc/mwcacs65xienqdp/"; http_uri; nocase; content:"pierreconsulting.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004002; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skoda22.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004003; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004004; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; http_uri; nocase; content:"qjbutterflyevents.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004005; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004006; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004007; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004008; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004009; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004010; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004011; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/myqseeaccount/one/main/one.htm"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004012; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004013; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004014; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004015; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tennc/webshell/master/other/small_shell.txt"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004016; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; http_uri; nocase; content:"res.yeshen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004017; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/q05z91"; http_uri; nocase; content:"sendspace.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004018; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ey4lpx8rx.zip"; http_uri; nocase; content:"shribharatvatika.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004019; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004020; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004021; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004022; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004023; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004024; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004025; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004026; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004027; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004028; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004029; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004030; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a-nurse-ss8d9/z/"; http_uri; nocase; content:"technologydistilled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004031; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/crisanar/defis/jek_crackme1.7.zip"; http_uri; nocase; content:"users.skynet.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100004032; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/amowvegfrt9ja/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004033; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004034; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wuk/kuqyslbgavnwlmcuk0qalhxifzp4mgze8anlcewu1pa8fw4lfex0y/"; http_uri; nocase; content:"vokasi.ub.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004035; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004036; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004037; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004038; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb%5efr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004039; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb^fr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004040; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004041; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/151_155/tidex_-_short_stuff.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004042; rev:1;) +alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/syria-files/attach/222/222051_instruction.zip"; http_uri; nocase; content:"wikileaks.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004043; rev:1;) diff --git a/urlhaus-filter-snort3-online.rules b/urlhaus-filter-snort3-online.rules index 42798e1c..1ce0dc03 100644 --- a/urlhaus-filter-snort3-online.rules +++ b/urlhaus-filter-snort3-online.rules @@ -1,5 +1,5 @@ # Title: Online Malicious URL Snort3 Ruleset -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -39,38 +39,38 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.98",nocase; classtype:trojan-activity; sid:100000033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.10",nocase; classtype:trojan-activity; sid:100000034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.105",nocase; classtype:trojan-activity; sid:100000035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.109",nocase; classtype:trojan-activity; sid:100000036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.126",nocase; classtype:trojan-activity; sid:100000037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.127",nocase; classtype:trojan-activity; sid:100000038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.130",nocase; classtype:trojan-activity; sid:100000039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.146",nocase; classtype:trojan-activity; sid:100000040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.148",nocase; classtype:trojan-activity; sid:100000041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.15",nocase; classtype:trojan-activity; sid:100000042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.151",nocase; classtype:trojan-activity; sid:100000043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.22",nocase; classtype:trojan-activity; sid:100000044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.32",nocase; classtype:trojan-activity; sid:100000045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.4",nocase; classtype:trojan-activity; sid:100000046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.48",nocase; classtype:trojan-activity; sid:100000047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.54",nocase; classtype:trojan-activity; sid:100000048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.58",nocase; classtype:trojan-activity; sid:100000049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.59",nocase; classtype:trojan-activity; sid:100000050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.6",nocase; classtype:trojan-activity; sid:100000051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.61",nocase; classtype:trojan-activity; sid:100000052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.71",nocase; classtype:trojan-activity; sid:100000053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.83",nocase; classtype:trojan-activity; sid:100000054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.94",nocase; classtype:trojan-activity; sid:100000055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.247.221.141",nocase; classtype:trojan-activity; sid:100000056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.247.221.142",nocase; classtype:trojan-activity; sid:100000057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.250.159.41",nocase; classtype:trojan-activity; sid:100000058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.65.166.225",nocase; classtype:trojan-activity; sid:100000059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.82.104.89",nocase; classtype:trojan-activity; sid:100000060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.12.184.63",nocase; classtype:trojan-activity; sid:100000061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.12.51.122",nocase; classtype:trojan-activity; sid:100000062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.8.77.4",nocase; classtype:trojan-activity; sid:100000063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1008691.com",nocase; classtype:trojan-activity; sid:100000064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.129.251",nocase; classtype:trojan-activity; sid:100000065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.130.121",nocase; classtype:trojan-activity; sid:100000066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.131.47",nocase; classtype:trojan-activity; sid:100000067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.126",nocase; classtype:trojan-activity; sid:100000036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.127",nocase; classtype:trojan-activity; sid:100000037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.130",nocase; classtype:trojan-activity; sid:100000038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.146",nocase; classtype:trojan-activity; sid:100000039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.148",nocase; classtype:trojan-activity; sid:100000040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.15",nocase; classtype:trojan-activity; sid:100000041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.151",nocase; classtype:trojan-activity; sid:100000042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.22",nocase; classtype:trojan-activity; sid:100000043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.32",nocase; classtype:trojan-activity; sid:100000044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.4",nocase; classtype:trojan-activity; sid:100000045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.48",nocase; classtype:trojan-activity; sid:100000046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.54",nocase; classtype:trojan-activity; sid:100000047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.58",nocase; classtype:trojan-activity; sid:100000048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.59",nocase; classtype:trojan-activity; sid:100000049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.6",nocase; classtype:trojan-activity; sid:100000050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.61",nocase; classtype:trojan-activity; sid:100000051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.71",nocase; classtype:trojan-activity; sid:100000052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.83",nocase; classtype:trojan-activity; sid:100000053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.94",nocase; classtype:trojan-activity; sid:100000054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.247.221.141",nocase; classtype:trojan-activity; sid:100000055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.247.221.142",nocase; classtype:trojan-activity; sid:100000056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.250.159.41",nocase; classtype:trojan-activity; sid:100000057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.65.166.225",nocase; classtype:trojan-activity; sid:100000058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.82.104.89",nocase; classtype:trojan-activity; sid:100000059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.12.184.63",nocase; classtype:trojan-activity; sid:100000060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.12.51.122",nocase; classtype:trojan-activity; sid:100000061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.8.77.4",nocase; classtype:trojan-activity; sid:100000062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1008691.com",nocase; classtype:trojan-activity; sid:100000063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.129.251",nocase; classtype:trojan-activity; sid:100000064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.130.121",nocase; classtype:trojan-activity; sid:100000065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.131.99",nocase; classtype:trojan-activity; sid:100000066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.138.150",nocase; classtype:trojan-activity; sid:100000067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.16.183.179",nocase; classtype:trojan-activity; sid:100000068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.229.85.127",nocase; classtype:trojan-activity; sid:100000069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.255.36.154",nocase; classtype:trojan-activity; sid:100000070; rev:1;) @@ -78,402 +78,402 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.218.245",nocase; classtype:trojan-activity; sid:100000072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.76.34",nocase; classtype:trojan-activity; sid:100000073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.75.157.99",nocase; classtype:trojan-activity; sid:100000074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.130.115.14",nocase; classtype:trojan-activity; sid:100000075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.141.240.139",nocase; classtype:trojan-activity; sid:100000076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.113.99.79",nocase; classtype:trojan-activity; sid:100000077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.136.82.50",nocase; classtype:trojan-activity; sid:100000078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.16.145.25",nocase; classtype:trojan-activity; sid:100000079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.204.168.34",nocase; classtype:trojan-activity; sid:100000080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.217.215.21",nocase; classtype:trojan-activity; sid:100000081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.219.152.228",nocase; classtype:trojan-activity; sid:100000082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.224.200.146",nocase; classtype:trojan-activity; sid:100000083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.224.200.40",nocase; classtype:trojan-activity; sid:100000084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.227.118.129",nocase; classtype:trojan-activity; sid:100000085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.237.21.36",nocase; classtype:trojan-activity; sid:100000086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.238.228.3",nocase; classtype:trojan-activity; sid:100000087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.240.249.121",nocase; classtype:trojan-activity; sid:100000088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.4.117.26",nocase; classtype:trojan-activity; sid:100000089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.47.104.246",nocase; classtype:trojan-activity; sid:100000090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.99.91.200",nocase; classtype:trojan-activity; sid:100000075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.99.94.15",nocase; classtype:trojan-activity; sid:100000076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.130.115.14",nocase; classtype:trojan-activity; sid:100000077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.141.240.139",nocase; classtype:trojan-activity; sid:100000078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.113.99.79",nocase; classtype:trojan-activity; sid:100000079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.136.82.50",nocase; classtype:trojan-activity; sid:100000080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.16.145.25",nocase; classtype:trojan-activity; sid:100000081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.204.168.34",nocase; classtype:trojan-activity; sid:100000082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.217.215.21",nocase; classtype:trojan-activity; sid:100000083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.219.152.228",nocase; classtype:trojan-activity; sid:100000084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.224.200.146",nocase; classtype:trojan-activity; sid:100000085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.224.200.40",nocase; classtype:trojan-activity; sid:100000086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.227.118.129",nocase; classtype:trojan-activity; sid:100000087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.237.21.36",nocase; classtype:trojan-activity; sid:100000088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.238.228.3",nocase; classtype:trojan-activity; sid:100000089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.240.249.121",nocase; classtype:trojan-activity; sid:100000090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.79.112.254",nocase; classtype:trojan-activity; sid:100000091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.98.170",nocase; classtype:trojan-activity; sid:100000092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.81.37",nocase; classtype:trojan-activity; sid:100000092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.240.130",nocase; classtype:trojan-activity; sid:100000093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.241.94",nocase; classtype:trojan-activity; sid:100000094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.12",nocase; classtype:trojan-activity; sid:100000095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.13",nocase; classtype:trojan-activity; sid:100000096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.14",nocase; classtype:trojan-activity; sid:100000097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.16",nocase; classtype:trojan-activity; sid:100000098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.17",nocase; classtype:trojan-activity; sid:100000099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.27",nocase; classtype:trojan-activity; sid:100000100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.3",nocase; classtype:trojan-activity; sid:100000101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.36",nocase; classtype:trojan-activity; sid:100000102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.46",nocase; classtype:trojan-activity; sid:100000103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.47",nocase; classtype:trojan-activity; sid:100000104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.90",nocase; classtype:trojan-activity; sid:100000105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.95",nocase; classtype:trojan-activity; sid:100000106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.168.44.57",nocase; classtype:trojan-activity; sid:100000107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.184.75.123",nocase; classtype:trojan-activity; sid:100000108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.206.93.94",nocase; classtype:trojan-activity; sid:100000109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.33.52.85",nocase; classtype:trojan-activity; sid:100000110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.61.86.37",nocase; classtype:trojan-activity; sid:100000111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.1.111.91",nocase; classtype:trojan-activity; sid:100000112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.172.178",nocase; classtype:trojan-activity; sid:100000113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.193.155",nocase; classtype:trojan-activity; sid:100000114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.105.33.43",nocase; classtype:trojan-activity; sid:100000115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.104.105",nocase; classtype:trojan-activity; sid:100000116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.141.115",nocase; classtype:trojan-activity; sid:100000117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.249.148",nocase; classtype:trojan-activity; sid:100000118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.219.80",nocase; classtype:trojan-activity; sid:100000119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.23.240",nocase; classtype:trojan-activity; sid:100000120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.24.143",nocase; classtype:trojan-activity; sid:100000121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.61.139",nocase; classtype:trojan-activity; sid:100000122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.197.135",nocase; classtype:trojan-activity; sid:100000123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.33.48",nocase; classtype:trojan-activity; sid:100000124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.181.136.96",nocase; classtype:trojan-activity; sid:100000125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.194.242.170",nocase; classtype:trojan-activity; sid:100000126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.219.185.75",nocase; classtype:trojan-activity; sid:100000127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.220.119.25",nocase; classtype:trojan-activity; sid:100000128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.221.96.202",nocase; classtype:trojan-activity; sid:100000129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.201.37",nocase; classtype:trojan-activity; sid:100000130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.250.48",nocase; classtype:trojan-activity; sid:100000131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.239.155.26",nocase; classtype:trojan-activity; sid:100000132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.249.194.121",nocase; classtype:trojan-activity; sid:100000133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.104.151.108",nocase; classtype:trojan-activity; sid:100000134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.124.90.229",nocase; classtype:trojan-activity; sid:100000135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.233.196.232",nocase; classtype:trojan-activity; sid:100000136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.235.7.228",nocase; classtype:trojan-activity; sid:100000137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.86.85.253",nocase; classtype:trojan-activity; sid:100000138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.102",nocase; classtype:trojan-activity; sid:100000139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.230",nocase; classtype:trojan-activity; sid:100000140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.127.90",nocase; classtype:trojan-activity; sid:100000141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.57.246",nocase; classtype:trojan-activity; sid:100000142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.99.37.97",nocase; classtype:trojan-activity; sid:100000143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.14.58.190",nocase; classtype:trojan-activity; sid:100000144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.182.102.201",nocase; classtype:trojan-activity; sid:100000145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.182.126.118",nocase; classtype:trojan-activity; sid:100000146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.187.229.182",nocase; classtype:trojan-activity; sid:100000147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.124.254",nocase; classtype:trojan-activity; sid:100000148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.175.141",nocase; classtype:trojan-activity; sid:100000149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.251.194",nocase; classtype:trojan-activity; sid:100000150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.251.10.18",nocase; classtype:trojan-activity; sid:100000151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.213.198",nocase; classtype:trojan-activity; sid:100000152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.208.21",nocase; classtype:trojan-activity; sid:100000153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.209.175",nocase; classtype:trojan-activity; sid:100000154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.223.92",nocase; classtype:trojan-activity; sid:100000155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.225.24",nocase; classtype:trojan-activity; sid:100000156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.235.57",nocase; classtype:trojan-activity; sid:100000157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.4.2",nocase; classtype:trojan-activity; sid:100000158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.88.128",nocase; classtype:trojan-activity; sid:100000159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.88.61",nocase; classtype:trojan-activity; sid:100000160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.119.245.114",nocase; classtype:trojan-activity; sid:100000161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.125.67.125",nocase; classtype:trojan-activity; sid:100000162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.86.31",nocase; classtype:trojan-activity; sid:100000163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.172.57.20",nocase; classtype:trojan-activity; sid:100000164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.182.237.107",nocase; classtype:trojan-activity; sid:100000165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.171.111",nocase; classtype:trojan-activity; sid:100000166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.177.85",nocase; classtype:trojan-activity; sid:100000167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.23.84",nocase; classtype:trojan-activity; sid:100000168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.230.136",nocase; classtype:trojan-activity; sid:100000169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.27.9",nocase; classtype:trojan-activity; sid:100000170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.49.223",nocase; classtype:trojan-activity; sid:100000171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.114",nocase; classtype:trojan-activity; sid:100000172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.122",nocase; classtype:trojan-activity; sid:100000173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.141",nocase; classtype:trojan-activity; sid:100000174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.222",nocase; classtype:trojan-activity; sid:100000175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.223",nocase; classtype:trojan-activity; sid:100000176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.226",nocase; classtype:trojan-activity; sid:100000177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.136",nocase; classtype:trojan-activity; sid:100000178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.15",nocase; classtype:trojan-activity; sid:100000179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.200",nocase; classtype:trojan-activity; sid:100000180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.26.243",nocase; classtype:trojan-activity; sid:100000181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.8.81",nocase; classtype:trojan-activity; sid:100000182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.108.184",nocase; classtype:trojan-activity; sid:100000183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.133.222.151",nocase; classtype:trojan-activity; sid:100000184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.124.75",nocase; classtype:trojan-activity; sid:100000185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.233.9",nocase; classtype:trojan-activity; sid:100000186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.210.211",nocase; classtype:trojan-activity; sid:100000187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.96.252",nocase; classtype:trojan-activity; sid:100000188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.187.91.117",nocase; classtype:trojan-activity; sid:100000189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.214.127.42",nocase; classtype:trojan-activity; sid:100000190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.187.19",nocase; classtype:trojan-activity; sid:100000191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.236.77",nocase; classtype:trojan-activity; sid:100000192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.239.126",nocase; classtype:trojan-activity; sid:100000193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.43.27",nocase; classtype:trojan-activity; sid:100000194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.162.148",nocase; classtype:trojan-activity; sid:100000195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.180.95",nocase; classtype:trojan-activity; sid:100000196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.230.168.103",nocase; classtype:trojan-activity; sid:100000197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.232.0.112",nocase; classtype:trojan-activity; sid:100000198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.141.241",nocase; classtype:trojan-activity; sid:100000199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.144.226",nocase; classtype:trojan-activity; sid:100000200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.75.157",nocase; classtype:trojan-activity; sid:100000201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.99.207",nocase; classtype:trojan-activity; sid:100000202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.143.135",nocase; classtype:trojan-activity; sid:100000203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.190.207",nocase; classtype:trojan-activity; sid:100000204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.227.228",nocase; classtype:trojan-activity; sid:100000205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.39.2",nocase; classtype:trojan-activity; sid:100000206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.239.101.146",nocase; classtype:trojan-activity; sid:100000207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.240.216.17",nocase; classtype:trojan-activity; sid:100000208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.12.89",nocase; classtype:trojan-activity; sid:100000209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.8.24",nocase; classtype:trojan-activity; sid:100000210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.126.58",nocase; classtype:trojan-activity; sid:100000211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.162.50",nocase; classtype:trojan-activity; sid:100000212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.100.14",nocase; classtype:trojan-activity; sid:100000213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.16.222",nocase; classtype:trojan-activity; sid:100000214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.191.118",nocase; classtype:trojan-activity; sid:100000215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.214.146",nocase; classtype:trojan-activity; sid:100000216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.240.226",nocase; classtype:trojan-activity; sid:100000217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.82.122",nocase; classtype:trojan-activity; sid:100000218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.148.90",nocase; classtype:trojan-activity; sid:100000219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.63.212",nocase; classtype:trojan-activity; sid:100000220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.109.217",nocase; classtype:trojan-activity; sid:100000221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.118.157",nocase; classtype:trojan-activity; sid:100000222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.102.173",nocase; classtype:trojan-activity; sid:100000223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.218.210",nocase; classtype:trojan-activity; sid:100000224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.128.143",nocase; classtype:trojan-activity; sid:100000225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.221.244",nocase; classtype:trojan-activity; sid:100000226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.6.129",nocase; classtype:trojan-activity; sid:100000227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.8.235",nocase; classtype:trojan-activity; sid:100000228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.120",nocase; classtype:trojan-activity; sid:100000229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.124",nocase; classtype:trojan-activity; sid:100000230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.131",nocase; classtype:trojan-activity; sid:100000231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.132",nocase; classtype:trojan-activity; sid:100000232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.133",nocase; classtype:trojan-activity; sid:100000233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.139",nocase; classtype:trojan-activity; sid:100000234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.143",nocase; classtype:trojan-activity; sid:100000235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.147",nocase; classtype:trojan-activity; sid:100000236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.149",nocase; classtype:trojan-activity; sid:100000237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.158",nocase; classtype:trojan-activity; sid:100000238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.165",nocase; classtype:trojan-activity; sid:100000239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.175",nocase; classtype:trojan-activity; sid:100000240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.177",nocase; classtype:trojan-activity; sid:100000241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.179",nocase; classtype:trojan-activity; sid:100000242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.125.109",nocase; classtype:trojan-activity; sid:100000243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.127.155",nocase; classtype:trojan-activity; sid:100000244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.80.120",nocase; classtype:trojan-activity; sid:100000245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.81.238",nocase; classtype:trojan-activity; sid:100000246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.82.29",nocase; classtype:trojan-activity; sid:100000247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.182",nocase; classtype:trojan-activity; sid:100000248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.85.113",nocase; classtype:trojan-activity; sid:100000249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.87.130",nocase; classtype:trojan-activity; sid:100000250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.88.116",nocase; classtype:trojan-activity; sid:100000251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.91.212",nocase; classtype:trojan-activity; sid:100000252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.119",nocase; classtype:trojan-activity; sid:100000253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.149",nocase; classtype:trojan-activity; sid:100000254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.158",nocase; classtype:trojan-activity; sid:100000255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.159",nocase; classtype:trojan-activity; sid:100000256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.168",nocase; classtype:trojan-activity; sid:100000257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.177",nocase; classtype:trojan-activity; sid:100000258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.200",nocase; classtype:trojan-activity; sid:100000259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.211",nocase; classtype:trojan-activity; sid:100000260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.219",nocase; classtype:trojan-activity; sid:100000261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.230",nocase; classtype:trojan-activity; sid:100000262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.238",nocase; classtype:trojan-activity; sid:100000263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.245",nocase; classtype:trojan-activity; sid:100000264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.247",nocase; classtype:trojan-activity; sid:100000265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.55",nocase; classtype:trojan-activity; sid:100000266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.60",nocase; classtype:trojan-activity; sid:100000267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.90",nocase; classtype:trojan-activity; sid:100000268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.91",nocase; classtype:trojan-activity; sid:100000269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.38",nocase; classtype:trojan-activity; sid:100000270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.45",nocase; classtype:trojan-activity; sid:100000271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.60",nocase; classtype:trojan-activity; sid:100000272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.35.237",nocase; classtype:trojan-activity; sid:100000273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.103",nocase; classtype:trojan-activity; sid:100000274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.118",nocase; classtype:trojan-activity; sid:100000275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.124",nocase; classtype:trojan-activity; sid:100000276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.53",nocase; classtype:trojan-activity; sid:100000277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.61",nocase; classtype:trojan-activity; sid:100000278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.68",nocase; classtype:trojan-activity; sid:100000279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.70",nocase; classtype:trojan-activity; sid:100000280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.73",nocase; classtype:trojan-activity; sid:100000281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.90",nocase; classtype:trojan-activity; sid:100000282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.0.113",nocase; classtype:trojan-activity; sid:100000283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.177.39",nocase; classtype:trojan-activity; sid:100000284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.211.135",nocase; classtype:trojan-activity; sid:100000285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.216.207",nocase; classtype:trojan-activity; sid:100000286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.240.239",nocase; classtype:trojan-activity; sid:100000287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.224.79",nocase; classtype:trojan-activity; sid:100000288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.227.66",nocase; classtype:trojan-activity; sid:100000289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.65.53.175",nocase; classtype:trojan-activity; sid:100000290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.49",nocase; classtype:trojan-activity; sid:100000291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.175.147",nocase; classtype:trojan-activity; sid:100000292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.112",nocase; classtype:trojan-activity; sid:100000293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.226.202",nocase; classtype:trojan-activity; sid:100000294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.215.101",nocase; classtype:trojan-activity; sid:100000295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.146.253",nocase; classtype:trojan-activity; sid:100000296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.224.139",nocase; classtype:trojan-activity; sid:100000297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.93.29.211",nocase; classtype:trojan-activity; sid:100000298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.11.95.254",nocase; classtype:trojan-activity; sid:100000299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.118.249.97",nocase; classtype:trojan-activity; sid:100000300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.122.238.68",nocase; classtype:trojan-activity; sid:100000301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.13.241.32",nocase; classtype:trojan-activity; sid:100000302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.161.58.249",nocase; classtype:trojan-activity; sid:100000303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.161.78.185",nocase; classtype:trojan-activity; sid:100000304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.230.86.107",nocase; classtype:trojan-activity; sid:100000305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.184.245",nocase; classtype:trojan-activity; sid:100000306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.211.131",nocase; classtype:trojan-activity; sid:100000307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.254.169.251",nocase; classtype:trojan-activity; sid:100000308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.128.133",nocase; classtype:trojan-activity; sid:100000309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.149.125",nocase; classtype:trojan-activity; sid:100000310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.154.21",nocase; classtype:trojan-activity; sid:100000311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.180.40",nocase; classtype:trojan-activity; sid:100000312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.191.47",nocase; classtype:trojan-activity; sid:100000313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.61.204.205",nocase; classtype:trojan-activity; sid:100000314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.65.10.139",nocase; classtype:trojan-activity; sid:100000315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.153.5",nocase; classtype:trojan-activity; sid:100000316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.192.87",nocase; classtype:trojan-activity; sid:100000317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.89.43.165",nocase; classtype:trojan-activity; sid:100000318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.199.204.37",nocase; classtype:trojan-activity; sid:100000319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.199.253.235",nocase; classtype:trojan-activity; sid:100000320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.201.201.68",nocase; classtype:trojan-activity; sid:100000321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.224.203.128",nocase; classtype:trojan-activity; sid:100000322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.30.54.64",nocase; classtype:trojan-activity; sid:100000323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.35.254.7",nocase; classtype:trojan-activity; sid:100000324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.79.172.42",nocase; classtype:trojan-activity; sid:100000325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.165.216.112",nocase; classtype:trojan-activity; sid:100000326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.171.204.161",nocase; classtype:trojan-activity; sid:100000327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.42.47.36",nocase; classtype:trojan-activity; sid:100000328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.140.22",nocase; classtype:trojan-activity; sid:100000329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.77.222",nocase; classtype:trojan-activity; sid:100000330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.106.238",nocase; classtype:trojan-activity; sid:100000331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.53.203.161",nocase; classtype:trojan-activity; sid:100000332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.241.214",nocase; classtype:trojan-activity; sid:100000333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.156.203",nocase; classtype:trojan-activity; sid:100000334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.131.242",nocase; classtype:trojan-activity; sid:100000335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.133.96",nocase; classtype:trojan-activity; sid:100000336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.155.202",nocase; classtype:trojan-activity; sid:100000337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.178.168",nocase; classtype:trojan-activity; sid:100000338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.182.146",nocase; classtype:trojan-activity; sid:100000339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.182.151",nocase; classtype:trojan-activity; sid:100000340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.111.76",nocase; classtype:trojan-activity; sid:100000341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.132.140",nocase; classtype:trojan-activity; sid:100000342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.203.197",nocase; classtype:trojan-activity; sid:100000343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.214.205",nocase; classtype:trojan-activity; sid:100000344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.233.160",nocase; classtype:trojan-activity; sid:100000345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.252.120",nocase; classtype:trojan-activity; sid:100000346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.110.120",nocase; classtype:trojan-activity; sid:100000347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.73.3.11",nocase; classtype:trojan-activity; sid:100000348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.75.217.79",nocase; classtype:trojan-activity; sid:100000349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.88.133.148",nocase; classtype:trojan-activity; sid:100000350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.92.174.231",nocase; classtype:trojan-activity; sid:100000351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.97.139.110",nocase; classtype:trojan-activity; sid:100000352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.124.219.2",nocase; classtype:trojan-activity; sid:100000353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.206.164.46",nocase; classtype:trojan-activity; sid:100000354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.211.100.26",nocase; classtype:trojan-activity; sid:100000355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.138",nocase; classtype:trojan-activity; sid:100000356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.5",nocase; classtype:trojan-activity; sid:100000357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.210.52",nocase; classtype:trojan-activity; sid:100000358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.243.40",nocase; classtype:trojan-activity; sid:100000359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.201.205.232",nocase; classtype:trojan-activity; sid:100000360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.251.59.124",nocase; classtype:trojan-activity; sid:100000361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.26.124.173",nocase; classtype:trojan-activity; sid:100000362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.113.146",nocase; classtype:trojan-activity; sid:100000363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.53.15",nocase; classtype:trojan-activity; sid:100000364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.86.105.110",nocase; classtype:trojan-activity; sid:100000365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.101.7.28",nocase; classtype:trojan-activity; sid:100000366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.104.35",nocase; classtype:trojan-activity; sid:100000367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.157.64",nocase; classtype:trojan-activity; sid:100000368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.7.132",nocase; classtype:trojan-activity; sid:100000369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.32.74",nocase; classtype:trojan-activity; sid:100000370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.5.149",nocase; classtype:trojan-activity; sid:100000371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.72.141",nocase; classtype:trojan-activity; sid:100000372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.12.130",nocase; classtype:trojan-activity; sid:100000373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.128.147",nocase; classtype:trojan-activity; sid:100000374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.208.215",nocase; classtype:trojan-activity; sid:100000375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.209.108",nocase; classtype:trojan-activity; sid:100000376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.214.72",nocase; classtype:trojan-activity; sid:100000377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.88.146",nocase; classtype:trojan-activity; sid:100000378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.150",nocase; classtype:trojan-activity; sid:100000379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.6",nocase; classtype:trojan-activity; sid:100000380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.165.213",nocase; classtype:trojan-activity; sid:100000381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.221.162",nocase; classtype:trojan-activity; sid:100000382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.63.194",nocase; classtype:trojan-activity; sid:100000383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.65.93",nocase; classtype:trojan-activity; sid:100000384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.42.125.246",nocase; classtype:trojan-activity; sid:100000385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.43.180.33",nocase; classtype:trojan-activity; sid:100000386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.218.213",nocase; classtype:trojan-activity; sid:100000387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.50.203",nocase; classtype:trojan-activity; sid:100000388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.74.77",nocase; classtype:trojan-activity; sid:100000389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.91.41.135",nocase; classtype:trojan-activity; sid:100000390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.179.164",nocase; classtype:trojan-activity; sid:100000391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.183.235",nocase; classtype:trojan-activity; sid:100000392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.239.217",nocase; classtype:trojan-activity; sid:100000393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.14.143.145",nocase; classtype:trojan-activity; sid:100000394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.147.213.57",nocase; classtype:trojan-activity; sid:100000395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.18.235",nocase; classtype:trojan-activity; sid:100000396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.218.229",nocase; classtype:trojan-activity; sid:100000397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.107.93",nocase; classtype:trojan-activity; sid:100000398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.241.222",nocase; classtype:trojan-activity; sid:100000399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.27.77",nocase; classtype:trojan-activity; sid:100000400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.68.145",nocase; classtype:trojan-activity; sid:100000401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.97.6",nocase; classtype:trojan-activity; sid:100000402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.26.33",nocase; classtype:trojan-activity; sid:100000403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.177.147.38",nocase; classtype:trojan-activity; sid:100000404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.248.123",nocase; classtype:trojan-activity; sid:100000405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.43.1",nocase; classtype:trojan-activity; sid:100000406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.58.163",nocase; classtype:trojan-activity; sid:100000407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.18.38.144",nocase; classtype:trojan-activity; sid:100000408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.106.217",nocase; classtype:trojan-activity; sid:100000409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.119.21",nocase; classtype:trojan-activity; sid:100000410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.182.97.232",nocase; classtype:trojan-activity; sid:100000411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.172.199",nocase; classtype:trojan-activity; sid:100000412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.15.159",nocase; classtype:trojan-activity; sid:100000413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.195.161",nocase; classtype:trojan-activity; sid:100000414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.245.61",nocase; classtype:trojan-activity; sid:100000415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.137.195",nocase; classtype:trojan-activity; sid:100000416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.227.244",nocase; classtype:trojan-activity; sid:100000417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.187.206",nocase; classtype:trojan-activity; sid:100000418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.215.221",nocase; classtype:trojan-activity; sid:100000419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.240.20",nocase; classtype:trojan-activity; sid:100000420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.255.236",nocase; classtype:trojan-activity; sid:100000421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.204.30.144",nocase; classtype:trojan-activity; sid:100000422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.250.129.231",nocase; classtype:trojan-activity; sid:100000423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.105.221",nocase; classtype:trojan-activity; sid:100000424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.131.155",nocase; classtype:trojan-activity; sid:100000425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.46",nocase; classtype:trojan-activity; sid:100000426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.71",nocase; classtype:trojan-activity; sid:100000427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.148.115",nocase; classtype:trojan-activity; sid:100000428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.155.57",nocase; classtype:trojan-activity; sid:100000429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.166.36",nocase; classtype:trojan-activity; sid:100000430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.96.38.150",nocase; classtype:trojan-activity; sid:100000431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.132.113.2",nocase; classtype:trojan-activity; sid:100000432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.15.69.83",nocase; classtype:trojan-activity; sid:100000433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.6",nocase; classtype:trojan-activity; sid:100000434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.7",nocase; classtype:trojan-activity; sid:100000435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.8",nocase; classtype:trojan-activity; sid:100000436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.9",nocase; classtype:trojan-activity; sid:100000437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.207.39.227",nocase; classtype:trojan-activity; sid:100000438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.25.204.189",nocase; classtype:trojan-activity; sid:100000439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.70.108.141",nocase; classtype:trojan-activity; sid:100000440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.0.255.173",nocase; classtype:trojan-activity; sid:100000441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.1.54.62",nocase; classtype:trojan-activity; sid:100000442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.142.222.22",nocase; classtype:trojan-activity; sid:100000443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.150.213.110",nocase; classtype:trojan-activity; sid:100000444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.151.248.134",nocase; classtype:trojan-activity; sid:100000445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.180",nocase; classtype:trojan-activity; sid:100000446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.183",nocase; classtype:trojan-activity; sid:100000447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.185",nocase; classtype:trojan-activity; sid:100000448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.191",nocase; classtype:trojan-activity; sid:100000449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.193",nocase; classtype:trojan-activity; sid:100000450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.201",nocase; classtype:trojan-activity; sid:100000451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.202",nocase; classtype:trojan-activity; sid:100000452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.204",nocase; classtype:trojan-activity; sid:100000453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.208",nocase; classtype:trojan-activity; sid:100000454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.215",nocase; classtype:trojan-activity; sid:100000455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.233",nocase; classtype:trojan-activity; sid:100000456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.235",nocase; classtype:trojan-activity; sid:100000457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.239",nocase; classtype:trojan-activity; sid:100000458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.25",nocase; classtype:trojan-activity; sid:100000459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.250",nocase; classtype:trojan-activity; sid:100000460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.60",nocase; classtype:trojan-activity; sid:100000461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.74",nocase; classtype:trojan-activity; sid:100000462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.99.127",nocase; classtype:trojan-activity; sid:100000463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.66.60",nocase; classtype:trojan-activity; sid:100000464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.93.115",nocase; classtype:trojan-activity; sid:100000465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.57.123.202",nocase; classtype:trojan-activity; sid:100000466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.8.11",nocase; classtype:trojan-activity; sid:100000467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.7.75.99",nocase; classtype:trojan-activity; sid:100000468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.83.79.42",nocase; classtype:trojan-activity; sid:100000469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.172.111",nocase; classtype:trojan-activity; sid:100000470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.14",nocase; classtype:trojan-activity; sid:100000096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.19",nocase; classtype:trojan-activity; sid:100000097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.36",nocase; classtype:trojan-activity; sid:100000098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.48",nocase; classtype:trojan-activity; sid:100000099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.90",nocase; classtype:trojan-activity; sid:100000100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.95",nocase; classtype:trojan-activity; sid:100000101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.97.184.180",nocase; classtype:trojan-activity; sid:100000102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.184.75.123",nocase; classtype:trojan-activity; sid:100000103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.206.93.94",nocase; classtype:trojan-activity; sid:100000104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.33.52.85",nocase; classtype:trojan-activity; sid:100000105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.61.86.37",nocase; classtype:trojan-activity; sid:100000106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.1.111.91",nocase; classtype:trojan-activity; sid:100000107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.172.178",nocase; classtype:trojan-activity; sid:100000108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.193.155",nocase; classtype:trojan-activity; sid:100000109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.105.33.43",nocase; classtype:trojan-activity; sid:100000110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.104.105",nocase; classtype:trojan-activity; sid:100000111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.141.115",nocase; classtype:trojan-activity; sid:100000112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.156.3",nocase; classtype:trojan-activity; sid:100000113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.249.148",nocase; classtype:trojan-activity; sid:100000114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.219.80",nocase; classtype:trojan-activity; sid:100000115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.23.240",nocase; classtype:trojan-activity; sid:100000116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.24.143",nocase; classtype:trojan-activity; sid:100000117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.61.139",nocase; classtype:trojan-activity; sid:100000118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.197.135",nocase; classtype:trojan-activity; sid:100000119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.33.48",nocase; classtype:trojan-activity; sid:100000120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.181.136.96",nocase; classtype:trojan-activity; sid:100000121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.194.242.170",nocase; classtype:trojan-activity; sid:100000122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.219.185.75",nocase; classtype:trojan-activity; sid:100000123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.220.119.25",nocase; classtype:trojan-activity; sid:100000124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.221.96.202",nocase; classtype:trojan-activity; sid:100000125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.201.37",nocase; classtype:trojan-activity; sid:100000126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.250.48",nocase; classtype:trojan-activity; sid:100000127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.239.155.26",nocase; classtype:trojan-activity; sid:100000128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.249.194.121",nocase; classtype:trojan-activity; sid:100000129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.124.90.229",nocase; classtype:trojan-activity; sid:100000130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.233.196.232",nocase; classtype:trojan-activity; sid:100000131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.235.7.228",nocase; classtype:trojan-activity; sid:100000132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.248.58.238",nocase; classtype:trojan-activity; sid:100000133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.86.85.253",nocase; classtype:trojan-activity; sid:100000134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.102",nocase; classtype:trojan-activity; sid:100000135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.230",nocase; classtype:trojan-activity; sid:100000136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.127.90",nocase; classtype:trojan-activity; sid:100000137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.57.246",nocase; classtype:trojan-activity; sid:100000138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.99.37.97",nocase; classtype:trojan-activity; sid:100000139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.14.58.190",nocase; classtype:trojan-activity; sid:100000140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.182.102.201",nocase; classtype:trojan-activity; sid:100000141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.182.126.118",nocase; classtype:trojan-activity; sid:100000142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.187.229.182",nocase; classtype:trojan-activity; sid:100000143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.124.254",nocase; classtype:trojan-activity; sid:100000144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.175.141",nocase; classtype:trojan-activity; sid:100000145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.251.194",nocase; classtype:trojan-activity; sid:100000146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.251.10.18",nocase; classtype:trojan-activity; sid:100000147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.213.198",nocase; classtype:trojan-activity; sid:100000148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.145.127",nocase; classtype:trojan-activity; sid:100000149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.208.21",nocase; classtype:trojan-activity; sid:100000150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.221.77",nocase; classtype:trojan-activity; sid:100000151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.235.57",nocase; classtype:trojan-activity; sid:100000152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.249.21",nocase; classtype:trojan-activity; sid:100000153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.4.2",nocase; classtype:trojan-activity; sid:100000154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.89.10.147",nocase; classtype:trojan-activity; sid:100000155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.88.61",nocase; classtype:trojan-activity; sid:100000156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.119.245.114",nocase; classtype:trojan-activity; sid:100000157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.125.67.125",nocase; classtype:trojan-activity; sid:100000158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.86.31",nocase; classtype:trojan-activity; sid:100000159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.172.57.20",nocase; classtype:trojan-activity; sid:100000160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.182.237.107",nocase; classtype:trojan-activity; sid:100000161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.171.111",nocase; classtype:trojan-activity; sid:100000162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.177.85",nocase; classtype:trojan-activity; sid:100000163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.23.84",nocase; classtype:trojan-activity; sid:100000164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.230.136",nocase; classtype:trojan-activity; sid:100000165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.27.9",nocase; classtype:trojan-activity; sid:100000166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.49.223",nocase; classtype:trojan-activity; sid:100000167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.114",nocase; classtype:trojan-activity; sid:100000168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.122",nocase; classtype:trojan-activity; sid:100000169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.222",nocase; classtype:trojan-activity; sid:100000170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.226",nocase; classtype:trojan-activity; sid:100000171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.136",nocase; classtype:trojan-activity; sid:100000172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.200",nocase; classtype:trojan-activity; sid:100000173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.26.243",nocase; classtype:trojan-activity; sid:100000174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.8.81",nocase; classtype:trojan-activity; sid:100000175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.108.184",nocase; classtype:trojan-activity; sid:100000176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.133.222.151",nocase; classtype:trojan-activity; sid:100000177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.124.75",nocase; classtype:trojan-activity; sid:100000178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.233.9",nocase; classtype:trojan-activity; sid:100000179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.210.211",nocase; classtype:trojan-activity; sid:100000180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.96.252",nocase; classtype:trojan-activity; sid:100000181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.187.91.117",nocase; classtype:trojan-activity; sid:100000182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.214.127.42",nocase; classtype:trojan-activity; sid:100000183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.187.19",nocase; classtype:trojan-activity; sid:100000184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.236.77",nocase; classtype:trojan-activity; sid:100000185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.239.126",nocase; classtype:trojan-activity; sid:100000186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.43.27",nocase; classtype:trojan-activity; sid:100000187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.162.148",nocase; classtype:trojan-activity; sid:100000188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.180.95",nocase; classtype:trojan-activity; sid:100000189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.230.168.103",nocase; classtype:trojan-activity; sid:100000190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.232.0.112",nocase; classtype:trojan-activity; sid:100000191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.141.241",nocase; classtype:trojan-activity; sid:100000192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.143.135",nocase; classtype:trojan-activity; sid:100000193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.190.207",nocase; classtype:trojan-activity; sid:100000194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.39.2",nocase; classtype:trojan-activity; sid:100000195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.239.101.146",nocase; classtype:trojan-activity; sid:100000196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.240.216.17",nocase; classtype:trojan-activity; sid:100000197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.12.89",nocase; classtype:trojan-activity; sid:100000198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.8.24",nocase; classtype:trojan-activity; sid:100000199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.126.58",nocase; classtype:trojan-activity; sid:100000200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.162.50",nocase; classtype:trojan-activity; sid:100000201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.100.14",nocase; classtype:trojan-activity; sid:100000202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.16.222",nocase; classtype:trojan-activity; sid:100000203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.191.118",nocase; classtype:trojan-activity; sid:100000204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.214.146",nocase; classtype:trojan-activity; sid:100000205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.240.226",nocase; classtype:trojan-activity; sid:100000206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.82.122",nocase; classtype:trojan-activity; sid:100000207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.109.156",nocase; classtype:trojan-activity; sid:100000208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.148.90",nocase; classtype:trojan-activity; sid:100000209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.63.212",nocase; classtype:trojan-activity; sid:100000210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.109.217",nocase; classtype:trojan-activity; sid:100000211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.118.157",nocase; classtype:trojan-activity; sid:100000212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.102.173",nocase; classtype:trojan-activity; sid:100000213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.218.210",nocase; classtype:trojan-activity; sid:100000214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.128.143",nocase; classtype:trojan-activity; sid:100000215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.221.244",nocase; classtype:trojan-activity; sid:100000216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.6.129",nocase; classtype:trojan-activity; sid:100000217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.8.235",nocase; classtype:trojan-activity; sid:100000218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.120",nocase; classtype:trojan-activity; sid:100000219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.124",nocase; classtype:trojan-activity; sid:100000220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.131",nocase; classtype:trojan-activity; sid:100000221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.132",nocase; classtype:trojan-activity; sid:100000222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.133",nocase; classtype:trojan-activity; sid:100000223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.139",nocase; classtype:trojan-activity; sid:100000224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.143",nocase; classtype:trojan-activity; sid:100000225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.147",nocase; classtype:trojan-activity; sid:100000226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.149",nocase; classtype:trojan-activity; sid:100000227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.150",nocase; classtype:trojan-activity; sid:100000228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.158",nocase; classtype:trojan-activity; sid:100000229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.165",nocase; classtype:trojan-activity; sid:100000230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.175",nocase; classtype:trojan-activity; sid:100000231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.177",nocase; classtype:trojan-activity; sid:100000232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.179",nocase; classtype:trojan-activity; sid:100000233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.125.109",nocase; classtype:trojan-activity; sid:100000234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.127.155",nocase; classtype:trojan-activity; sid:100000235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.80.120",nocase; classtype:trojan-activity; sid:100000236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.81.238",nocase; classtype:trojan-activity; sid:100000237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.82.29",nocase; classtype:trojan-activity; sid:100000238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.182",nocase; classtype:trojan-activity; sid:100000239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.85.113",nocase; classtype:trojan-activity; sid:100000240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.87.130",nocase; classtype:trojan-activity; sid:100000241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.88.116",nocase; classtype:trojan-activity; sid:100000242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.91.212",nocase; classtype:trojan-activity; sid:100000243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.119",nocase; classtype:trojan-activity; sid:100000244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.149",nocase; classtype:trojan-activity; sid:100000245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.158",nocase; classtype:trojan-activity; sid:100000246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.159",nocase; classtype:trojan-activity; sid:100000247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.168",nocase; classtype:trojan-activity; sid:100000248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.177",nocase; classtype:trojan-activity; sid:100000249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.200",nocase; classtype:trojan-activity; sid:100000250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.211",nocase; classtype:trojan-activity; sid:100000251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.219",nocase; classtype:trojan-activity; sid:100000252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.230",nocase; classtype:trojan-activity; sid:100000253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.238",nocase; classtype:trojan-activity; sid:100000254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.245",nocase; classtype:trojan-activity; sid:100000255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.247",nocase; classtype:trojan-activity; sid:100000256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.55",nocase; classtype:trojan-activity; sid:100000257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.60",nocase; classtype:trojan-activity; sid:100000258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.90",nocase; classtype:trojan-activity; sid:100000259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.91",nocase; classtype:trojan-activity; sid:100000260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.30",nocase; classtype:trojan-activity; sid:100000261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.38",nocase; classtype:trojan-activity; sid:100000262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.45",nocase; classtype:trojan-activity; sid:100000263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.60",nocase; classtype:trojan-activity; sid:100000264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.35.237",nocase; classtype:trojan-activity; sid:100000265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.118",nocase; classtype:trojan-activity; sid:100000266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.124",nocase; classtype:trojan-activity; sid:100000267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.53",nocase; classtype:trojan-activity; sid:100000268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.61",nocase; classtype:trojan-activity; sid:100000269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.68",nocase; classtype:trojan-activity; sid:100000270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.73",nocase; classtype:trojan-activity; sid:100000271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.90",nocase; classtype:trojan-activity; sid:100000272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.0.113",nocase; classtype:trojan-activity; sid:100000273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.177.39",nocase; classtype:trojan-activity; sid:100000274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.216.207",nocase; classtype:trojan-activity; sid:100000275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.224.79",nocase; classtype:trojan-activity; sid:100000276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.227.66",nocase; classtype:trojan-activity; sid:100000277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.65.53.175",nocase; classtype:trojan-activity; sid:100000278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.159",nocase; classtype:trojan-activity; sid:100000279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.49",nocase; classtype:trojan-activity; sid:100000280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.175.147",nocase; classtype:trojan-activity; sid:100000281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.112",nocase; classtype:trojan-activity; sid:100000282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.84",nocase; classtype:trojan-activity; sid:100000283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.226.202",nocase; classtype:trojan-activity; sid:100000284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.215.101",nocase; classtype:trojan-activity; sid:100000285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.146.253",nocase; classtype:trojan-activity; sid:100000286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.224.139",nocase; classtype:trojan-activity; sid:100000287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.9.155.122",nocase; classtype:trojan-activity; sid:100000288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.93.29.211",nocase; classtype:trojan-activity; sid:100000289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.11.95.254",nocase; classtype:trojan-activity; sid:100000290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.118.249.97",nocase; classtype:trojan-activity; sid:100000291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.122.238.68",nocase; classtype:trojan-activity; sid:100000292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.13.241.32",nocase; classtype:trojan-activity; sid:100000293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.161.58.249",nocase; classtype:trojan-activity; sid:100000294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.161.78.185",nocase; classtype:trojan-activity; sid:100000295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.194.131.72",nocase; classtype:trojan-activity; sid:100000296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.194.135.223",nocase; classtype:trojan-activity; sid:100000297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.226.42.250",nocase; classtype:trojan-activity; sid:100000298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.230.86.107",nocase; classtype:trojan-activity; sid:100000299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.184.245",nocase; classtype:trojan-activity; sid:100000300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.211.131",nocase; classtype:trojan-activity; sid:100000301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.254.169.251",nocase; classtype:trojan-activity; sid:100000302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.128.133",nocase; classtype:trojan-activity; sid:100000303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.136.39",nocase; classtype:trojan-activity; sid:100000304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.144.42",nocase; classtype:trojan-activity; sid:100000305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.149.125",nocase; classtype:trojan-activity; sid:100000306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.191.47",nocase; classtype:trojan-activity; sid:100000307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.61.204.205",nocase; classtype:trojan-activity; sid:100000308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.65.10.139",nocase; classtype:trojan-activity; sid:100000309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.123.22",nocase; classtype:trojan-activity; sid:100000310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.228.152",nocase; classtype:trojan-activity; sid:100000311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.89.43.165",nocase; classtype:trojan-activity; sid:100000312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.199.253.235",nocase; classtype:trojan-activity; sid:100000313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.201.201.68",nocase; classtype:trojan-activity; sid:100000314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.224.203.128",nocase; classtype:trojan-activity; sid:100000315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.30.54.64",nocase; classtype:trojan-activity; sid:100000316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.79.172.42",nocase; classtype:trojan-activity; sid:100000317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.165.216.112",nocase; classtype:trojan-activity; sid:100000318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.171.204.161",nocase; classtype:trojan-activity; sid:100000319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.42.47.36",nocase; classtype:trojan-activity; sid:100000320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.232.197",nocase; classtype:trojan-activity; sid:100000321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.172.22",nocase; classtype:trojan-activity; sid:100000322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.2.148",nocase; classtype:trojan-activity; sid:100000323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.106.238",nocase; classtype:trojan-activity; sid:100000324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.91.81",nocase; classtype:trojan-activity; sid:100000325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.53.203.161",nocase; classtype:trojan-activity; sid:100000326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.212.175",nocase; classtype:trojan-activity; sid:100000327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.156.203",nocase; classtype:trojan-activity; sid:100000328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.7.9",nocase; classtype:trojan-activity; sid:100000329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.131.242",nocase; classtype:trojan-activity; sid:100000330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.133.96",nocase; classtype:trojan-activity; sid:100000331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.155.202",nocase; classtype:trojan-activity; sid:100000332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.214.205",nocase; classtype:trojan-activity; sid:100000333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.233.160",nocase; classtype:trojan-activity; sid:100000334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.252.120",nocase; classtype:trojan-activity; sid:100000335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.110.120",nocase; classtype:trojan-activity; sid:100000336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.167.21",nocase; classtype:trojan-activity; sid:100000337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.172.140",nocase; classtype:trojan-activity; sid:100000338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.26.113",nocase; classtype:trojan-activity; sid:100000339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.73.3.11",nocase; classtype:trojan-activity; sid:100000340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.75.217.79",nocase; classtype:trojan-activity; sid:100000341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.88.133.148",nocase; classtype:trojan-activity; sid:100000342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.92.174.231",nocase; classtype:trojan-activity; sid:100000343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.108.92.154",nocase; classtype:trojan-activity; sid:100000344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.124.219.2",nocase; classtype:trojan-activity; sid:100000345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.206.164.46",nocase; classtype:trojan-activity; sid:100000346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.211.100.26",nocase; classtype:trojan-activity; sid:100000347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.162.12",nocase; classtype:trojan-activity; sid:100000348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.138",nocase; classtype:trojan-activity; sid:100000349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.5",nocase; classtype:trojan-activity; sid:100000350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.210.52",nocase; classtype:trojan-activity; sid:100000351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.220.126",nocase; classtype:trojan-activity; sid:100000352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.243.40",nocase; classtype:trojan-activity; sid:100000353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.201.205.232",nocase; classtype:trojan-activity; sid:100000354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.64.149",nocase; classtype:trojan-activity; sid:100000355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.12.177",nocase; classtype:trojan-activity; sid:100000356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.47.94",nocase; classtype:trojan-activity; sid:100000357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.9.42",nocase; classtype:trojan-activity; sid:100000358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.215.249.250",nocase; classtype:trojan-activity; sid:100000359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.173.91",nocase; classtype:trojan-activity; sid:100000360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.175.134",nocase; classtype:trojan-activity; sid:100000361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.242.208.197",nocase; classtype:trojan-activity; sid:100000362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.247.201.45",nocase; classtype:trojan-activity; sid:100000363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.26.124.173",nocase; classtype:trojan-activity; sid:100000364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.113.146",nocase; classtype:trojan-activity; sid:100000365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.133.251",nocase; classtype:trojan-activity; sid:100000366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.53.15",nocase; classtype:trojan-activity; sid:100000367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.86.105.110",nocase; classtype:trojan-activity; sid:100000368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.101.7.28",nocase; classtype:trojan-activity; sid:100000369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.104.35",nocase; classtype:trojan-activity; sid:100000370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.157.64",nocase; classtype:trojan-activity; sid:100000371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.7.132",nocase; classtype:trojan-activity; sid:100000372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.32.74",nocase; classtype:trojan-activity; sid:100000373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.5.149",nocase; classtype:trojan-activity; sid:100000374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.72.141",nocase; classtype:trojan-activity; sid:100000375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.12.130",nocase; classtype:trojan-activity; sid:100000376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.128.147",nocase; classtype:trojan-activity; sid:100000377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.208.215",nocase; classtype:trojan-activity; sid:100000378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.209.108",nocase; classtype:trojan-activity; sid:100000379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.214.72",nocase; classtype:trojan-activity; sid:100000380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.88.146",nocase; classtype:trojan-activity; sid:100000381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.150",nocase; classtype:trojan-activity; sid:100000382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.6",nocase; classtype:trojan-activity; sid:100000383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.165.213",nocase; classtype:trojan-activity; sid:100000384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.221.162",nocase; classtype:trojan-activity; sid:100000385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.63.194",nocase; classtype:trojan-activity; sid:100000386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.65.93",nocase; classtype:trojan-activity; sid:100000387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.42.125.246",nocase; classtype:trojan-activity; sid:100000388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.43.180.33",nocase; classtype:trojan-activity; sid:100000389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.113.239",nocase; classtype:trojan-activity; sid:100000390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.218.213",nocase; classtype:trojan-activity; sid:100000391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.50.203",nocase; classtype:trojan-activity; sid:100000392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.179.164",nocase; classtype:trojan-activity; sid:100000393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.183.235",nocase; classtype:trojan-activity; sid:100000394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.239.217",nocase; classtype:trojan-activity; sid:100000395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.14.143.145",nocase; classtype:trojan-activity; sid:100000396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.147.213.57",nocase; classtype:trojan-activity; sid:100000397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.18.235",nocase; classtype:trojan-activity; sid:100000398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.218.229",nocase; classtype:trojan-activity; sid:100000399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.107.93",nocase; classtype:trojan-activity; sid:100000400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.241.222",nocase; classtype:trojan-activity; sid:100000401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.27.77",nocase; classtype:trojan-activity; sid:100000402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.68.145",nocase; classtype:trojan-activity; sid:100000403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.97.6",nocase; classtype:trojan-activity; sid:100000404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.26.33",nocase; classtype:trojan-activity; sid:100000405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.177.147.38",nocase; classtype:trojan-activity; sid:100000406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.248.123",nocase; classtype:trojan-activity; sid:100000407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.43.1",nocase; classtype:trojan-activity; sid:100000408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.58.163",nocase; classtype:trojan-activity; sid:100000409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.18.38.144",nocase; classtype:trojan-activity; sid:100000410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.18.88.78",nocase; classtype:trojan-activity; sid:100000411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.106.217",nocase; classtype:trojan-activity; sid:100000412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.119.21",nocase; classtype:trojan-activity; sid:100000413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.182.97.232",nocase; classtype:trojan-activity; sid:100000414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.172.199",nocase; classtype:trojan-activity; sid:100000415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.15.159",nocase; classtype:trojan-activity; sid:100000416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.195.161",nocase; classtype:trojan-activity; sid:100000417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.245.61",nocase; classtype:trojan-activity; sid:100000418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.137.195",nocase; classtype:trojan-activity; sid:100000419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.227.244",nocase; classtype:trojan-activity; sid:100000420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.187.206",nocase; classtype:trojan-activity; sid:100000421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.215.221",nocase; classtype:trojan-activity; sid:100000422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.240.20",nocase; classtype:trojan-activity; sid:100000423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.255.236",nocase; classtype:trojan-activity; sid:100000424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.204.30.144",nocase; classtype:trojan-activity; sid:100000425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.250.129.231",nocase; classtype:trojan-activity; sid:100000426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.131.155",nocase; classtype:trojan-activity; sid:100000427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.46",nocase; classtype:trojan-activity; sid:100000428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.71",nocase; classtype:trojan-activity; sid:100000429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.148.115",nocase; classtype:trojan-activity; sid:100000430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.155.57",nocase; classtype:trojan-activity; sid:100000431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.206.43",nocase; classtype:trojan-activity; sid:100000432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.96.38.150",nocase; classtype:trojan-activity; sid:100000433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.52.69",nocase; classtype:trojan-activity; sid:100000434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.132.113.2",nocase; classtype:trojan-activity; sid:100000435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.15.69.83",nocase; classtype:trojan-activity; sid:100000436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.6",nocase; classtype:trojan-activity; sid:100000437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.7",nocase; classtype:trojan-activity; sid:100000438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.8",nocase; classtype:trojan-activity; sid:100000439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.9",nocase; classtype:trojan-activity; sid:100000440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.207.39.227",nocase; classtype:trojan-activity; sid:100000441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.25.204.189",nocase; classtype:trojan-activity; sid:100000442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.70.108.141",nocase; classtype:trojan-activity; sid:100000443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.0.255.173",nocase; classtype:trojan-activity; sid:100000444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.1.54.62",nocase; classtype:trojan-activity; sid:100000445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.142.222.22",nocase; classtype:trojan-activity; sid:100000446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.150.213.110",nocase; classtype:trojan-activity; sid:100000447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.151.248.134",nocase; classtype:trojan-activity; sid:100000448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.180",nocase; classtype:trojan-activity; sid:100000449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.183",nocase; classtype:trojan-activity; sid:100000450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.185",nocase; classtype:trojan-activity; sid:100000451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.191",nocase; classtype:trojan-activity; sid:100000452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.193",nocase; classtype:trojan-activity; sid:100000453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.201",nocase; classtype:trojan-activity; sid:100000454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.202",nocase; classtype:trojan-activity; sid:100000455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.204",nocase; classtype:trojan-activity; sid:100000456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.215",nocase; classtype:trojan-activity; sid:100000457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.233",nocase; classtype:trojan-activity; sid:100000458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.206",nocase; classtype:trojan-activity; sid:100000459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.235",nocase; classtype:trojan-activity; sid:100000460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.239",nocase; classtype:trojan-activity; sid:100000461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.250",nocase; classtype:trojan-activity; sid:100000462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.60",nocase; classtype:trojan-activity; sid:100000463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.74",nocase; classtype:trojan-activity; sid:100000464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.99.127",nocase; classtype:trojan-activity; sid:100000465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.66.60",nocase; classtype:trojan-activity; sid:100000466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.93.115",nocase; classtype:trojan-activity; sid:100000467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.8.11",nocase; classtype:trojan-activity; sid:100000468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.7.75.99",nocase; classtype:trojan-activity; sid:100000469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.83.79.42",nocase; classtype:trojan-activity; sid:100000470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.114.164",nocase; classtype:trojan-activity; sid:100000471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.96.8",nocase; classtype:trojan-activity; sid:100000472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.121.44.222",nocase; classtype:trojan-activity; sid:100000473; rev:1;) @@ -494,26 +494,26 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.254.76.17",nocase; classtype:trojan-activity; sid:100000488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.96.158",nocase; classtype:trojan-activity; sid:100000489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.97.64",nocase; classtype:trojan-activity; sid:100000490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.88.99.236",nocase; classtype:trojan-activity; sid:100000491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.100.150.204",nocase; classtype:trojan-activity; sid:100000492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.137.53.134",nocase; classtype:trojan-activity; sid:100000493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.160.147.53",nocase; classtype:trojan-activity; sid:100000494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.66.28",nocase; classtype:trojan-activity; sid:100000495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.72.23",nocase; classtype:trojan-activity; sid:100000496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.79.27",nocase; classtype:trojan-activity; sid:100000497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.37.85",nocase; classtype:trojan-activity; sid:100000498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.232.227.128",nocase; classtype:trojan-activity; sid:100000499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.33.214",nocase; classtype:trojan-activity; sid:100000500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.0.240.58",nocase; classtype:trojan-activity; sid:100000501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.137.193",nocase; classtype:trojan-activity; sid:100000502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.202.178",nocase; classtype:trojan-activity; sid:100000503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.244",nocase; classtype:trojan-activity; sid:100000504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.170.237",nocase; classtype:trojan-activity; sid:100000505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.182.187",nocase; classtype:trojan-activity; sid:100000506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.19.248",nocase; classtype:trojan-activity; sid:100000507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.200.98",nocase; classtype:trojan-activity; sid:100000508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.238.188",nocase; classtype:trojan-activity; sid:100000509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.12.164.165",nocase; classtype:trojan-activity; sid:100000510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.8.107.214",nocase; classtype:trojan-activity; sid:100000491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.88.99.236",nocase; classtype:trojan-activity; sid:100000492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.100.150.204",nocase; classtype:trojan-activity; sid:100000493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.137.53.134",nocase; classtype:trojan-activity; sid:100000494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.160.147.53",nocase; classtype:trojan-activity; sid:100000495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.66.28",nocase; classtype:trojan-activity; sid:100000496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.72.23",nocase; classtype:trojan-activity; sid:100000497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.79.27",nocase; classtype:trojan-activity; sid:100000498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.37.85",nocase; classtype:trojan-activity; sid:100000499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.232.227.128",nocase; classtype:trojan-activity; sid:100000500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.33.214",nocase; classtype:trojan-activity; sid:100000501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.0.240.58",nocase; classtype:trojan-activity; sid:100000502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.32.252",nocase; classtype:trojan-activity; sid:100000503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.202.178",nocase; classtype:trojan-activity; sid:100000504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.244",nocase; classtype:trojan-activity; sid:100000505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.170.237",nocase; classtype:trojan-activity; sid:100000506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.182.187",nocase; classtype:trojan-activity; sid:100000507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.19.248",nocase; classtype:trojan-activity; sid:100000508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.200.98",nocase; classtype:trojan-activity; sid:100000509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.238.188",nocase; classtype:trojan-activity; sid:100000510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.129.2.28",nocase; classtype:trojan-activity; sid:100000511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.129.84.36",nocase; classtype:trojan-activity; sid:100000512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.208.52",nocase; classtype:trojan-activity; sid:100000513; rev:1;) @@ -527,192 +527,192 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.14.130",nocase; classtype:trojan-activity; sid:100000521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.20.164",nocase; classtype:trojan-activity; sid:100000522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.246.180",nocase; classtype:trojan-activity; sid:100000523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.236.114",nocase; classtype:trojan-activity; sid:100000524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.8.100",nocase; classtype:trojan-activity; sid:100000525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.183.16.71",nocase; classtype:trojan-activity; sid:100000526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.191.164.92",nocase; classtype:trojan-activity; sid:100000527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.101.163",nocase; classtype:trojan-activity; sid:100000528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.53.237",nocase; classtype:trojan-activity; sid:100000529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.235.37",nocase; classtype:trojan-activity; sid:100000530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.35.146",nocase; classtype:trojan-activity; sid:100000531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.52.79",nocase; classtype:trojan-activity; sid:100000532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.60.238",nocase; classtype:trojan-activity; sid:100000533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.112.240",nocase; classtype:trojan-activity; sid:100000534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.184.191",nocase; classtype:trojan-activity; sid:100000535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.212.29.154",nocase; classtype:trojan-activity; sid:100000536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.213.225.130",nocase; classtype:trojan-activity; sid:100000537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.130.162",nocase; classtype:trojan-activity; sid:100000538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.152.249",nocase; classtype:trojan-activity; sid:100000539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.116.110",nocase; classtype:trojan-activity; sid:100000540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.184.57",nocase; classtype:trojan-activity; sid:100000541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.103.89",nocase; classtype:trojan-activity; sid:100000542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.181.57",nocase; classtype:trojan-activity; sid:100000543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.79.61",nocase; classtype:trojan-activity; sid:100000544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.11.41",nocase; classtype:trojan-activity; sid:100000545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.148.58",nocase; classtype:trojan-activity; sid:100000546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.184.124",nocase; classtype:trojan-activity; sid:100000547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.28.217.23",nocase; classtype:trojan-activity; sid:100000548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.204.223",nocase; classtype:trojan-activity; sid:100000549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.251.81",nocase; classtype:trojan-activity; sid:100000550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.250.132",nocase; classtype:trojan-activity; sid:100000551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.9.193.253",nocase; classtype:trojan-activity; sid:100000552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.9.85.25",nocase; classtype:trojan-activity; sid:100000553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.221.150",nocase; classtype:trojan-activity; sid:100000554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.76.230",nocase; classtype:trojan-activity; sid:100000555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.130.40.31",nocase; classtype:trojan-activity; sid:100000556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.104.82",nocase; classtype:trojan-activity; sid:100000557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.131.105",nocase; classtype:trojan-activity; sid:100000558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.151.135",nocase; classtype:trojan-activity; sid:100000559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.24.185",nocase; classtype:trojan-activity; sid:100000560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.26.243",nocase; classtype:trojan-activity; sid:100000561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.42.98",nocase; classtype:trojan-activity; sid:100000562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.54.33",nocase; classtype:trojan-activity; sid:100000563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.132.110.150",nocase; classtype:trojan-activity; sid:100000564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.135.34.49",nocase; classtype:trojan-activity; sid:100000565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.136.175",nocase; classtype:trojan-activity; sid:100000566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.236.6",nocase; classtype:trojan-activity; sid:100000567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.160.126.238",nocase; classtype:trojan-activity; sid:100000568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.65.64",nocase; classtype:trojan-activity; sid:100000569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.165.123.7",nocase; classtype:trojan-activity; sid:100000570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.187.111.160",nocase; classtype:trojan-activity; sid:100000571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.199.56.198",nocase; classtype:trojan-activity; sid:100000572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.230.174.233",nocase; classtype:trojan-activity; sid:100000573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.254.210.69",nocase; classtype:trojan-activity; sid:100000574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.5.112.43",nocase; classtype:trojan-activity; sid:100000575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.5.92.20",nocase; classtype:trojan-activity; sid:100000576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.6.0.4",nocase; classtype:trojan-activity; sid:100000577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.67.89.28",nocase; classtype:trojan-activity; sid:100000578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.80.46.73",nocase; classtype:trojan-activity; sid:100000579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.93.94.207",nocase; classtype:trojan-activity; sid:100000580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.95.10.235",nocase; classtype:trojan-activity; sid:100000581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.128.28.161",nocase; classtype:trojan-activity; sid:100000582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.142.93.34",nocase; classtype:trojan-activity; sid:100000583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.191.113.212",nocase; classtype:trojan-activity; sid:100000584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.36.222.249",nocase; classtype:trojan-activity; sid:100000585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.1.235",nocase; classtype:trojan-activity; sid:100000586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.146.46",nocase; classtype:trojan-activity; sid:100000587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.3.71",nocase; classtype:trojan-activity; sid:100000588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.82.59",nocase; classtype:trojan-activity; sid:100000589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.8.154",nocase; classtype:trojan-activity; sid:100000590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.186.88",nocase; classtype:trojan-activity; sid:100000591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.66.253",nocase; classtype:trojan-activity; sid:100000592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.244.8",nocase; classtype:trojan-activity; sid:100000593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.74.230",nocase; classtype:trojan-activity; sid:100000594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.93.160",nocase; classtype:trojan-activity; sid:100000595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.95.26",nocase; classtype:trojan-activity; sid:100000524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.236.114",nocase; classtype:trojan-activity; sid:100000525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.8.100",nocase; classtype:trojan-activity; sid:100000526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.183.16.71",nocase; classtype:trojan-activity; sid:100000527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.191.164.92",nocase; classtype:trojan-activity; sid:100000528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.101.163",nocase; classtype:trojan-activity; sid:100000529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.53.237",nocase; classtype:trojan-activity; sid:100000530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.235.37",nocase; classtype:trojan-activity; sid:100000531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.35.146",nocase; classtype:trojan-activity; sid:100000532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.52.79",nocase; classtype:trojan-activity; sid:100000533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.60.238",nocase; classtype:trojan-activity; sid:100000534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.112.240",nocase; classtype:trojan-activity; sid:100000535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.184.191",nocase; classtype:trojan-activity; sid:100000536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.212.29.154",nocase; classtype:trojan-activity; sid:100000537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.213.225.130",nocase; classtype:trojan-activity; sid:100000538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.130.162",nocase; classtype:trojan-activity; sid:100000539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.152.249",nocase; classtype:trojan-activity; sid:100000540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.116.110",nocase; classtype:trojan-activity; sid:100000541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.184.57",nocase; classtype:trojan-activity; sid:100000542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.103.89",nocase; classtype:trojan-activity; sid:100000543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.181.57",nocase; classtype:trojan-activity; sid:100000544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.79.61",nocase; classtype:trojan-activity; sid:100000545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.11.41",nocase; classtype:trojan-activity; sid:100000546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.148.58",nocase; classtype:trojan-activity; sid:100000547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.184.124",nocase; classtype:trojan-activity; sid:100000548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.28.217.23",nocase; classtype:trojan-activity; sid:100000549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.242.19",nocase; classtype:trojan-activity; sid:100000550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.47.57",nocase; classtype:trojan-activity; sid:100000551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.148.182",nocase; classtype:trojan-activity; sid:100000552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.189.15",nocase; classtype:trojan-activity; sid:100000553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.9.36.120",nocase; classtype:trojan-activity; sid:100000554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.221.150",nocase; classtype:trojan-activity; sid:100000555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.76.230",nocase; classtype:trojan-activity; sid:100000556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.130.40.31",nocase; classtype:trojan-activity; sid:100000557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.104.82",nocase; classtype:trojan-activity; sid:100000558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.131.105",nocase; classtype:trojan-activity; sid:100000559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.151.135",nocase; classtype:trojan-activity; sid:100000560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.24.185",nocase; classtype:trojan-activity; sid:100000561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.26.243",nocase; classtype:trojan-activity; sid:100000562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.42.98",nocase; classtype:trojan-activity; sid:100000563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.54.33",nocase; classtype:trojan-activity; sid:100000564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.132.110.150",nocase; classtype:trojan-activity; sid:100000565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.135.34.49",nocase; classtype:trojan-activity; sid:100000566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.136.175",nocase; classtype:trojan-activity; sid:100000567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.236.6",nocase; classtype:trojan-activity; sid:100000568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.160.126.238",nocase; classtype:trojan-activity; sid:100000569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.65.64",nocase; classtype:trojan-activity; sid:100000570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.165.123.7",nocase; classtype:trojan-activity; sid:100000571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.187.111.160",nocase; classtype:trojan-activity; sid:100000572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.199.56.198",nocase; classtype:trojan-activity; sid:100000573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.230.174.233",nocase; classtype:trojan-activity; sid:100000574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.254.210.69",nocase; classtype:trojan-activity; sid:100000575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.5.112.43",nocase; classtype:trojan-activity; sid:100000576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.5.92.20",nocase; classtype:trojan-activity; sid:100000577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.6.0.4",nocase; classtype:trojan-activity; sid:100000578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.67.89.28",nocase; classtype:trojan-activity; sid:100000579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.80.46.73",nocase; classtype:trojan-activity; sid:100000580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.93.94.207",nocase; classtype:trojan-activity; sid:100000581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.95.10.235",nocase; classtype:trojan-activity; sid:100000582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.128.28.161",nocase; classtype:trojan-activity; sid:100000583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.142.93.34",nocase; classtype:trojan-activity; sid:100000584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.191.113.212",nocase; classtype:trojan-activity; sid:100000585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.36.222.249",nocase; classtype:trojan-activity; sid:100000586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.1.235",nocase; classtype:trojan-activity; sid:100000587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.146.46",nocase; classtype:trojan-activity; sid:100000588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.3.71",nocase; classtype:trojan-activity; sid:100000589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.14.228",nocase; classtype:trojan-activity; sid:100000590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.82.59",nocase; classtype:trojan-activity; sid:100000591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.186.88",nocase; classtype:trojan-activity; sid:100000592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.66.253",nocase; classtype:trojan-activity; sid:100000593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.244.126",nocase; classtype:trojan-activity; sid:100000594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.74.230",nocase; classtype:trojan-activity; sid:100000595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"126.39.155.210",nocase; classtype:trojan-activity; sid:100000596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"128.116.133.92",nocase; classtype:trojan-activity; sid:100000597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"13.114.247.134",nocase; classtype:trojan-activity; sid:100000598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"130.255.159.133",nocase; classtype:trojan-activity; sid:100000599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"134.119.186.214",nocase; classtype:trojan-activity; sid:100000600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"135.148.36.127",nocase; classtype:trojan-activity; sid:100000601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"138.99.204.224",nocase; classtype:trojan-activity; sid:100000602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.159.226.180",nocase; classtype:trojan-activity; sid:100000603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.173.198",nocase; classtype:trojan-activity; sid:100000604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.216.102.151",nocase; classtype:trojan-activity; sid:100000605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.102.17.222",nocase; classtype:trojan-activity; sid:100000606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.136.80.242",nocase; classtype:trojan-activity; sid:100000607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.215",nocase; classtype:trojan-activity; sid:100000608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.51",nocase; classtype:trojan-activity; sid:100000609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.155.86.253",nocase; classtype:trojan-activity; sid:100000610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.160.34.50",nocase; classtype:trojan-activity; sid:100000611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.232.33.212",nocase; classtype:trojan-activity; sid:100000612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.37.222.190",nocase; classtype:trojan-activity; sid:100000613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.42.237.237",nocase; classtype:trojan-activity; sid:100000614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.45.127.110",nocase; classtype:trojan-activity; sid:100000615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.25.17",nocase; classtype:trojan-activity; sid:100000616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.50.129.248",nocase; classtype:trojan-activity; sid:100000617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.55.29.2",nocase; classtype:trojan-activity; sid:100000618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"140.237.12.32",nocase; classtype:trojan-activity; sid:100000619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.11.216.5",nocase; classtype:trojan-activity; sid:100000620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.177.56.127",nocase; classtype:trojan-activity; sid:100000621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"148.69.108.177",nocase; classtype:trojan-activity; sid:100000622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.134",nocase; classtype:trojan-activity; sid:100000623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.99",nocase; classtype:trojan-activity; sid:100000624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.124.194",nocase; classtype:trojan-activity; sid:100000625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14karatvisions.com",nocase; classtype:trojan-activity; sid:100000626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"150.116.207.99",nocase; classtype:trojan-activity; sid:100000627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.177.163.87",nocase; classtype:trojan-activity; sid:100000628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.33.230.191",nocase; classtype:trojan-activity; sid:100000629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.234.167",nocase; classtype:trojan-activity; sid:100000630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.152.106",nocase; classtype:trojan-activity; sid:100000631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.135.92",nocase; classtype:trojan-activity; sid:100000632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.159.207",nocase; classtype:trojan-activity; sid:100000633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"156.234.211.198",nocase; classtype:trojan-activity; sid:100000634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.101.165.14",nocase; classtype:trojan-activity; sid:100000635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.174.213.128",nocase; classtype:trojan-activity; sid:100000636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.51.125.115",nocase; classtype:trojan-activity; sid:100000637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"159.224.74.112",nocase; classtype:trojan-activity; sid:100000638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"159.65.199.92",nocase; classtype:trojan-activity; sid:100000639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.191.165.238",nocase; classtype:trojan-activity; sid:100000640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.194.28.60",nocase; classtype:trojan-activity; sid:100000641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.209.98.174",nocase; classtype:trojan-activity; sid:100000642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.200.234",nocase; classtype:trojan-activity; sid:100000643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.206.193",nocase; classtype:trojan-activity; sid:100000644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.53.206.228",nocase; classtype:trojan-activity; sid:100000645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"167.114.172.177",nocase; classtype:trojan-activity; sid:100000646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"170.81.238.178",nocase; classtype:trojan-activity; sid:100000647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.121.255.12",nocase; classtype:trojan-activity; sid:100000648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.247.155.56",nocase; classtype:trojan-activity; sid:100000649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.250.131.25",nocase; classtype:trojan-activity; sid:100000650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.162.156",nocase; classtype:trojan-activity; sid:100000651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.150.133",nocase; classtype:trojan-activity; sid:100000652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.105.36.168",nocase; classtype:trojan-activity; sid:100000653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.114.244.127",nocase; classtype:trojan-activity; sid:100000654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.186.107",nocase; classtype:trojan-activity; sid:100000655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.185",nocase; classtype:trojan-activity; sid:100000656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.190",nocase; classtype:trojan-activity; sid:100000657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.81.19",nocase; classtype:trojan-activity; sid:100000658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.93.194.114",nocase; classtype:trojan-activity; sid:100000659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.167.85.89",nocase; classtype:trojan-activity; sid:100000660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.169.46.85",nocase; classtype:trojan-activity; sid:100000661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.19.58.108",nocase; classtype:trojan-activity; sid:100000662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.233.85.171",nocase; classtype:trojan-activity; sid:100000663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.235.209.70",nocase; classtype:trojan-activity; sid:100000664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.25.113.8",nocase; classtype:trojan-activity; sid:100000665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.95.134",nocase; classtype:trojan-activity; sid:100000666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.97.25",nocase; classtype:trojan-activity; sid:100000667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.119.108",nocase; classtype:trojan-activity; sid:100000668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.92.166",nocase; classtype:trojan-activity; sid:100000669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.63.64.213",nocase; classtype:trojan-activity; sid:100000670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.68.100.93",nocase; classtype:trojan-activity; sid:100000671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.61.3.149",nocase; classtype:trojan-activity; sid:100000672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.73.246.193",nocase; classtype:trojan-activity; sid:100000673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.81.78.7",nocase; classtype:trojan-activity; sid:100000674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.83.73.163",nocase; classtype:trojan-activity; sid:100000675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.11.65.112",nocase; classtype:trojan-activity; sid:100000676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.117.66.74",nocase; classtype:trojan-activity; sid:100000677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.169.13.182",nocase; classtype:trojan-activity; sid:100000678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.194.116.27",nocase; classtype:trojan-activity; sid:100000679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.201.104.192",nocase; classtype:trojan-activity; sid:100000680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.208.230.8",nocase; classtype:trojan-activity; sid:100000681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.213.25.192",nocase; classtype:trojan-activity; sid:100000682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.42.46.118",nocase; classtype:trojan-activity; sid:100000683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"130.255.159.133",nocase; classtype:trojan-activity; sid:100000598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"135.148.36.127",nocase; classtype:trojan-activity; sid:100000599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"138.99.204.224",nocase; classtype:trojan-activity; sid:100000600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.159.226.180",nocase; classtype:trojan-activity; sid:100000601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.173.198",nocase; classtype:trojan-activity; sid:100000602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.216.102.151",nocase; classtype:trojan-activity; sid:100000603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.136.80.242",nocase; classtype:trojan-activity; sid:100000604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.215",nocase; classtype:trojan-activity; sid:100000605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.51",nocase; classtype:trojan-activity; sid:100000606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.155.86.253",nocase; classtype:trojan-activity; sid:100000607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.160.34.50",nocase; classtype:trojan-activity; sid:100000608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.232.33.212",nocase; classtype:trojan-activity; sid:100000609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.37.222.190",nocase; classtype:trojan-activity; sid:100000610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.42.237.237",nocase; classtype:trojan-activity; sid:100000611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.45.127.110",nocase; classtype:trojan-activity; sid:100000612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.25.17",nocase; classtype:trojan-activity; sid:100000613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.50.129.248",nocase; classtype:trojan-activity; sid:100000614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.55.29.2",nocase; classtype:trojan-activity; sid:100000615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"140.237.12.32",nocase; classtype:trojan-activity; sid:100000616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"141.105.65.94",nocase; classtype:trojan-activity; sid:100000617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.11.216.5",nocase; classtype:trojan-activity; sid:100000618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.177.56.127",nocase; classtype:trojan-activity; sid:100000619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"143.198.120.58",nocase; classtype:trojan-activity; sid:100000620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"148.69.108.177",nocase; classtype:trojan-activity; sid:100000621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.134",nocase; classtype:trojan-activity; sid:100000622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.170",nocase; classtype:trojan-activity; sid:100000623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.29",nocase; classtype:trojan-activity; sid:100000624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.44",nocase; classtype:trojan-activity; sid:100000625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.99",nocase; classtype:trojan-activity; sid:100000626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.124.194",nocase; classtype:trojan-activity; sid:100000627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14karatvisions.com",nocase; classtype:trojan-activity; sid:100000628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"150.116.207.99",nocase; classtype:trojan-activity; sid:100000629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.177.163.87",nocase; classtype:trojan-activity; sid:100000630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.33.230.191",nocase; classtype:trojan-activity; sid:100000631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.234.167",nocase; classtype:trojan-activity; sid:100000632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.152.106",nocase; classtype:trojan-activity; sid:100000633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.135.92",nocase; classtype:trojan-activity; sid:100000634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.159.207",nocase; classtype:trojan-activity; sid:100000635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"156.234.211.198",nocase; classtype:trojan-activity; sid:100000636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.101.165.14",nocase; classtype:trojan-activity; sid:100000637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.174.213.128",nocase; classtype:trojan-activity; sid:100000638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.51.125.115",nocase; classtype:trojan-activity; sid:100000639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"159.224.74.112",nocase; classtype:trojan-activity; sid:100000640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"159.65.199.92",nocase; classtype:trojan-activity; sid:100000641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.191.165.238",nocase; classtype:trojan-activity; sid:100000642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.194.28.60",nocase; classtype:trojan-activity; sid:100000643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.209.98.174",nocase; classtype:trojan-activity; sid:100000644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.245.221.121",nocase; classtype:trojan-activity; sid:100000645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.206.193",nocase; classtype:trojan-activity; sid:100000646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"167.114.172.177",nocase; classtype:trojan-activity; sid:100000647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"170.81.238.178",nocase; classtype:trojan-activity; sid:100000648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.121.255.12",nocase; classtype:trojan-activity; sid:100000649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.247.155.56",nocase; classtype:trojan-activity; sid:100000650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.250.131.25",nocase; classtype:trojan-activity; sid:100000651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.162.156",nocase; classtype:trojan-activity; sid:100000652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.150.133",nocase; classtype:trojan-activity; sid:100000653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.105.36.168",nocase; classtype:trojan-activity; sid:100000654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.114.244.127",nocase; classtype:trojan-activity; sid:100000655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.186.107",nocase; classtype:trojan-activity; sid:100000656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.185",nocase; classtype:trojan-activity; sid:100000657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.190",nocase; classtype:trojan-activity; sid:100000658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.81.19",nocase; classtype:trojan-activity; sid:100000659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.93.194.114",nocase; classtype:trojan-activity; sid:100000660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.167.85.89",nocase; classtype:trojan-activity; sid:100000661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.169.46.85",nocase; classtype:trojan-activity; sid:100000662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.19.58.108",nocase; classtype:trojan-activity; sid:100000663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.233.85.171",nocase; classtype:trojan-activity; sid:100000664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.235.209.70",nocase; classtype:trojan-activity; sid:100000665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.25.113.8",nocase; classtype:trojan-activity; sid:100000666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.95.134",nocase; classtype:trojan-activity; sid:100000667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.97.25",nocase; classtype:trojan-activity; sid:100000668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.119.108",nocase; classtype:trojan-activity; sid:100000669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.92.166",nocase; classtype:trojan-activity; sid:100000670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.63.64.213",nocase; classtype:trojan-activity; sid:100000671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.68.100.93",nocase; classtype:trojan-activity; sid:100000672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.61.3.149",nocase; classtype:trojan-activity; sid:100000673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.73.246.193",nocase; classtype:trojan-activity; sid:100000674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.81.78.7",nocase; classtype:trojan-activity; sid:100000675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.83.73.163",nocase; classtype:trojan-activity; sid:100000676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.11.65.112",nocase; classtype:trojan-activity; sid:100000677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.117.66.74",nocase; classtype:trojan-activity; sid:100000678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.169.13.182",nocase; classtype:trojan-activity; sid:100000679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.194.116.27",nocase; classtype:trojan-activity; sid:100000680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.201.104.192",nocase; classtype:trojan-activity; sid:100000681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.208.230.8",nocase; classtype:trojan-activity; sid:100000682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.213.25.192",nocase; classtype:trojan-activity; sid:100000683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.35",nocase; classtype:trojan-activity; sid:100000684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.66",nocase; classtype:trojan-activity; sid:100000685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.67",nocase; classtype:trojan-activity; sid:100000686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.104",nocase; classtype:trojan-activity; sid:100000687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.121",nocase; classtype:trojan-activity; sid:100000688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.59",nocase; classtype:trojan-activity; sid:100000689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.66",nocase; classtype:trojan-activity; sid:100000690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.71",nocase; classtype:trojan-activity; sid:100000691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.76",nocase; classtype:trojan-activity; sid:100000692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.84",nocase; classtype:trojan-activity; sid:100000693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.95",nocase; classtype:trojan-activity; sid:100000694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.12.117.70",nocase; classtype:trojan-activity; sid:100000695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.115",nocase; classtype:trojan-activity; sid:100000696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.127",nocase; classtype:trojan-activity; sid:100000697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.124.7.225",nocase; classtype:trojan-activity; sid:100000698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.221.188.251",nocase; classtype:trojan-activity; sid:100000699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.240.84.106",nocase; classtype:trojan-activity; sid:100000700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.11.92.78",nocase; classtype:trojan-activity; sid:100000701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.131.226.235",nocase; classtype:trojan-activity; sid:100000702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.54.82.154",nocase; classtype:trojan-activity; sid:100000703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.124.182.187",nocase; classtype:trojan-activity; sid:100000704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.134.185.112",nocase; classtype:trojan-activity; sid:100000705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.150.174.65",nocase; classtype:trojan-activity; sid:100000706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.151.143.2",nocase; classtype:trojan-activity; sid:100000707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.165.122.141",nocase; classtype:trojan-activity; sid:100000708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.17.171.144",nocase; classtype:trojan-activity; sid:100000709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.65",nocase; classtype:trojan-activity; sid:100000690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.66",nocase; classtype:trojan-activity; sid:100000691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.71",nocase; classtype:trojan-activity; sid:100000692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.76",nocase; classtype:trojan-activity; sid:100000693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.84",nocase; classtype:trojan-activity; sid:100000694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.91",nocase; classtype:trojan-activity; sid:100000695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.95",nocase; classtype:trojan-activity; sid:100000696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.12.117.70",nocase; classtype:trojan-activity; sid:100000697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.115",nocase; classtype:trojan-activity; sid:100000698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.127",nocase; classtype:trojan-activity; sid:100000699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.124.7.225",nocase; classtype:trojan-activity; sid:100000700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.221.188.251",nocase; classtype:trojan-activity; sid:100000701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.240.84.106",nocase; classtype:trojan-activity; sid:100000702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.131.226.235",nocase; classtype:trojan-activity; sid:100000703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.54.82.154",nocase; classtype:trojan-activity; sid:100000704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.124.182.187",nocase; classtype:trojan-activity; sid:100000705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.134.185.112",nocase; classtype:trojan-activity; sid:100000706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.150.174.65",nocase; classtype:trojan-activity; sid:100000707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.151.143.2",nocase; classtype:trojan-activity; sid:100000708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.165.122.141",nocase; classtype:trojan-activity; sid:100000709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.0.145",nocase; classtype:trojan-activity; sid:100000710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.0.24",nocase; classtype:trojan-activity; sid:100000711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.179",nocase; classtype:trojan-activity; sid:100000712; rev:1;) @@ -721,359 +721,359 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.124",nocase; classtype:trojan-activity; sid:100000715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.182",nocase; classtype:trojan-activity; sid:100000716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.221",nocase; classtype:trojan-activity; sid:100000717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.96",nocase; classtype:trojan-activity; sid:100000718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.151",nocase; classtype:trojan-activity; sid:100000719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.252",nocase; classtype:trojan-activity; sid:100000720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.207",nocase; classtype:trojan-activity; sid:100000721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.217",nocase; classtype:trojan-activity; sid:100000722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.25",nocase; classtype:trojan-activity; sid:100000723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.52",nocase; classtype:trojan-activity; sid:100000724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.58",nocase; classtype:trojan-activity; sid:100000725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.112",nocase; classtype:trojan-activity; sid:100000726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.67",nocase; classtype:trojan-activity; sid:100000727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.89",nocase; classtype:trojan-activity; sid:100000728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.160",nocase; classtype:trojan-activity; sid:100000729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.179",nocase; classtype:trojan-activity; sid:100000730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.199",nocase; classtype:trojan-activity; sid:100000731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.142",nocase; classtype:trojan-activity; sid:100000732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.156",nocase; classtype:trojan-activity; sid:100000733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.224",nocase; classtype:trojan-activity; sid:100000734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.127",nocase; classtype:trojan-activity; sid:100000735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.173",nocase; classtype:trojan-activity; sid:100000736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.87",nocase; classtype:trojan-activity; sid:100000737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.165",nocase; classtype:trojan-activity; sid:100000738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.181",nocase; classtype:trojan-activity; sid:100000739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.101",nocase; classtype:trojan-activity; sid:100000740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.139",nocase; classtype:trojan-activity; sid:100000741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.6",nocase; classtype:trojan-activity; sid:100000742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.191",nocase; classtype:trojan-activity; sid:100000743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.195",nocase; classtype:trojan-activity; sid:100000744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.190",nocase; classtype:trojan-activity; sid:100000745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.111",nocase; classtype:trojan-activity; sid:100000746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.183",nocase; classtype:trojan-activity; sid:100000747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.254",nocase; classtype:trojan-activity; sid:100000748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.247",nocase; classtype:trojan-activity; sid:100000718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.96",nocase; classtype:trojan-activity; sid:100000719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.104",nocase; classtype:trojan-activity; sid:100000720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.151",nocase; classtype:trojan-activity; sid:100000721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.212",nocase; classtype:trojan-activity; sid:100000722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.252",nocase; classtype:trojan-activity; sid:100000723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.207",nocase; classtype:trojan-activity; sid:100000724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.217",nocase; classtype:trojan-activity; sid:100000725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.25",nocase; classtype:trojan-activity; sid:100000726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.14",nocase; classtype:trojan-activity; sid:100000727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.58",nocase; classtype:trojan-activity; sid:100000728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.112",nocase; classtype:trojan-activity; sid:100000729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.115",nocase; classtype:trojan-activity; sid:100000730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.67",nocase; classtype:trojan-activity; sid:100000731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.160",nocase; classtype:trojan-activity; sid:100000732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.179",nocase; classtype:trojan-activity; sid:100000733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.135",nocase; classtype:trojan-activity; sid:100000734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.142",nocase; classtype:trojan-activity; sid:100000735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.224",nocase; classtype:trojan-activity; sid:100000736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.127",nocase; classtype:trojan-activity; sid:100000737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.173",nocase; classtype:trojan-activity; sid:100000738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.165",nocase; classtype:trojan-activity; sid:100000739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.181",nocase; classtype:trojan-activity; sid:100000740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.100",nocase; classtype:trojan-activity; sid:100000741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.101",nocase; classtype:trojan-activity; sid:100000742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.139",nocase; classtype:trojan-activity; sid:100000743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.6",nocase; classtype:trojan-activity; sid:100000744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.191",nocase; classtype:trojan-activity; sid:100000745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.195",nocase; classtype:trojan-activity; sid:100000746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.111",nocase; classtype:trojan-activity; sid:100000747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.183",nocase; classtype:trojan-activity; sid:100000748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.85",nocase; classtype:trojan-activity; sid:100000749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.174",nocase; classtype:trojan-activity; sid:100000750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.151",nocase; classtype:trojan-activity; sid:100000751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.51",nocase; classtype:trojan-activity; sid:100000752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.106",nocase; classtype:trojan-activity; sid:100000753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.208",nocase; classtype:trojan-activity; sid:100000754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.254",nocase; classtype:trojan-activity; sid:100000755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.56",nocase; classtype:trojan-activity; sid:100000756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.110",nocase; classtype:trojan-activity; sid:100000757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.112",nocase; classtype:trojan-activity; sid:100000758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.129",nocase; classtype:trojan-activity; sid:100000759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.174",nocase; classtype:trojan-activity; sid:100000760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.41",nocase; classtype:trojan-activity; sid:100000761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.161",nocase; classtype:trojan-activity; sid:100000762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.43",nocase; classtype:trojan-activity; sid:100000763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.222",nocase; classtype:trojan-activity; sid:100000764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.68",nocase; classtype:trojan-activity; sid:100000765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.12",nocase; classtype:trojan-activity; sid:100000766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.87",nocase; classtype:trojan-activity; sid:100000750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.174",nocase; classtype:trojan-activity; sid:100000751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.117",nocase; classtype:trojan-activity; sid:100000752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.151",nocase; classtype:trojan-activity; sid:100000753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.51",nocase; classtype:trojan-activity; sid:100000754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.106",nocase; classtype:trojan-activity; sid:100000755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.208",nocase; classtype:trojan-activity; sid:100000756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.254",nocase; classtype:trojan-activity; sid:100000757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.174",nocase; classtype:trojan-activity; sid:100000758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.41",nocase; classtype:trojan-activity; sid:100000759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.161",nocase; classtype:trojan-activity; sid:100000760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.43",nocase; classtype:trojan-activity; sid:100000761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.68",nocase; classtype:trojan-activity; sid:100000762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.91",nocase; classtype:trojan-activity; sid:100000763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.12",nocase; classtype:trojan-activity; sid:100000764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.125",nocase; classtype:trojan-activity; sid:100000765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.130",nocase; classtype:trojan-activity; sid:100000766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.151",nocase; classtype:trojan-activity; sid:100000767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.169",nocase; classtype:trojan-activity; sid:100000768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.172",nocase; classtype:trojan-activity; sid:100000769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.28",nocase; classtype:trojan-activity; sid:100000770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.47",nocase; classtype:trojan-activity; sid:100000771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.202",nocase; classtype:trojan-activity; sid:100000772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.53",nocase; classtype:trojan-activity; sid:100000773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.38",nocase; classtype:trojan-activity; sid:100000774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.149",nocase; classtype:trojan-activity; sid:100000775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.218",nocase; classtype:trojan-activity; sid:100000776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.52",nocase; classtype:trojan-activity; sid:100000777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.243",nocase; classtype:trojan-activity; sid:100000769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.77",nocase; classtype:trojan-activity; sid:100000770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.172",nocase; classtype:trojan-activity; sid:100000771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.197",nocase; classtype:trojan-activity; sid:100000772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.47",nocase; classtype:trojan-activity; sid:100000773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.53",nocase; classtype:trojan-activity; sid:100000774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.113",nocase; classtype:trojan-activity; sid:100000775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.38",nocase; classtype:trojan-activity; sid:100000776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.218",nocase; classtype:trojan-activity; sid:100000777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.129",nocase; classtype:trojan-activity; sid:100000778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.18",nocase; classtype:trojan-activity; sid:100000779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.234",nocase; classtype:trojan-activity; sid:100000780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.46",nocase; classtype:trojan-activity; sid:100000781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.43",nocase; classtype:trojan-activity; sid:100000781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.80",nocase; classtype:trojan-activity; sid:100000782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.202",nocase; classtype:trojan-activity; sid:100000783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.90",nocase; classtype:trojan-activity; sid:100000784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.222",nocase; classtype:trojan-activity; sid:100000785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.248",nocase; classtype:trojan-activity; sid:100000786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.34",nocase; classtype:trojan-activity; sid:100000787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.19",nocase; classtype:trojan-activity; sid:100000788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.232",nocase; classtype:trojan-activity; sid:100000789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.250",nocase; classtype:trojan-activity; sid:100000790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.72",nocase; classtype:trojan-activity; sid:100000791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.219",nocase; classtype:trojan-activity; sid:100000785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.19",nocase; classtype:trojan-activity; sid:100000786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.196",nocase; classtype:trojan-activity; sid:100000787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.232",nocase; classtype:trojan-activity; sid:100000788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.250",nocase; classtype:trojan-activity; sid:100000789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.72",nocase; classtype:trojan-activity; sid:100000790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.224",nocase; classtype:trojan-activity; sid:100000791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.26",nocase; classtype:trojan-activity; sid:100000792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.86",nocase; classtype:trojan-activity; sid:100000793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.13",nocase; classtype:trojan-activity; sid:100000794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.135",nocase; classtype:trojan-activity; sid:100000795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.14",nocase; classtype:trojan-activity; sid:100000796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.50",nocase; classtype:trojan-activity; sid:100000797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.54",nocase; classtype:trojan-activity; sid:100000798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.9",nocase; classtype:trojan-activity; sid:100000799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.163",nocase; classtype:trojan-activity; sid:100000800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.183",nocase; classtype:trojan-activity; sid:100000801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.189",nocase; classtype:trojan-activity; sid:100000802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.217",nocase; classtype:trojan-activity; sid:100000803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.46",nocase; classtype:trojan-activity; sid:100000804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.71",nocase; classtype:trojan-activity; sid:100000805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.117",nocase; classtype:trojan-activity; sid:100000806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.126",nocase; classtype:trojan-activity; sid:100000807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.231",nocase; classtype:trojan-activity; sid:100000808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.194",nocase; classtype:trojan-activity; sid:100000809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.34",nocase; classtype:trojan-activity; sid:100000810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.71",nocase; classtype:trojan-activity; sid:100000811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.120",nocase; classtype:trojan-activity; sid:100000812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.135",nocase; classtype:trojan-activity; sid:100000794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.14",nocase; classtype:trojan-activity; sid:100000795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.50",nocase; classtype:trojan-activity; sid:100000796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.9",nocase; classtype:trojan-activity; sid:100000797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.177",nocase; classtype:trojan-activity; sid:100000798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.31",nocase; classtype:trojan-activity; sid:100000799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.189",nocase; classtype:trojan-activity; sid:100000800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.217",nocase; classtype:trojan-activity; sid:100000801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.23",nocase; classtype:trojan-activity; sid:100000802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.46",nocase; classtype:trojan-activity; sid:100000803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.71",nocase; classtype:trojan-activity; sid:100000804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.117",nocase; classtype:trojan-activity; sid:100000805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.126",nocase; classtype:trojan-activity; sid:100000806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.231",nocase; classtype:trojan-activity; sid:100000807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.194",nocase; classtype:trojan-activity; sid:100000808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.53",nocase; classtype:trojan-activity; sid:100000809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.71",nocase; classtype:trojan-activity; sid:100000810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.120",nocase; classtype:trojan-activity; sid:100000811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.198",nocase; classtype:trojan-activity; sid:100000812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.206",nocase; classtype:trojan-activity; sid:100000813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.51",nocase; classtype:trojan-activity; sid:100000814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.93",nocase; classtype:trojan-activity; sid:100000815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.94",nocase; classtype:trojan-activity; sid:100000816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.107",nocase; classtype:trojan-activity; sid:100000817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.176",nocase; classtype:trojan-activity; sid:100000818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.183",nocase; classtype:trojan-activity; sid:100000819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.232",nocase; classtype:trojan-activity; sid:100000820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.114",nocase; classtype:trojan-activity; sid:100000821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.56",nocase; classtype:trojan-activity; sid:100000822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.74",nocase; classtype:trojan-activity; sid:100000815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.93",nocase; classtype:trojan-activity; sid:100000816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.94",nocase; classtype:trojan-activity; sid:100000817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.107",nocase; classtype:trojan-activity; sid:100000818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.176",nocase; classtype:trojan-activity; sid:100000819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.183",nocase; classtype:trojan-activity; sid:100000820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.52",nocase; classtype:trojan-activity; sid:100000821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.162",nocase; classtype:trojan-activity; sid:100000822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.215",nocase; classtype:trojan-activity; sid:100000823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.151",nocase; classtype:trojan-activity; sid:100000824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.32",nocase; classtype:trojan-activity; sid:100000825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.48",nocase; classtype:trojan-activity; sid:100000826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.5",nocase; classtype:trojan-activity; sid:100000827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.135",nocase; classtype:trojan-activity; sid:100000828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.233",nocase; classtype:trojan-activity; sid:100000829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.35",nocase; classtype:trojan-activity; sid:100000830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.203",nocase; classtype:trojan-activity; sid:100000825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.32",nocase; classtype:trojan-activity; sid:100000826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.43",nocase; classtype:trojan-activity; sid:100000827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.5",nocase; classtype:trojan-activity; sid:100000828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.135",nocase; classtype:trojan-activity; sid:100000829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.233",nocase; classtype:trojan-activity; sid:100000830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.109",nocase; classtype:trojan-activity; sid:100000831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.187",nocase; classtype:trojan-activity; sid:100000832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.254",nocase; classtype:trojan-activity; sid:100000833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.71",nocase; classtype:trojan-activity; sid:100000834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.71",nocase; classtype:trojan-activity; sid:100000833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.90",nocase; classtype:trojan-activity; sid:100000834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.128",nocase; classtype:trojan-activity; sid:100000835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.55",nocase; classtype:trojan-activity; sid:100000836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.92",nocase; classtype:trojan-activity; sid:100000837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.34",nocase; classtype:trojan-activity; sid:100000838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.190",nocase; classtype:trojan-activity; sid:100000839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.180",nocase; classtype:trojan-activity; sid:100000840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.222",nocase; classtype:trojan-activity; sid:100000841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.83",nocase; classtype:trojan-activity; sid:100000842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.150",nocase; classtype:trojan-activity; sid:100000843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.175",nocase; classtype:trojan-activity; sid:100000844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.218",nocase; classtype:trojan-activity; sid:100000845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.248",nocase; classtype:trojan-activity; sid:100000846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.250",nocase; classtype:trojan-activity; sid:100000847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.98",nocase; classtype:trojan-activity; sid:100000848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.10",nocase; classtype:trojan-activity; sid:100000849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.122",nocase; classtype:trojan-activity; sid:100000850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.149",nocase; classtype:trojan-activity; sid:100000851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.215",nocase; classtype:trojan-activity; sid:100000852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.234",nocase; classtype:trojan-activity; sid:100000853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.12",nocase; classtype:trojan-activity; sid:100000854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.74",nocase; classtype:trojan-activity; sid:100000855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.88",nocase; classtype:trojan-activity; sid:100000856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.157",nocase; classtype:trojan-activity; sid:100000857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.158",nocase; classtype:trojan-activity; sid:100000858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.203",nocase; classtype:trojan-activity; sid:100000859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.210",nocase; classtype:trojan-activity; sid:100000860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.120",nocase; classtype:trojan-activity; sid:100000861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.180",nocase; classtype:trojan-activity; sid:100000862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.225",nocase; classtype:trojan-activity; sid:100000863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.108",nocase; classtype:trojan-activity; sid:100000864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.254",nocase; classtype:trojan-activity; sid:100000865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.124",nocase; classtype:trojan-activity; sid:100000866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.139",nocase; classtype:trojan-activity; sid:100000867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.182",nocase; classtype:trojan-activity; sid:100000868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.217",nocase; classtype:trojan-activity; sid:100000869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.68",nocase; classtype:trojan-activity; sid:100000870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.221",nocase; classtype:trojan-activity; sid:100000871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.28",nocase; classtype:trojan-activity; sid:100000872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.46",nocase; classtype:trojan-activity; sid:100000873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.114",nocase; classtype:trojan-activity; sid:100000874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.217",nocase; classtype:trojan-activity; sid:100000875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.238",nocase; classtype:trojan-activity; sid:100000876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.186",nocase; classtype:trojan-activity; sid:100000877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.38",nocase; classtype:trojan-activity; sid:100000878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.56",nocase; classtype:trojan-activity; sid:100000879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.78",nocase; classtype:trojan-activity; sid:100000880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.125",nocase; classtype:trojan-activity; sid:100000881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.234",nocase; classtype:trojan-activity; sid:100000882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.113",nocase; classtype:trojan-activity; sid:100000883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.196",nocase; classtype:trojan-activity; sid:100000884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.208",nocase; classtype:trojan-activity; sid:100000885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.11",nocase; classtype:trojan-activity; sid:100000886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.122",nocase; classtype:trojan-activity; sid:100000887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.2",nocase; classtype:trojan-activity; sid:100000888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.222",nocase; classtype:trojan-activity; sid:100000889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.75",nocase; classtype:trojan-activity; sid:100000890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.80",nocase; classtype:trojan-activity; sid:100000891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.99",nocase; classtype:trojan-activity; sid:100000892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.185",nocase; classtype:trojan-activity; sid:100000893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.194",nocase; classtype:trojan-activity; sid:100000894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.223",nocase; classtype:trojan-activity; sid:100000895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.30",nocase; classtype:trojan-activity; sid:100000896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.51",nocase; classtype:trojan-activity; sid:100000897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.54",nocase; classtype:trojan-activity; sid:100000898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.82",nocase; classtype:trojan-activity; sid:100000899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.254",nocase; classtype:trojan-activity; sid:100000900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.44",nocase; classtype:trojan-activity; sid:100000901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.217",nocase; classtype:trojan-activity; sid:100000902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.3",nocase; classtype:trojan-activity; sid:100000903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.42",nocase; classtype:trojan-activity; sid:100000904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.54",nocase; classtype:trojan-activity; sid:100000905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.68",nocase; classtype:trojan-activity; sid:100000906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.177",nocase; classtype:trojan-activity; sid:100000907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.2",nocase; classtype:trojan-activity; sid:100000908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.15",nocase; classtype:trojan-activity; sid:100000909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.176",nocase; classtype:trojan-activity; sid:100000910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.181",nocase; classtype:trojan-activity; sid:100000911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.24",nocase; classtype:trojan-activity; sid:100000912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.214",nocase; classtype:trojan-activity; sid:100000913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.231",nocase; classtype:trojan-activity; sid:100000914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.62",nocase; classtype:trojan-activity; sid:100000915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.79",nocase; classtype:trojan-activity; sid:100000916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.100",nocase; classtype:trojan-activity; sid:100000917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.196",nocase; classtype:trojan-activity; sid:100000918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.170",nocase; classtype:trojan-activity; sid:100000919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.60",nocase; classtype:trojan-activity; sid:100000920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.99",nocase; classtype:trojan-activity; sid:100000921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.30",nocase; classtype:trojan-activity; sid:100000922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.64",nocase; classtype:trojan-activity; sid:100000923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.74",nocase; classtype:trojan-activity; sid:100000924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.112",nocase; classtype:trojan-activity; sid:100000925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.145",nocase; classtype:trojan-activity; sid:100000926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.12",nocase; classtype:trojan-activity; sid:100000927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.235",nocase; classtype:trojan-activity; sid:100000928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.103",nocase; classtype:trojan-activity; sid:100000929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.106",nocase; classtype:trojan-activity; sid:100000930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.12",nocase; classtype:trojan-activity; sid:100000931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.158",nocase; classtype:trojan-activity; sid:100000932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.144",nocase; classtype:trojan-activity; sid:100000933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.180",nocase; classtype:trojan-activity; sid:100000934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.158",nocase; classtype:trojan-activity; sid:100000935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.49",nocase; classtype:trojan-activity; sid:100000936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.7",nocase; classtype:trojan-activity; sid:100000937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.250",nocase; classtype:trojan-activity; sid:100000938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.28",nocase; classtype:trojan-activity; sid:100000939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.137",nocase; classtype:trojan-activity; sid:100000940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.151",nocase; classtype:trojan-activity; sid:100000941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.206",nocase; classtype:trojan-activity; sid:100000942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.223",nocase; classtype:trojan-activity; sid:100000943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.53",nocase; classtype:trojan-activity; sid:100000944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.116",nocase; classtype:trojan-activity; sid:100000945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.234",nocase; classtype:trojan-activity; sid:100000946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.237",nocase; classtype:trojan-activity; sid:100000947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.140",nocase; classtype:trojan-activity; sid:100000948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.186",nocase; classtype:trojan-activity; sid:100000949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.214",nocase; classtype:trojan-activity; sid:100000950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.28",nocase; classtype:trojan-activity; sid:100000951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.65",nocase; classtype:trojan-activity; sid:100000952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.140",nocase; classtype:trojan-activity; sid:100000953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.17",nocase; classtype:trojan-activity; sid:100000954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.171",nocase; classtype:trojan-activity; sid:100000955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.18",nocase; classtype:trojan-activity; sid:100000956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.186",nocase; classtype:trojan-activity; sid:100000957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.35",nocase; classtype:trojan-activity; sid:100000958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.4",nocase; classtype:trojan-activity; sid:100000959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.5",nocase; classtype:trojan-activity; sid:100000960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.18",nocase; classtype:trojan-activity; sid:100000961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.113",nocase; classtype:trojan-activity; sid:100000962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.19",nocase; classtype:trojan-activity; sid:100000963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.198",nocase; classtype:trojan-activity; sid:100000964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.108",nocase; classtype:trojan-activity; sid:100000965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.177",nocase; classtype:trojan-activity; sid:100000966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.178",nocase; classtype:trojan-activity; sid:100000967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.218",nocase; classtype:trojan-activity; sid:100000968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.9",nocase; classtype:trojan-activity; sid:100000969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.143",nocase; classtype:trojan-activity; sid:100000970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.69",nocase; classtype:trojan-activity; sid:100000971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.208",nocase; classtype:trojan-activity; sid:100000972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.220",nocase; classtype:trojan-activity; sid:100000973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.74.223",nocase; classtype:trojan-activity; sid:100000974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.94",nocase; classtype:trojan-activity; sid:100000975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.146",nocase; classtype:trojan-activity; sid:100000976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.221",nocase; classtype:trojan-activity; sid:100000977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.33",nocase; classtype:trojan-activity; sid:100000978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.8",nocase; classtype:trojan-activity; sid:100000979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.47",nocase; classtype:trojan-activity; sid:100000980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.118",nocase; classtype:trojan-activity; sid:100000981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.125",nocase; classtype:trojan-activity; sid:100000982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.250",nocase; classtype:trojan-activity; sid:100000983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.128",nocase; classtype:trojan-activity; sid:100000984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.146",nocase; classtype:trojan-activity; sid:100000985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.198",nocase; classtype:trojan-activity; sid:100000986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.119",nocase; classtype:trojan-activity; sid:100000987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.13",nocase; classtype:trojan-activity; sid:100000988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.130",nocase; classtype:trojan-activity; sid:100000989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.40",nocase; classtype:trojan-activity; sid:100000990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.114",nocase; classtype:trojan-activity; sid:100000991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.144",nocase; classtype:trojan-activity; sid:100000992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.189",nocase; classtype:trojan-activity; sid:100000993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.82.110",nocase; classtype:trojan-activity; sid:100000994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.82.73",nocase; classtype:trojan-activity; sid:100000995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.125",nocase; classtype:trojan-activity; sid:100000996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.154",nocase; classtype:trojan-activity; sid:100000997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.201",nocase; classtype:trojan-activity; sid:100000998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.237",nocase; classtype:trojan-activity; sid:100000999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.190",nocase; classtype:trojan-activity; sid:100001000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.117",nocase; classtype:trojan-activity; sid:100001001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.49",nocase; classtype:trojan-activity; sid:100001002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.59",nocase; classtype:trojan-activity; sid:100001003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.151",nocase; classtype:trojan-activity; sid:100001004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.161",nocase; classtype:trojan-activity; sid:100001005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.202",nocase; classtype:trojan-activity; sid:100001006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.207",nocase; classtype:trojan-activity; sid:100001007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.227",nocase; classtype:trojan-activity; sid:100001008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.102",nocase; classtype:trojan-activity; sid:100001009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.130",nocase; classtype:trojan-activity; sid:100001010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.194",nocase; classtype:trojan-activity; sid:100001011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.204",nocase; classtype:trojan-activity; sid:100001012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.85",nocase; classtype:trojan-activity; sid:100001013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.152",nocase; classtype:trojan-activity; sid:100001014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.69",nocase; classtype:trojan-activity; sid:100001015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.223",nocase; classtype:trojan-activity; sid:100001016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.24",nocase; classtype:trojan-activity; sid:100001017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.137",nocase; classtype:trojan-activity; sid:100001018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.236",nocase; classtype:trojan-activity; sid:100001019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.3",nocase; classtype:trojan-activity; sid:100001020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.79",nocase; classtype:trojan-activity; sid:100001021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.3",nocase; classtype:trojan-activity; sid:100001022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.97",nocase; classtype:trojan-activity; sid:100001023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.170",nocase; classtype:trojan-activity; sid:100001024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.115",nocase; classtype:trojan-activity; sid:100001025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.120",nocase; classtype:trojan-activity; sid:100001026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.234",nocase; classtype:trojan-activity; sid:100001027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.42",nocase; classtype:trojan-activity; sid:100001028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.98",nocase; classtype:trojan-activity; sid:100001029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.248",nocase; classtype:trojan-activity; sid:100001030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.27",nocase; classtype:trojan-activity; sid:100001031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.216",nocase; classtype:trojan-activity; sid:100000836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.55",nocase; classtype:trojan-activity; sid:100000837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.92",nocase; classtype:trojan-activity; sid:100000838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.34",nocase; classtype:trojan-activity; sid:100000839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.190",nocase; classtype:trojan-activity; sid:100000840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.233",nocase; classtype:trojan-activity; sid:100000841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.180",nocase; classtype:trojan-activity; sid:100000842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.222",nocase; classtype:trojan-activity; sid:100000843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.83",nocase; classtype:trojan-activity; sid:100000844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.150",nocase; classtype:trojan-activity; sid:100000845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.175",nocase; classtype:trojan-activity; sid:100000846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.218",nocase; classtype:trojan-activity; sid:100000847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.248",nocase; classtype:trojan-activity; sid:100000848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.250",nocase; classtype:trojan-activity; sid:100000849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.98",nocase; classtype:trojan-activity; sid:100000850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.10",nocase; classtype:trojan-activity; sid:100000851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.149",nocase; classtype:trojan-activity; sid:100000852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.215",nocase; classtype:trojan-activity; sid:100000853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.234",nocase; classtype:trojan-activity; sid:100000854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.12",nocase; classtype:trojan-activity; sid:100000855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.74",nocase; classtype:trojan-activity; sid:100000856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.88",nocase; classtype:trojan-activity; sid:100000857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.110",nocase; classtype:trojan-activity; sid:100000858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.158",nocase; classtype:trojan-activity; sid:100000859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.203",nocase; classtype:trojan-activity; sid:100000860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.210",nocase; classtype:trojan-activity; sid:100000861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.120",nocase; classtype:trojan-activity; sid:100000862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.14",nocase; classtype:trojan-activity; sid:100000863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.180",nocase; classtype:trojan-activity; sid:100000864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.225",nocase; classtype:trojan-activity; sid:100000865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.108",nocase; classtype:trojan-activity; sid:100000866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.254",nocase; classtype:trojan-activity; sid:100000867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.124",nocase; classtype:trojan-activity; sid:100000868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.139",nocase; classtype:trojan-activity; sid:100000869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.182",nocase; classtype:trojan-activity; sid:100000870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.217",nocase; classtype:trojan-activity; sid:100000871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.230",nocase; classtype:trojan-activity; sid:100000872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.68",nocase; classtype:trojan-activity; sid:100000873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.221",nocase; classtype:trojan-activity; sid:100000874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.28",nocase; classtype:trojan-activity; sid:100000875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.46",nocase; classtype:trojan-activity; sid:100000876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.114",nocase; classtype:trojan-activity; sid:100000877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.217",nocase; classtype:trojan-activity; sid:100000878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.90",nocase; classtype:trojan-activity; sid:100000879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.186",nocase; classtype:trojan-activity; sid:100000880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.38",nocase; classtype:trojan-activity; sid:100000881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.56",nocase; classtype:trojan-activity; sid:100000882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.78",nocase; classtype:trojan-activity; sid:100000883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.234",nocase; classtype:trojan-activity; sid:100000884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.110",nocase; classtype:trojan-activity; sid:100000885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.113",nocase; classtype:trojan-activity; sid:100000886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.11",nocase; classtype:trojan-activity; sid:100000887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.122",nocase; classtype:trojan-activity; sid:100000888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.127",nocase; classtype:trojan-activity; sid:100000889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.2",nocase; classtype:trojan-activity; sid:100000890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.222",nocase; classtype:trojan-activity; sid:100000891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.75",nocase; classtype:trojan-activity; sid:100000892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.80",nocase; classtype:trojan-activity; sid:100000893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.99",nocase; classtype:trojan-activity; sid:100000894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.164",nocase; classtype:trojan-activity; sid:100000895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.185",nocase; classtype:trojan-activity; sid:100000896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.194",nocase; classtype:trojan-activity; sid:100000897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.223",nocase; classtype:trojan-activity; sid:100000898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.104",nocase; classtype:trojan-activity; sid:100000899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.253",nocase; classtype:trojan-activity; sid:100000900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.30",nocase; classtype:trojan-activity; sid:100000901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.51",nocase; classtype:trojan-activity; sid:100000902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.54",nocase; classtype:trojan-activity; sid:100000903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.82",nocase; classtype:trojan-activity; sid:100000904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.223",nocase; classtype:trojan-activity; sid:100000905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.44",nocase; classtype:trojan-activity; sid:100000906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.217",nocase; classtype:trojan-activity; sid:100000907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.3",nocase; classtype:trojan-activity; sid:100000908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.42",nocase; classtype:trojan-activity; sid:100000909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.54",nocase; classtype:trojan-activity; sid:100000910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.68",nocase; classtype:trojan-activity; sid:100000911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.117",nocase; classtype:trojan-activity; sid:100000912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.2",nocase; classtype:trojan-activity; sid:100000913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.114",nocase; classtype:trojan-activity; sid:100000914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.139",nocase; classtype:trojan-activity; sid:100000915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.15",nocase; classtype:trojan-activity; sid:100000916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.176",nocase; classtype:trojan-activity; sid:100000917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.181",nocase; classtype:trojan-activity; sid:100000918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.24",nocase; classtype:trojan-activity; sid:100000919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.255",nocase; classtype:trojan-activity; sid:100000920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.214",nocase; classtype:trojan-activity; sid:100000921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.231",nocase; classtype:trojan-activity; sid:100000922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.62",nocase; classtype:trojan-activity; sid:100000923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.79",nocase; classtype:trojan-activity; sid:100000924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.87",nocase; classtype:trojan-activity; sid:100000925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.100",nocase; classtype:trojan-activity; sid:100000926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.119",nocase; classtype:trojan-activity; sid:100000927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.78",nocase; classtype:trojan-activity; sid:100000928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.118",nocase; classtype:trojan-activity; sid:100000929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.170",nocase; classtype:trojan-activity; sid:100000930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.60",nocase; classtype:trojan-activity; sid:100000931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.99",nocase; classtype:trojan-activity; sid:100000932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.30",nocase; classtype:trojan-activity; sid:100000933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.64",nocase; classtype:trojan-activity; sid:100000934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.74",nocase; classtype:trojan-activity; sid:100000935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.121",nocase; classtype:trojan-activity; sid:100000936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.145",nocase; classtype:trojan-activity; sid:100000937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.12",nocase; classtype:trojan-activity; sid:100000938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.130",nocase; classtype:trojan-activity; sid:100000939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.18",nocase; classtype:trojan-activity; sid:100000940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.103",nocase; classtype:trojan-activity; sid:100000941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.12",nocase; classtype:trojan-activity; sid:100000942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.173",nocase; classtype:trojan-activity; sid:100000943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.8",nocase; classtype:trojan-activity; sid:100000944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.201",nocase; classtype:trojan-activity; sid:100000945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.203",nocase; classtype:trojan-activity; sid:100000946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.212",nocase; classtype:trojan-activity; sid:100000947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.28",nocase; classtype:trojan-activity; sid:100000948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.130",nocase; classtype:trojan-activity; sid:100000949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.151",nocase; classtype:trojan-activity; sid:100000950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.206",nocase; classtype:trojan-activity; sid:100000951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.53",nocase; classtype:trojan-activity; sid:100000952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.116",nocase; classtype:trojan-activity; sid:100000953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.234",nocase; classtype:trojan-activity; sid:100000954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.237",nocase; classtype:trojan-activity; sid:100000955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.186",nocase; classtype:trojan-activity; sid:100000956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.28",nocase; classtype:trojan-activity; sid:100000957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.65",nocase; classtype:trojan-activity; sid:100000958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.140",nocase; classtype:trojan-activity; sid:100000959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.17",nocase; classtype:trojan-activity; sid:100000960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.171",nocase; classtype:trojan-activity; sid:100000961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.18",nocase; classtype:trojan-activity; sid:100000962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.186",nocase; classtype:trojan-activity; sid:100000963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.35",nocase; classtype:trojan-activity; sid:100000964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.4",nocase; classtype:trojan-activity; sid:100000965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.5",nocase; classtype:trojan-activity; sid:100000966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.113",nocase; classtype:trojan-activity; sid:100000967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.198",nocase; classtype:trojan-activity; sid:100000968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.108",nocase; classtype:trojan-activity; sid:100000969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.177",nocase; classtype:trojan-activity; sid:100000970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.178",nocase; classtype:trojan-activity; sid:100000971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.218",nocase; classtype:trojan-activity; sid:100000972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.9",nocase; classtype:trojan-activity; sid:100000973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.143",nocase; classtype:trojan-activity; sid:100000974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.69",nocase; classtype:trojan-activity; sid:100000975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.208",nocase; classtype:trojan-activity; sid:100000976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.220",nocase; classtype:trojan-activity; sid:100000977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.58",nocase; classtype:trojan-activity; sid:100000978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.74.223",nocase; classtype:trojan-activity; sid:100000979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.94",nocase; classtype:trojan-activity; sid:100000980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.146",nocase; classtype:trojan-activity; sid:100000981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.221",nocase; classtype:trojan-activity; sid:100000982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.33",nocase; classtype:trojan-activity; sid:100000983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.34",nocase; classtype:trojan-activity; sid:100000984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.8",nocase; classtype:trojan-activity; sid:100000985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.118",nocase; classtype:trojan-activity; sid:100000986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.250",nocase; classtype:trojan-activity; sid:100000987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.128",nocase; classtype:trojan-activity; sid:100000988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.146",nocase; classtype:trojan-activity; sid:100000989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.198",nocase; classtype:trojan-activity; sid:100000990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.27",nocase; classtype:trojan-activity; sid:100000991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.119",nocase; classtype:trojan-activity; sid:100000992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.40",nocase; classtype:trojan-activity; sid:100000993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.144",nocase; classtype:trojan-activity; sid:100000994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.189",nocase; classtype:trojan-activity; sid:100000995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.82.110",nocase; classtype:trojan-activity; sid:100000996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.82.73",nocase; classtype:trojan-activity; sid:100000997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.125",nocase; classtype:trojan-activity; sid:100000998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.17",nocase; classtype:trojan-activity; sid:100000999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.146",nocase; classtype:trojan-activity; sid:100001000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.154",nocase; classtype:trojan-activity; sid:100001001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.201",nocase; classtype:trojan-activity; sid:100001002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.237",nocase; classtype:trojan-activity; sid:100001003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.190",nocase; classtype:trojan-activity; sid:100001004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.49",nocase; classtype:trojan-activity; sid:100001005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.151",nocase; classtype:trojan-activity; sid:100001006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.161",nocase; classtype:trojan-activity; sid:100001007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.202",nocase; classtype:trojan-activity; sid:100001008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.227",nocase; classtype:trojan-activity; sid:100001009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.102",nocase; classtype:trojan-activity; sid:100001010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.130",nocase; classtype:trojan-activity; sid:100001011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.194",nocase; classtype:trojan-activity; sid:100001012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.204",nocase; classtype:trojan-activity; sid:100001013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.85",nocase; classtype:trojan-activity; sid:100001014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.152",nocase; classtype:trojan-activity; sid:100001015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.195",nocase; classtype:trojan-activity; sid:100001016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.217",nocase; classtype:trojan-activity; sid:100001017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.223",nocase; classtype:trojan-activity; sid:100001018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.137",nocase; classtype:trojan-activity; sid:100001019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.236",nocase; classtype:trojan-activity; sid:100001020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.3",nocase; classtype:trojan-activity; sid:100001021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.79",nocase; classtype:trojan-activity; sid:100001022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.243",nocase; classtype:trojan-activity; sid:100001023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.3",nocase; classtype:trojan-activity; sid:100001024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.97",nocase; classtype:trojan-activity; sid:100001025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.170",nocase; classtype:trojan-activity; sid:100001026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.213",nocase; classtype:trojan-activity; sid:100001027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.120",nocase; classtype:trojan-activity; sid:100001028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.204",nocase; classtype:trojan-activity; sid:100001029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.234",nocase; classtype:trojan-activity; sid:100001030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.42",nocase; classtype:trojan-activity; sid:100001031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.105",nocase; classtype:trojan-activity; sid:100001032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.54",nocase; classtype:trojan-activity; sid:100001033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.136",nocase; classtype:trojan-activity; sid:100001034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.177",nocase; classtype:trojan-activity; sid:100001035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.198",nocase; classtype:trojan-activity; sid:100001036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.83",nocase; classtype:trojan-activity; sid:100001034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.136",nocase; classtype:trojan-activity; sid:100001035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.177",nocase; classtype:trojan-activity; sid:100001036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.225",nocase; classtype:trojan-activity; sid:100001037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.248",nocase; classtype:trojan-activity; sid:100001038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.70",nocase; classtype:trojan-activity; sid:100001039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.63",nocase; classtype:trojan-activity; sid:100001040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.45",nocase; classtype:trojan-activity; sid:100001041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.90",nocase; classtype:trojan-activity; sid:100001042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.19.183.14",nocase; classtype:trojan-activity; sid:100001043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.205.101.33",nocase; classtype:trojan-activity; sid:100001044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.21.164.68",nocase; classtype:trojan-activity; sid:100001045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.217.8.194",nocase; classtype:trojan-activity; sid:100001046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.22.117.102",nocase; classtype:trojan-activity; sid:100001047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.222.252.130",nocase; classtype:trojan-activity; sid:100001048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.34.183.30",nocase; classtype:trojan-activity; sid:100001049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.48.235.59",nocase; classtype:trojan-activity; sid:100001050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.95.136.35",nocase; classtype:trojan-activity; sid:100001051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.159.58.134",nocase; classtype:trojan-activity; sid:100001052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.225.152.238",nocase; classtype:trojan-activity; sid:100001053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.43.176.41",nocase; classtype:trojan-activity; sid:100001054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.43.176.48",nocase; classtype:trojan-activity; sid:100001055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.60.84.7",nocase; classtype:trojan-activity; sid:100001056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.99.210.161",nocase; classtype:trojan-activity; sid:100001057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.108.21.172",nocase; classtype:trojan-activity; sid:100001058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.114.60.229",nocase; classtype:trojan-activity; sid:100001059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.174.205.57",nocase; classtype:trojan-activity; sid:100001060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.175.236.209",nocase; classtype:trojan-activity; sid:100001061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.105.41",nocase; classtype:trojan-activity; sid:100001062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.110.243",nocase; classtype:trojan-activity; sid:100001063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.165.230",nocase; classtype:trojan-activity; sid:100001064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.214.171",nocase; classtype:trojan-activity; sid:100001065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.34.51",nocase; classtype:trojan-activity; sid:100001066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.104.65",nocase; classtype:trojan-activity; sid:100001067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.180.6",nocase; classtype:trojan-activity; sid:100001068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.242.73",nocase; classtype:trojan-activity; sid:100001069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.218.5.171",nocase; classtype:trojan-activity; sid:100001070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.63",nocase; classtype:trojan-activity; sid:100001039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.45",nocase; classtype:trojan-activity; sid:100001040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.19.183.14",nocase; classtype:trojan-activity; sid:100001041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.205.101.33",nocase; classtype:trojan-activity; sid:100001042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.21.164.68",nocase; classtype:trojan-activity; sid:100001043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.217.8.194",nocase; classtype:trojan-activity; sid:100001044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.22.117.102",nocase; classtype:trojan-activity; sid:100001045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.222.252.130",nocase; classtype:trojan-activity; sid:100001046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.34.183.30",nocase; classtype:trojan-activity; sid:100001047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.48.235.59",nocase; classtype:trojan-activity; sid:100001048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.95.136.35",nocase; classtype:trojan-activity; sid:100001049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.159.58.134",nocase; classtype:trojan-activity; sid:100001050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.225.152.238",nocase; classtype:trojan-activity; sid:100001051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.43.176.41",nocase; classtype:trojan-activity; sid:100001052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.43.176.48",nocase; classtype:trojan-activity; sid:100001053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.60.84.7",nocase; classtype:trojan-activity; sid:100001054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.99.210.161",nocase; classtype:trojan-activity; sid:100001055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.108.21.172",nocase; classtype:trojan-activity; sid:100001056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.114.60.229",nocase; classtype:trojan-activity; sid:100001057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.174.205.57",nocase; classtype:trojan-activity; sid:100001058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.175.236.209",nocase; classtype:trojan-activity; sid:100001059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.105.41",nocase; classtype:trojan-activity; sid:100001060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.110.243",nocase; classtype:trojan-activity; sid:100001061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.165.230",nocase; classtype:trojan-activity; sid:100001062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.214.171",nocase; classtype:trojan-activity; sid:100001063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.34.51",nocase; classtype:trojan-activity; sid:100001064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.104.65",nocase; classtype:trojan-activity; sid:100001065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.180.6",nocase; classtype:trojan-activity; sid:100001066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.242.73",nocase; classtype:trojan-activity; sid:100001067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.5.36",nocase; classtype:trojan-activity; sid:100001068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.218.5.171",nocase; classtype:trojan-activity; sid:100001069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.248.80.38",nocase; classtype:trojan-activity; sid:100001070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.111.36",nocase; classtype:trojan-activity; sid:100001071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.53.93",nocase; classtype:trojan-activity; sid:100001072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.94.170.166",nocase; classtype:trojan-activity; sid:100001073; rev:1;) @@ -1090,226 +1090,226 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.236.4",nocase; classtype:trojan-activity; sid:100001084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.59.162",nocase; classtype:trojan-activity; sid:100001085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.177.134",nocase; classtype:trojan-activity; sid:100001086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.88.240",nocase; classtype:trojan-activity; sid:100001087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.88.247",nocase; classtype:trojan-activity; sid:100001088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.115.176.253",nocase; classtype:trojan-activity; sid:100001089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.102.190",nocase; classtype:trojan-activity; sid:100001090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.35.52",nocase; classtype:trojan-activity; sid:100001091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.200.55",nocase; classtype:trojan-activity; sid:100001092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.22",nocase; classtype:trojan-activity; sid:100001093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.192.88",nocase; classtype:trojan-activity; sid:100001094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.34.180",nocase; classtype:trojan-activity; sid:100001095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.73.158",nocase; classtype:trojan-activity; sid:100001096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.254.7",nocase; classtype:trojan-activity; sid:100001097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.87.210",nocase; classtype:trojan-activity; sid:100001098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.87.246",nocase; classtype:trojan-activity; sid:100001099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.213.136",nocase; classtype:trojan-activity; sid:100001100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.160.98.250",nocase; classtype:trojan-activity; sid:100001101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.233.0.252",nocase; classtype:trojan-activity; sid:100001102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.235.252.31",nocase; classtype:trojan-activity; sid:100001103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.53.197.62",nocase; classtype:trojan-activity; sid:100001104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.59.170.157",nocase; classtype:trojan-activity; sid:100001105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.88.27.89",nocase; classtype:trojan-activity; sid:100001106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.104.83",nocase; classtype:trojan-activity; sid:100001107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.109.169.45",nocase; classtype:trojan-activity; sid:100001108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.17.145.112",nocase; classtype:trojan-activity; sid:100001109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.144.204",nocase; classtype:trojan-activity; sid:100001110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.146.216",nocase; classtype:trojan-activity; sid:100001111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.109.216",nocase; classtype:trojan-activity; sid:100001112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.14.20",nocase; classtype:trojan-activity; sid:100001113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.97.40.9",nocase; classtype:trojan-activity; sid:100001114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.164.185.41",nocase; classtype:trojan-activity; sid:100001115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.175.115.10",nocase; classtype:trojan-activity; sid:100001116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.74.149.230",nocase; classtype:trojan-activity; sid:100001117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.106.209.68",nocase; classtype:trojan-activity; sid:100001118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.107.3.8",nocase; classtype:trojan-activity; sid:100001119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.117.2.107",nocase; classtype:trojan-activity; sid:100001120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.172.110.209",nocase; classtype:trojan-activity; sid:100001121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.172.110.235",nocase; classtype:trojan-activity; sid:100001122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.174.101.41",nocase; classtype:trojan-activity; sid:100001123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.181.10.234",nocase; classtype:trojan-activity; sid:100001124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.112",nocase; classtype:trojan-activity; sid:100001125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.23",nocase; classtype:trojan-activity; sid:100001126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.54",nocase; classtype:trojan-activity; sid:100001127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.77",nocase; classtype:trojan-activity; sid:100001128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.221.3.244",nocase; classtype:trojan-activity; sid:100001129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.222.58.152",nocase; classtype:trojan-activity; sid:100001130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.224.129.224",nocase; classtype:trojan-activity; sid:100001131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.224.129.235",nocase; classtype:trojan-activity; sid:100001132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.228.141.74",nocase; classtype:trojan-activity; sid:100001133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.245.96.94",nocase; classtype:trojan-activity; sid:100001134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.26.113.95",nocase; classtype:trojan-activity; sid:100001135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.34.16.231",nocase; classtype:trojan-activity; sid:100001136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.55.1.182",nocase; classtype:trojan-activity; sid:100001137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.68.230.207",nocase; classtype:trojan-activity; sid:100001138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.81.154.208",nocase; classtype:trojan-activity; sid:100001139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.81.157.186",nocase; classtype:trojan-activity; sid:100001140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.185",nocase; classtype:trojan-activity; sid:100001141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.213",nocase; classtype:trojan-activity; sid:100001142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.160",nocase; classtype:trojan-activity; sid:100001143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.161",nocase; classtype:trojan-activity; sid:100001144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.219",nocase; classtype:trojan-activity; sid:100001145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.80",nocase; classtype:trojan-activity; sid:100001146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.151.144.85",nocase; classtype:trojan-activity; sid:100001147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.219.164",nocase; classtype:trojan-activity; sid:100001148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.112",nocase; classtype:trojan-activity; sid:100001149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.77",nocase; classtype:trojan-activity; sid:100001150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.91",nocase; classtype:trojan-activity; sid:100001151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.253.150",nocase; classtype:trojan-activity; sid:100001152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.225.120.173",nocase; classtype:trojan-activity; sid:100001153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.232.44.86",nocase; classtype:trojan-activity; sid:100001154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.28.60.184",nocase; classtype:trojan-activity; sid:100001155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.34.4.40",nocase; classtype:trojan-activity; sid:100001156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.73.188.132",nocase; classtype:trojan-activity; sid:100001157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.73.188.134",nocase; classtype:trojan-activity; sid:100001158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.12.10.98",nocase; classtype:trojan-activity; sid:100001159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.135.141.192",nocase; classtype:trojan-activity; sid:100001160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.188.124.229",nocase; classtype:trojan-activity; sid:100001161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.233.234.215",nocase; classtype:trojan-activity; sid:100001162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.21.14",nocase; classtype:trojan-activity; sid:100001163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.231.246",nocase; classtype:trojan-activity; sid:100001164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.13.179.87",nocase; classtype:trojan-activity; sid:100001165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.138.200.32",nocase; classtype:trojan-activity; sid:100001166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.152.41.141",nocase; classtype:trojan-activity; sid:100001167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.178.50",nocase; classtype:trojan-activity; sid:100001168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.179.127",nocase; classtype:trojan-activity; sid:100001169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.30.30",nocase; classtype:trojan-activity; sid:100001170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.36.163",nocase; classtype:trojan-activity; sid:100001171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.242.242.144",nocase; classtype:trojan-activity; sid:100001172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.69.251.12",nocase; classtype:trojan-activity; sid:100001173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.83.202.25",nocase; classtype:trojan-activity; sid:100001174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"189.201.250.184",nocase; classtype:trojan-activity; sid:100001175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"189.252.184.115",nocase; classtype:trojan-activity; sid:100001176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.0.42.106",nocase; classtype:trojan-activity; sid:100001177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.109.178.139",nocase; classtype:trojan-activity; sid:100001178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.110.161.252",nocase; classtype:trojan-activity; sid:100001179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.111.151.164",nocase; classtype:trojan-activity; sid:100001180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.119.207.58",nocase; classtype:trojan-activity; sid:100001181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.12.99.194",nocase; classtype:trojan-activity; sid:100001182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.160",nocase; classtype:trojan-activity; sid:100001183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.3",nocase; classtype:trojan-activity; sid:100001184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.37",nocase; classtype:trojan-activity; sid:100001185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.41",nocase; classtype:trojan-activity; sid:100001186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.42",nocase; classtype:trojan-activity; sid:100001187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.76",nocase; classtype:trojan-activity; sid:100001188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.20.14",nocase; classtype:trojan-activity; sid:100001189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.141.117.41",nocase; classtype:trojan-activity; sid:100001190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.147.16.184",nocase; classtype:trojan-activity; sid:100001191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.159.240.9",nocase; classtype:trojan-activity; sid:100001192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.210.214.130",nocase; classtype:trojan-activity; sid:100001193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.177.39",nocase; classtype:trojan-activity; sid:100001194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.226.63",nocase; classtype:trojan-activity; sid:100001195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.49.207",nocase; classtype:trojan-activity; sid:100001196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.214.24.194",nocase; classtype:trojan-activity; sid:100001197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.216.140.123",nocase; classtype:trojan-activity; sid:100001198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.65.206.162",nocase; classtype:trojan-activity; sid:100001199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.73.12.149",nocase; classtype:trojan-activity; sid:100001200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.92.4.231",nocase; classtype:trojan-activity; sid:100001201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.135",nocase; classtype:trojan-activity; sid:100001202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.200",nocase; classtype:trojan-activity; sid:100001203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.41.33",nocase; classtype:trojan-activity; sid:100001204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"191.255.248.220",nocase; classtype:trojan-activity; sid:100001205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.153.57.94",nocase; classtype:trojan-activity; sid:100001206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.210.175.130",nocase; classtype:trojan-activity; sid:100001207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.220.55",nocase; classtype:trojan-activity; sid:100001208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.228.67",nocase; classtype:trojan-activity; sid:100001209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.99.240.77",nocase; classtype:trojan-activity; sid:100001210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.113.107.243",nocase; classtype:trojan-activity; sid:100001211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.147.142.230",nocase; classtype:trojan-activity; sid:100001212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.15.36.167",nocase; classtype:trojan-activity; sid:100001213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.152.35.139",nocase; classtype:trojan-activity; sid:100001214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.38.20.199",nocase; classtype:trojan-activity; sid:100001215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.139.126.51",nocase; classtype:trojan-activity; sid:100001216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.228.231.218",nocase; classtype:trojan-activity; sid:100001217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.24.94.187",nocase; classtype:trojan-activity; sid:100001218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.202.26.182",nocase; classtype:trojan-activity; sid:100001219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.218.48.82",nocase; classtype:trojan-activity; sid:100001220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.148.90",nocase; classtype:trojan-activity; sid:100001221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.166.203",nocase; classtype:trojan-activity; sid:100001222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.159.2.106",nocase; classtype:trojan-activity; sid:100001223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.50.27.115",nocase; classtype:trojan-activity; sid:100001224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.133.218",nocase; classtype:trojan-activity; sid:100001225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.174.104",nocase; classtype:trojan-activity; sid:100001226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.207.121",nocase; classtype:trojan-activity; sid:100001227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.251.105",nocase; classtype:trojan-activity; sid:100001228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.132.132",nocase; classtype:trojan-activity; sid:100001229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1am.co.nz",nocase; classtype:trojan-activity; sid:100001230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.239.22.188",nocase; classtype:trojan-activity; sid:100001231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.36.231.201",nocase; classtype:trojan-activity; sid:100001232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.37.149.230",nocase; classtype:trojan-activity; sid:100001233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.37.203.65",nocase; classtype:trojan-activity; sid:100001234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.111.158",nocase; classtype:trojan-activity; sid:100001235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.4.24",nocase; classtype:trojan-activity; sid:100001236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.125.182",nocase; classtype:trojan-activity; sid:100001237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.92.184",nocase; classtype:trojan-activity; sid:100001238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.56.8.80",nocase; classtype:trojan-activity; sid:100001239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.57.122.107",nocase; classtype:trojan-activity; sid:100001240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.57.122.24",nocase; classtype:trojan-activity; sid:100001241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.83.152.16",nocase; classtype:trojan-activity; sid:100001242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"20.185.42.197",nocase; classtype:trojan-activity; sid:100001243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.105.167.98",nocase; classtype:trojan-activity; sid:100001244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.111.189.70",nocase; classtype:trojan-activity; sid:100001245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.194.4.24",nocase; classtype:trojan-activity; sid:100001246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.2.161.171",nocase; classtype:trojan-activity; sid:100001247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.29.105.207",nocase; classtype:trojan-activity; sid:100001248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.30.132.50",nocase; classtype:trojan-activity; sid:100001249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.170.46.2",nocase; classtype:trojan-activity; sid:100001250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.184.163.170",nocase; classtype:trojan-activity; sid:100001251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.187.102.73",nocase; classtype:trojan-activity; sid:100001252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.200.254.86",nocase; classtype:trojan-activity; sid:100001253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.203.221.20",nocase; classtype:trojan-activity; sid:100001254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.107.233.41",nocase; classtype:trojan-activity; sid:100001255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.111.131.236",nocase; classtype:trojan-activity; sid:100001256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.166.217.54",nocase; classtype:trojan-activity; sid:100001257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.182.125.175",nocase; classtype:trojan-activity; sid:100001258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.29.95.12",nocase; classtype:trojan-activity; sid:100001259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.4.124.58",nocase; classtype:trojan-activity; sid:100001260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.44.228.125",nocase; classtype:trojan-activity; sid:100001261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.113.4.247",nocase; classtype:trojan-activity; sid:100001087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.194.183",nocase; classtype:trojan-activity; sid:100001088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.102.190",nocase; classtype:trojan-activity; sid:100001089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.29.27",nocase; classtype:trojan-activity; sid:100001090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.200.55",nocase; classtype:trojan-activity; sid:100001091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.23.75",nocase; classtype:trojan-activity; sid:100001092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.48.230",nocase; classtype:trojan-activity; sid:100001093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.22",nocase; classtype:trojan-activity; sid:100001094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.192.88",nocase; classtype:trojan-activity; sid:100001095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.34.180",nocase; classtype:trojan-activity; sid:100001096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.200.137",nocase; classtype:trojan-activity; sid:100001097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.205.246",nocase; classtype:trojan-activity; sid:100001098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.254.7",nocase; classtype:trojan-activity; sid:100001099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.109.194",nocase; classtype:trojan-activity; sid:100001100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.126.162",nocase; classtype:trojan-activity; sid:100001101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.87.210",nocase; classtype:trojan-activity; sid:100001102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.87.246",nocase; classtype:trojan-activity; sid:100001103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.207.187",nocase; classtype:trojan-activity; sid:100001104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.80.240",nocase; classtype:trojan-activity; sid:100001105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.160.98.250",nocase; classtype:trojan-activity; sid:100001106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.233.0.252",nocase; classtype:trojan-activity; sid:100001107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.235.252.31",nocase; classtype:trojan-activity; sid:100001108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.53.197.62",nocase; classtype:trojan-activity; sid:100001109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.88.27.89",nocase; classtype:trojan-activity; sid:100001110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.104.83",nocase; classtype:trojan-activity; sid:100001111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.109.169.45",nocase; classtype:trojan-activity; sid:100001112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.141.61.174",nocase; classtype:trojan-activity; sid:100001113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.17.145.112",nocase; classtype:trojan-activity; sid:100001114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.144.204",nocase; classtype:trojan-activity; sid:100001115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.49.86.54",nocase; classtype:trojan-activity; sid:100001116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.14.20",nocase; classtype:trojan-activity; sid:100001117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.97.40.9",nocase; classtype:trojan-activity; sid:100001118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.164.185.41",nocase; classtype:trojan-activity; sid:100001119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.175.115.10",nocase; classtype:trojan-activity; sid:100001120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.74.149.230",nocase; classtype:trojan-activity; sid:100001121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.106.209.68",nocase; classtype:trojan-activity; sid:100001122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.117.2.107",nocase; classtype:trojan-activity; sid:100001123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.117.21.212",nocase; classtype:trojan-activity; sid:100001124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.132.53.182",nocase; classtype:trojan-activity; sid:100001125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.172.110.209",nocase; classtype:trojan-activity; sid:100001126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.172.110.235",nocase; classtype:trojan-activity; sid:100001127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.174.101.41",nocase; classtype:trojan-activity; sid:100001128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.181.10.234",nocase; classtype:trojan-activity; sid:100001129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.112",nocase; classtype:trojan-activity; sid:100001130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.23",nocase; classtype:trojan-activity; sid:100001131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.54",nocase; classtype:trojan-activity; sid:100001132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.77",nocase; classtype:trojan-activity; sid:100001133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.221.3.244",nocase; classtype:trojan-activity; sid:100001134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.222.58.152",nocase; classtype:trojan-activity; sid:100001135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.224.129.224",nocase; classtype:trojan-activity; sid:100001136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.224.129.235",nocase; classtype:trojan-activity; sid:100001137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.228.141.74",nocase; classtype:trojan-activity; sid:100001138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.245.96.94",nocase; classtype:trojan-activity; sid:100001139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.26.113.95",nocase; classtype:trojan-activity; sid:100001140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.34.16.231",nocase; classtype:trojan-activity; sid:100001141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.38.142.194",nocase; classtype:trojan-activity; sid:100001142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.55.1.182",nocase; classtype:trojan-activity; sid:100001143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.68.230.207",nocase; classtype:trojan-activity; sid:100001144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.81.154.208",nocase; classtype:trojan-activity; sid:100001145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.81.157.186",nocase; classtype:trojan-activity; sid:100001146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.185",nocase; classtype:trojan-activity; sid:100001147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.213",nocase; classtype:trojan-activity; sid:100001148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.219",nocase; classtype:trojan-activity; sid:100001149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.80",nocase; classtype:trojan-activity; sid:100001150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.151.144.85",nocase; classtype:trojan-activity; sid:100001151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.219.164",nocase; classtype:trojan-activity; sid:100001152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.112",nocase; classtype:trojan-activity; sid:100001153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.77",nocase; classtype:trojan-activity; sid:100001154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.91",nocase; classtype:trojan-activity; sid:100001155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.253.150",nocase; classtype:trojan-activity; sid:100001156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.225.120.173",nocase; classtype:trojan-activity; sid:100001157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.232.44.86",nocase; classtype:trojan-activity; sid:100001158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.28.60.184",nocase; classtype:trojan-activity; sid:100001159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.34.4.40",nocase; classtype:trojan-activity; sid:100001160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.73.188.132",nocase; classtype:trojan-activity; sid:100001161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.12.10.98",nocase; classtype:trojan-activity; sid:100001162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.135.141.192",nocase; classtype:trojan-activity; sid:100001163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.188.124.229",nocase; classtype:trojan-activity; sid:100001164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.233.234.215",nocase; classtype:trojan-activity; sid:100001165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.21.14",nocase; classtype:trojan-activity; sid:100001166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.231.246",nocase; classtype:trojan-activity; sid:100001167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.13.179.87",nocase; classtype:trojan-activity; sid:100001168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.138.200.32",nocase; classtype:trojan-activity; sid:100001169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.152.41.141",nocase; classtype:trojan-activity; sid:100001170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.178.50",nocase; classtype:trojan-activity; sid:100001171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.179.127",nocase; classtype:trojan-activity; sid:100001172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.199.59",nocase; classtype:trojan-activity; sid:100001173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.30.30",nocase; classtype:trojan-activity; sid:100001174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.36.163",nocase; classtype:trojan-activity; sid:100001175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.45.140",nocase; classtype:trojan-activity; sid:100001176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.242.242.144",nocase; classtype:trojan-activity; sid:100001177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.69.251.12",nocase; classtype:trojan-activity; sid:100001178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.83.202.25",nocase; classtype:trojan-activity; sid:100001179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"189.171.22.132",nocase; classtype:trojan-activity; sid:100001180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"189.175.214.112",nocase; classtype:trojan-activity; sid:100001181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"189.252.184.115",nocase; classtype:trojan-activity; sid:100001182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.0.42.106",nocase; classtype:trojan-activity; sid:100001183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.109.178.139",nocase; classtype:trojan-activity; sid:100001184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.110.161.252",nocase; classtype:trojan-activity; sid:100001185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.111.151.164",nocase; classtype:trojan-activity; sid:100001186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.119.207.58",nocase; classtype:trojan-activity; sid:100001187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.12.99.194",nocase; classtype:trojan-activity; sid:100001188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.160",nocase; classtype:trojan-activity; sid:100001189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.3",nocase; classtype:trojan-activity; sid:100001190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.37",nocase; classtype:trojan-activity; sid:100001191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.41",nocase; classtype:trojan-activity; sid:100001192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.42",nocase; classtype:trojan-activity; sid:100001193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.76",nocase; classtype:trojan-activity; sid:100001194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.20.14",nocase; classtype:trojan-activity; sid:100001195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.147.16.184",nocase; classtype:trojan-activity; sid:100001196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.159.240.9",nocase; classtype:trojan-activity; sid:100001197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.210.214.130",nocase; classtype:trojan-activity; sid:100001198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.177.39",nocase; classtype:trojan-activity; sid:100001199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.226.63",nocase; classtype:trojan-activity; sid:100001200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.49.207",nocase; classtype:trojan-activity; sid:100001201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.214.24.194",nocase; classtype:trojan-activity; sid:100001202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.216.140.123",nocase; classtype:trojan-activity; sid:100001203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.65.206.162",nocase; classtype:trojan-activity; sid:100001204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.73.12.149",nocase; classtype:trojan-activity; sid:100001205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.92.4.231",nocase; classtype:trojan-activity; sid:100001206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.135",nocase; classtype:trojan-activity; sid:100001207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.200",nocase; classtype:trojan-activity; sid:100001208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.41.33",nocase; classtype:trojan-activity; sid:100001209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"191.255.248.220",nocase; classtype:trojan-activity; sid:100001210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.210.175.130",nocase; classtype:trojan-activity; sid:100001211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.185.106",nocase; classtype:trojan-activity; sid:100001212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.220.55",nocase; classtype:trojan-activity; sid:100001213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.228.67",nocase; classtype:trojan-activity; sid:100001214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.99.221.230",nocase; classtype:trojan-activity; sid:100001215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.99.240.77",nocase; classtype:trojan-activity; sid:100001216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.113.107.243",nocase; classtype:trojan-activity; sid:100001217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.147.142.230",nocase; classtype:trojan-activity; sid:100001218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.152.35.139",nocase; classtype:trojan-activity; sid:100001219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.38.20.199",nocase; classtype:trojan-activity; sid:100001220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.139.126.51",nocase; classtype:trojan-activity; sid:100001221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.228.231.218",nocase; classtype:trojan-activity; sid:100001222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.24.94.187",nocase; classtype:trojan-activity; sid:100001223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.5.3.162",nocase; classtype:trojan-activity; sid:100001224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.202.26.182",nocase; classtype:trojan-activity; sid:100001225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.218.48.82",nocase; classtype:trojan-activity; sid:100001226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.148.90",nocase; classtype:trojan-activity; sid:100001227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.166.203",nocase; classtype:trojan-activity; sid:100001228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.159.2.106",nocase; classtype:trojan-activity; sid:100001229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.50.27.115",nocase; classtype:trojan-activity; sid:100001230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.133.218",nocase; classtype:trojan-activity; sid:100001231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.213.61",nocase; classtype:trojan-activity; sid:100001232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.251.105",nocase; classtype:trojan-activity; sid:100001233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1am.co.nz",nocase; classtype:trojan-activity; sid:100001234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.239.22.188",nocase; classtype:trojan-activity; sid:100001235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.36.231.201",nocase; classtype:trojan-activity; sid:100001236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.37.149.230",nocase; classtype:trojan-activity; sid:100001237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.111.158",nocase; classtype:trojan-activity; sid:100001238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.4.24",nocase; classtype:trojan-activity; sid:100001239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.125.182",nocase; classtype:trojan-activity; sid:100001240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.92.184",nocase; classtype:trojan-activity; sid:100001241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.56.8.80",nocase; classtype:trojan-activity; sid:100001242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.57.122.107",nocase; classtype:trojan-activity; sid:100001243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.57.122.24",nocase; classtype:trojan-activity; sid:100001244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.83.152.16",nocase; classtype:trojan-activity; sid:100001245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"20.185.42.197",nocase; classtype:trojan-activity; sid:100001246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.105.167.98",nocase; classtype:trojan-activity; sid:100001247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.111.189.70",nocase; classtype:trojan-activity; sid:100001248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.194.4.24",nocase; classtype:trojan-activity; sid:100001249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.29.105.207",nocase; classtype:trojan-activity; sid:100001250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.30.132.50",nocase; classtype:trojan-activity; sid:100001251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.170.46.2",nocase; classtype:trojan-activity; sid:100001252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.184.163.170",nocase; classtype:trojan-activity; sid:100001253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.187.102.73",nocase; classtype:trojan-activity; sid:100001254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.200.254.86",nocase; classtype:trojan-activity; sid:100001255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.203.221.20",nocase; classtype:trojan-activity; sid:100001256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.107.233.41",nocase; classtype:trojan-activity; sid:100001257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.111.131.236",nocase; classtype:trojan-activity; sid:100001258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.166.217.54",nocase; classtype:trojan-activity; sid:100001259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.29.95.12",nocase; classtype:trojan-activity; sid:100001260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.4.124.58",nocase; classtype:trojan-activity; sid:100001261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.176.114",nocase; classtype:trojan-activity; sid:100001262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.191.174",nocase; classtype:trojan-activity; sid:100001263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.74.236.9",nocase; classtype:trojan-activity; sid:100001264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.109.201.243",nocase; classtype:trojan-activity; sid:100001265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.159.80.128",nocase; classtype:trojan-activity; sid:100001266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.159.80.129",nocase; classtype:trojan-activity; sid:100001267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.159.80.164",nocase; classtype:trojan-activity; sid:100001268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.170.123.78",nocase; classtype:trojan-activity; sid:100001269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.189.156.107",nocase; classtype:trojan-activity; sid:100001270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.204.232.18",nocase; classtype:trojan-activity; sid:100001271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.229.21.56",nocase; classtype:trojan-activity; sid:100001272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.236.190.28",nocase; classtype:trojan-activity; sid:100001273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.70.166.107",nocase; classtype:trojan-activity; sid:100001274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.77.80.159",nocase; classtype:trojan-activity; sid:100001275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.119.166",nocase; classtype:trojan-activity; sid:100001276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.171.138",nocase; classtype:trojan-activity; sid:100001277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.82.36.34",nocase; classtype:trojan-activity; sid:100001278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.93.6.28",nocase; classtype:trojan-activity; sid:100001279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"204.195.116.171",nocase; classtype:trojan-activity; sid:100001280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.248.137.132",nocase; classtype:trojan-activity; sid:100001281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.5.32.6",nocase; classtype:trojan-activity; sid:100001282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"208.163.58.18",nocase; classtype:trojan-activity; sid:100001283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"208.75.27.157",nocase; classtype:trojan-activity; sid:100001284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.190",nocase; classtype:trojan-activity; sid:100001285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.31",nocase; classtype:trojan-activity; sid:100001286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.146.98.50",nocase; classtype:trojan-activity; sid:100001287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.124.149.19",nocase; classtype:trojan-activity; sid:100001288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.180.237.212",nocase; classtype:trojan-activity; sid:100001289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.152.122",nocase; classtype:trojan-activity; sid:100001290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.153.142",nocase; classtype:trojan-activity; sid:100001291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.237.70",nocase; classtype:trojan-activity; sid:100001292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.130.69.205",nocase; classtype:trojan-activity; sid:100001266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.159.80.128",nocase; classtype:trojan-activity; sid:100001267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.159.80.129",nocase; classtype:trojan-activity; sid:100001268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.159.80.164",nocase; classtype:trojan-activity; sid:100001269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.170.123.78",nocase; classtype:trojan-activity; sid:100001270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.189.156.107",nocase; classtype:trojan-activity; sid:100001271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.204.232.18",nocase; classtype:trojan-activity; sid:100001272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.229.21.56",nocase; classtype:trojan-activity; sid:100001273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.236.190.28",nocase; classtype:trojan-activity; sid:100001274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.70.166.107",nocase; classtype:trojan-activity; sid:100001275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.77.80.159",nocase; classtype:trojan-activity; sid:100001276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.119.166",nocase; classtype:trojan-activity; sid:100001277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.171.138",nocase; classtype:trojan-activity; sid:100001278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.82.36.34",nocase; classtype:trojan-activity; sid:100001279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.93.6.28",nocase; classtype:trojan-activity; sid:100001280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"204.195.116.171",nocase; classtype:trojan-activity; sid:100001281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.248.137.132",nocase; classtype:trojan-activity; sid:100001282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.5.32.6",nocase; classtype:trojan-activity; sid:100001283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"208.163.58.18",nocase; classtype:trojan-activity; sid:100001284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"208.75.27.157",nocase; classtype:trojan-activity; sid:100001285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.190",nocase; classtype:trojan-activity; sid:100001286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.31",nocase; classtype:trojan-activity; sid:100001287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.146.98.50",nocase; classtype:trojan-activity; sid:100001288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.124.149.19",nocase; classtype:trojan-activity; sid:100001289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.180.237.212",nocase; classtype:trojan-activity; sid:100001290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.152.122",nocase; classtype:trojan-activity; sid:100001291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.153.142",nocase; classtype:trojan-activity; sid:100001292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.245.109",nocase; classtype:trojan-activity; sid:100001293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.68.242.114",nocase; classtype:trojan-activity; sid:100001294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.132.204",nocase; classtype:trojan-activity; sid:100001295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.75.220",nocase; classtype:trojan-activity; sid:100001296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.200.160.239",nocase; classtype:trojan-activity; sid:100001297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.204.215.157",nocase; classtype:trojan-activity; sid:100001298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.66.179",nocase; classtype:trojan-activity; sid:100001299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.93.93",nocase; classtype:trojan-activity; sid:100001300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.216.66.105",nocase; classtype:trojan-activity; sid:100001301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.114.96",nocase; classtype:trojan-activity; sid:100001302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.120.13",nocase; classtype:trojan-activity; sid:100001303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.246.137",nocase; classtype:trojan-activity; sid:100001304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.238.83.238",nocase; classtype:trojan-activity; sid:100001305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.5.96",nocase; classtype:trojan-activity; sid:100001306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.203.111.207",nocase; classtype:trojan-activity; sid:100001298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.204.215.157",nocase; classtype:trojan-activity; sid:100001299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.66.179",nocase; classtype:trojan-activity; sid:100001300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.93.93",nocase; classtype:trojan-activity; sid:100001301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.216.66.105",nocase; classtype:trojan-activity; sid:100001302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.114.96",nocase; classtype:trojan-activity; sid:100001303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.120.13",nocase; classtype:trojan-activity; sid:100001304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.246.137",nocase; classtype:trojan-activity; sid:100001305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.238.83.238",nocase; classtype:trojan-activity; sid:100001306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.122.86.105",nocase; classtype:trojan-activity; sid:100001307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.156.215.178",nocase; classtype:trojan-activity; sid:100001308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.46.197.114",nocase; classtype:trojan-activity; sid:100001309; rev:1;) @@ -1319,7 +1319,7 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.14.173.117",nocase; classtype:trojan-activity; sid:100001313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.190.193",nocase; classtype:trojan-activity; sid:100001314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.160",nocase; classtype:trojan-activity; sid:100001315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.99",nocase; classtype:trojan-activity; sid:100001316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.20",nocase; classtype:trojan-activity; sid:100001316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.225",nocase; classtype:trojan-activity; sid:100001317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.51",nocase; classtype:trojan-activity; sid:100001318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.202",nocase; classtype:trojan-activity; sid:100001319; rev:1;) @@ -1336,7 +1336,7 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.227",nocase; classtype:trojan-activity; sid:100001330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.176",nocase; classtype:trojan-activity; sid:100001331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.201",nocase; classtype:trojan-activity; sid:100001332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.7",nocase; classtype:trojan-activity; sid:100001333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.204",nocase; classtype:trojan-activity; sid:100001333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.250",nocase; classtype:trojan-activity; sid:100001334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.46",nocase; classtype:trojan-activity; sid:100001335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.189.178.163",nocase; classtype:trojan-activity; sid:100001336; rev:1;) @@ -1356,21 +1356,21 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.2.40.34",nocase; classtype:trojan-activity; sid:100001350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.234.165.18",nocase; classtype:trojan-activity; sid:100001351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.238.246.3",nocase; classtype:trojan-activity; sid:100001352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.32.118.1",nocase; classtype:trojan-activity; sid:100001353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.207.119",nocase; classtype:trojan-activity; sid:100001354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.227.133",nocase; classtype:trojan-activity; sid:100001355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.68.35",nocase; classtype:trojan-activity; sid:100001356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.81.81",nocase; classtype:trojan-activity; sid:100001357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.56.93.129",nocase; classtype:trojan-activity; sid:100001358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.59.116.203",nocase; classtype:trojan-activity; sid:100001359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.79.103.159",nocase; classtype:trojan-activity; sid:100001360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.93.102.63",nocase; classtype:trojan-activity; sid:100001361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.93.102.75",nocase; classtype:trojan-activity; sid:100001362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.207.119",nocase; classtype:trojan-activity; sid:100001353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.227.133",nocase; classtype:trojan-activity; sid:100001354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.68.35",nocase; classtype:trojan-activity; sid:100001355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.81.81",nocase; classtype:trojan-activity; sid:100001356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.56.93.129",nocase; classtype:trojan-activity; sid:100001357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.59.116.203",nocase; classtype:trojan-activity; sid:100001358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.79.103.159",nocase; classtype:trojan-activity; sid:100001359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.93.102.63",nocase; classtype:trojan-activity; sid:100001360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.93.102.75",nocase; classtype:trojan-activity; sid:100001361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.113.171",nocase; classtype:trojan-activity; sid:100001362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.127.194",nocase; classtype:trojan-activity; sid:100001363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.137.93",nocase; classtype:trojan-activity; sid:100001364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.73.171",nocase; classtype:trojan-activity; sid:100001365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.136.212",nocase; classtype:trojan-activity; sid:100001366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.139.165",nocase; classtype:trojan-activity; sid:100001367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.226.205",nocase; classtype:trojan-activity; sid:100001364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.136.212",nocase; classtype:trojan-activity; sid:100001365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.14.239",nocase; classtype:trojan-activity; sid:100001366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.178.196",nocase; classtype:trojan-activity; sid:100001367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.37.210",nocase; classtype:trojan-activity; sid:100001368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.241.6.180",nocase; classtype:trojan-activity; sid:100001369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.148",nocase; classtype:trojan-activity; sid:100001370; rev:1;) @@ -1385,44 +1385,44 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.85.145.194",nocase; classtype:trojan-activity; sid:100001379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"21robo.com",nocase; classtype:trojan-activity; sid:100001380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.126.237.74",nocase; classtype:trojan-activity; sid:100001381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.132.106.247",nocase; classtype:trojan-activity; sid:100001382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.173.160.185",nocase; classtype:trojan-activity; sid:100001383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.200.22.163",nocase; classtype:trojan-activity; sid:100001384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.81.134.72",nocase; classtype:trojan-activity; sid:100001385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.90.159.188",nocase; classtype:trojan-activity; sid:100001386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.124.78.15",nocase; classtype:trojan-activity; sid:100001387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.13.150.74",nocase; classtype:trojan-activity; sid:100001388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.162.20",nocase; classtype:trojan-activity; sid:100001389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.173.160.185",nocase; classtype:trojan-activity; sid:100001382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.200.22.163",nocase; classtype:trojan-activity; sid:100001383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.81.134.72",nocase; classtype:trojan-activity; sid:100001384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.90.159.188",nocase; classtype:trojan-activity; sid:100001385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.124.78.15",nocase; classtype:trojan-activity; sid:100001386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.13.150.74",nocase; classtype:trojan-activity; sid:100001387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.162.20",nocase; classtype:trojan-activity; sid:100001388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.47.204",nocase; classtype:trojan-activity; sid:100001389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.127.60",nocase; classtype:trojan-activity; sid:100001390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.3.50",nocase; classtype:trojan-activity; sid:100001391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.157.191.178",nocase; classtype:trojan-activity; sid:100001392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.136.213",nocase; classtype:trojan-activity; sid:100001393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.201.54.97",nocase; classtype:trojan-activity; sid:100001394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.202.232.230",nocase; classtype:trojan-activity; sid:100001395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.130.147",nocase; classtype:trojan-activity; sid:100001396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.163.81",nocase; classtype:trojan-activity; sid:100001397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.197.120",nocase; classtype:trojan-activity; sid:100001398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.251.109",nocase; classtype:trojan-activity; sid:100001399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.116.167",nocase; classtype:trojan-activity; sid:100001400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.172.207",nocase; classtype:trojan-activity; sid:100001401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.184.31",nocase; classtype:trojan-activity; sid:100001402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.252.64",nocase; classtype:trojan-activity; sid:100001403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.8.64",nocase; classtype:trojan-activity; sid:100001404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.232.183.167",nocase; classtype:trojan-activity; sid:100001405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.235.137.36",nocase; classtype:trojan-activity; sid:100001406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.68.16",nocase; classtype:trojan-activity; sid:100001407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.108.17.64",nocase; classtype:trojan-activity; sid:100001408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.118.248.149",nocase; classtype:trojan-activity; sid:100001409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.119.65.145",nocase; classtype:trojan-activity; sid:100001410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.132.125.138",nocase; classtype:trojan-activity; sid:100001411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.9.5",nocase; classtype:trojan-activity; sid:100001412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.122.105",nocase; classtype:trojan-activity; sid:100001413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.139.86",nocase; classtype:trojan-activity; sid:100001414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.170.17",nocase; classtype:trojan-activity; sid:100001415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.182.72",nocase; classtype:trojan-activity; sid:100001391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.3.50",nocase; classtype:trojan-activity; sid:100001392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.157.191.178",nocase; classtype:trojan-activity; sid:100001393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.136.213",nocase; classtype:trojan-activity; sid:100001394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.201.54.97",nocase; classtype:trojan-activity; sid:100001395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.202.232.230",nocase; classtype:trojan-activity; sid:100001396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.130.147",nocase; classtype:trojan-activity; sid:100001397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.163.81",nocase; classtype:trojan-activity; sid:100001398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.197.120",nocase; classtype:trojan-activity; sid:100001399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.251.109",nocase; classtype:trojan-activity; sid:100001400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.116.167",nocase; classtype:trojan-activity; sid:100001401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.172.207",nocase; classtype:trojan-activity; sid:100001402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.184.31",nocase; classtype:trojan-activity; sid:100001403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.252.64",nocase; classtype:trojan-activity; sid:100001404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.8.64",nocase; classtype:trojan-activity; sid:100001405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.232.183.167",nocase; classtype:trojan-activity; sid:100001406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.235.137.36",nocase; classtype:trojan-activity; sid:100001407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.68.16",nocase; classtype:trojan-activity; sid:100001408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.107.145.56",nocase; classtype:trojan-activity; sid:100001409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.108.17.64",nocase; classtype:trojan-activity; sid:100001410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.118.248.149",nocase; classtype:trojan-activity; sid:100001411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.119.65.145",nocase; classtype:trojan-activity; sid:100001412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.9.5",nocase; classtype:trojan-activity; sid:100001413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.122.105",nocase; classtype:trojan-activity; sid:100001414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.139.86",nocase; classtype:trojan-activity; sid:100001415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.72.66",nocase; classtype:trojan-activity; sid:100001416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.133.186",nocase; classtype:trojan-activity; sid:100001417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.17.203",nocase; classtype:trojan-activity; sid:100001418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.139.21.190",nocase; classtype:trojan-activity; sid:100001419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.139.21.190",nocase; classtype:trojan-activity; sid:100001418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.163.181",nocase; classtype:trojan-activity; sid:100001419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.17.245",nocase; classtype:trojan-activity; sid:100001420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.187.9.178",nocase; classtype:trojan-activity; sid:100001421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.211.72.66",nocase; classtype:trojan-activity; sid:100001422; rev:1;) @@ -1445,9 +1445,9 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.24.213.121",nocase; classtype:trojan-activity; sid:100001439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.149.13",nocase; classtype:trojan-activity; sid:100001440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.21.167",nocase; classtype:trojan-activity; sid:100001441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.92.213.108",nocase; classtype:trojan-activity; sid:100001442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.94.190.101",nocase; classtype:trojan-activity; sid:100001443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.95.122.24",nocase; classtype:trojan-activity; sid:100001444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.94.190.101",nocase; classtype:trojan-activity; sid:100001442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.95.122.24",nocase; classtype:trojan-activity; sid:100001443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.95.122.25",nocase; classtype:trojan-activity; sid:100001444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.103.74.180",nocase; classtype:trojan-activity; sid:100001445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.11.141.134",nocase; classtype:trojan-activity; sid:100001446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.119.158.74",nocase; classtype:trojan-activity; sid:100001447; rev:1;) @@ -1518,2510 +1518,2532 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.255.202",nocase; classtype:trojan-activity; sid:100001512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.66.112",nocase; classtype:trojan-activity; sid:100001513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.84.74",nocase; classtype:trojan-activity; sid:100001514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.214.37.129",nocase; classtype:trojan-activity; sid:100001515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.139.242",nocase; classtype:trojan-activity; sid:100001516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.190.172",nocase; classtype:trojan-activity; sid:100001517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.212.209",nocase; classtype:trojan-activity; sid:100001518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.253.149",nocase; classtype:trojan-activity; sid:100001519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.71.243",nocase; classtype:trojan-activity; sid:100001520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.98.242",nocase; classtype:trojan-activity; sid:100001521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.144.66",nocase; classtype:trojan-activity; sid:100001522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.225.28",nocase; classtype:trojan-activity; sid:100001523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.227.95",nocase; classtype:trojan-activity; sid:100001524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.234.98",nocase; classtype:trojan-activity; sid:100001525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.191.58",nocase; classtype:trojan-activity; sid:100001526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.135.3",nocase; classtype:trojan-activity; sid:100001527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.132.71",nocase; classtype:trojan-activity; sid:100001528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.151.83",nocase; classtype:trojan-activity; sid:100001529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.160.112",nocase; classtype:trojan-activity; sid:100001530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.176.72",nocase; classtype:trojan-activity; sid:100001531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.83.244",nocase; classtype:trojan-activity; sid:100001532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.20.66",nocase; classtype:trojan-activity; sid:100001533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.249.0",nocase; classtype:trojan-activity; sid:100001534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.83.170",nocase; classtype:trojan-activity; sid:100001535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.85.168",nocase; classtype:trojan-activity; sid:100001536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.221.239.223",nocase; classtype:trojan-activity; sid:100001537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.221.242.95",nocase; classtype:trojan-activity; sid:100001538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.76.80",nocase; classtype:trojan-activity; sid:100001539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.223.242.164",nocase; classtype:trojan-activity; sid:100001540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.129.198",nocase; classtype:trojan-activity; sid:100001541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.154.13",nocase; classtype:trojan-activity; sid:100001542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.212.124",nocase; classtype:trojan-activity; sid:100001543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.58.5",nocase; classtype:trojan-activity; sid:100001544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.40.120.108",nocase; classtype:trojan-activity; sid:100001545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.40.73.175",nocase; classtype:trojan-activity; sid:100001546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.36.97",nocase; classtype:trojan-activity; sid:100001547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.45.90.246",nocase; classtype:trojan-activity; sid:100001548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.44.190",nocase; classtype:trojan-activity; sid:100001549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.0.98.131",nocase; classtype:trojan-activity; sid:100001550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.11.51.57",nocase; classtype:trojan-activity; sid:100001551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.13.23.180",nocase; classtype:trojan-activity; sid:100001552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.124.130",nocase; classtype:trojan-activity; sid:100001553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.146.199",nocase; classtype:trojan-activity; sid:100001554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.179.83",nocase; classtype:trojan-activity; sid:100001555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.184.59",nocase; classtype:trojan-activity; sid:100001556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.191.243",nocase; classtype:trojan-activity; sid:100001557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.194.67",nocase; classtype:trojan-activity; sid:100001558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.216.132",nocase; classtype:trojan-activity; sid:100001559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.219.28",nocase; classtype:trojan-activity; sid:100001560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.24.115",nocase; classtype:trojan-activity; sid:100001561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.30.65",nocase; classtype:trojan-activity; sid:100001562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.65.233",nocase; classtype:trojan-activity; sid:100001563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.79.66",nocase; classtype:trojan-activity; sid:100001564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.94.16",nocase; classtype:trojan-activity; sid:100001565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.179.201.26",nocase; classtype:trojan-activity; sid:100001566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.195.84.250",nocase; classtype:trojan-activity; sid:100001567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.138",nocase; classtype:trojan-activity; sid:100001568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.28.7.159",nocase; classtype:trojan-activity; sid:100001569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.30.119.23",nocase; classtype:trojan-activity; sid:100001570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32.208.157.193",nocase; classtype:trojan-activity; sid:100001571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32792.prolocksmithwinterpark.com",nocase; classtype:trojan-activity; sid:100001572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"34.122.44.188",nocase; classtype:trojan-activity; sid:100001573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"34.126.93.163",nocase; classtype:trojan-activity; sid:100001574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"35.184.169.169",nocase; classtype:trojan-activity; sid:100001575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.108.231.218",nocase; classtype:trojan-activity; sid:100001576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.248.83.98",nocase; classtype:trojan-activity; sid:100001577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.250.203.246",nocase; classtype:trojan-activity; sid:100001578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.157.225",nocase; classtype:trojan-activity; sid:100001579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.18.18",nocase; classtype:trojan-activity; sid:100001580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.51.244",nocase; classtype:trojan-activity; sid:100001581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.255.90.219",nocase; classtype:trojan-activity; sid:100001582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.32.28.18",nocase; classtype:trojan-activity; sid:100001583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.160.167",nocase; classtype:trojan-activity; sid:100001584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.34.150.236",nocase; classtype:trojan-activity; sid:100001585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.65.216.145",nocase; classtype:trojan-activity; sid:100001586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.105.159",nocase; classtype:trojan-activity; sid:100001587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.133.125",nocase; classtype:trojan-activity; sid:100001588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.139.36",nocase; classtype:trojan-activity; sid:100001589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.89.18.133",nocase; classtype:trojan-activity; sid:100001590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.91.89.187",nocase; classtype:trojan-activity; sid:100001591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360.lcy2zzx.pw",nocase; classtype:trojan-activity; sid:100001592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360down7.miiyun.cn",nocase; classtype:trojan-activity; sid:100001593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.222.98.51",nocase; classtype:trojan-activity; sid:100001594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.233.60.68",nocase; classtype:trojan-activity; sid:100001595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.179.221",nocase; classtype:trojan-activity; sid:100001596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.180.172",nocase; classtype:trojan-activity; sid:100001597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.44.238.35",nocase; classtype:trojan-activity; sid:100001598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.116.243",nocase; classtype:trojan-activity; sid:100001599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.14.36",nocase; classtype:trojan-activity; sid:100001600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.245.254",nocase; classtype:trojan-activity; sid:100001601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.98.136",nocase; classtype:trojan-activity; sid:100001602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.114.137.102",nocase; classtype:trojan-activity; sid:100001603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.115.0.100",nocase; classtype:trojan-activity; sid:100001604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.117.31.162",nocase; classtype:trojan-activity; sid:100001605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.162.104.119",nocase; classtype:trojan-activity; sid:100001606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.162.98.216",nocase; classtype:trojan-activity; sid:100001607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.164.112.139",nocase; classtype:trojan-activity; sid:100001608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.196.34",nocase; classtype:trojan-activity; sid:100001609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.104.83",nocase; classtype:trojan-activity; sid:100001610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.125.186",nocase; classtype:trojan-activity; sid:100001611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.146.60",nocase; classtype:trojan-activity; sid:100001612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.206.228",nocase; classtype:trojan-activity; sid:100001613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.171.125",nocase; classtype:trojan-activity; sid:100001614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.249.255",nocase; classtype:trojan-activity; sid:100001615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.60.61",nocase; classtype:trojan-activity; sid:100001616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.167.202",nocase; classtype:trojan-activity; sid:100001617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.67.64",nocase; classtype:trojan-activity; sid:100001618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.10.198",nocase; classtype:trojan-activity; sid:100001619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.163.231",nocase; classtype:trojan-activity; sid:100001620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.168.234",nocase; classtype:trojan-activity; sid:100001621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.203.225",nocase; classtype:trojan-activity; sid:100001622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.215.212",nocase; classtype:trojan-activity; sid:100001623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.194.65",nocase; classtype:trojan-activity; sid:100001624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.78.251",nocase; classtype:trojan-activity; sid:100001625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.113.201",nocase; classtype:trojan-activity; sid:100001626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.114.45",nocase; classtype:trojan-activity; sid:100001627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.150.203",nocase; classtype:trojan-activity; sid:100001628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.123.189",nocase; classtype:trojan-activity; sid:100001629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.166.31",nocase; classtype:trojan-activity; sid:100001630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.218.46",nocase; classtype:trojan-activity; sid:100001631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.91.244",nocase; classtype:trojan-activity; sid:100001632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.93.171",nocase; classtype:trojan-activity; sid:100001633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.127.214",nocase; classtype:trojan-activity; sid:100001634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.18.140",nocase; classtype:trojan-activity; sid:100001635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.191.137",nocase; classtype:trojan-activity; sid:100001636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.205.255",nocase; classtype:trojan-activity; sid:100001637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.24.54",nocase; classtype:trojan-activity; sid:100001638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.36.151",nocase; classtype:trojan-activity; sid:100001639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.37.182",nocase; classtype:trojan-activity; sid:100001640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.251.0",nocase; classtype:trojan-activity; sid:100001641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.27.15",nocase; classtype:trojan-activity; sid:100001642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.29.231",nocase; classtype:trojan-activity; sid:100001643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.70.88",nocase; classtype:trojan-activity; sid:100001644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.83.185.108",nocase; classtype:trojan-activity; sid:100001645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.83.94.11",nocase; classtype:trojan-activity; sid:100001646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.115.152",nocase; classtype:trojan-activity; sid:100001647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.85.54.4",nocase; classtype:trojan-activity; sid:100001648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.211.20",nocase; classtype:trojan-activity; sid:100001649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.234.187",nocase; classtype:trojan-activity; sid:100001650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.78.244",nocase; classtype:trojan-activity; sid:100001651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.93.109",nocase; classtype:trojan-activity; sid:100001652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.96.227",nocase; classtype:trojan-activity; sid:100001653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.143.176",nocase; classtype:trojan-activity; sid:100001654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.233.131",nocase; classtype:trojan-activity; sid:100001655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.67.238",nocase; classtype:trojan-activity; sid:100001656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.72.9",nocase; classtype:trojan-activity; sid:100001657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.145.11",nocase; classtype:trojan-activity; sid:100001658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.36",nocase; classtype:trojan-activity; sid:100001659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.63.23",nocase; classtype:trojan-activity; sid:100001660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.90.86.212",nocase; classtype:trojan-activity; sid:100001661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"40.88.2.151",nocase; classtype:trojan-activity; sid:100001662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.139.209.46",nocase; classtype:trojan-activity; sid:100001663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.165.130.43",nocase; classtype:trojan-activity; sid:100001664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.190.63.174",nocase; classtype:trojan-activity; sid:100001665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.193.192.100",nocase; classtype:trojan-activity; sid:100001666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.219.185.171",nocase; classtype:trojan-activity; sid:100001667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.226.60.115",nocase; classtype:trojan-activity; sid:100001668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.147",nocase; classtype:trojan-activity; sid:100001669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.152",nocase; classtype:trojan-activity; sid:100001670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.204",nocase; classtype:trojan-activity; sid:100001671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.19.146",nocase; classtype:trojan-activity; sid:100001672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.19.206",nocase; classtype:trojan-activity; sid:100001673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.28",nocase; classtype:trojan-activity; sid:100001674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.60",nocase; classtype:trojan-activity; sid:100001675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.198",nocase; classtype:trojan-activity; sid:100001676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.202.101.181",nocase; classtype:trojan-activity; sid:100001677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.202.101.199",nocase; classtype:trojan-activity; sid:100001678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.176.27",nocase; classtype:trojan-activity; sid:100001679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.40.143",nocase; classtype:trojan-activity; sid:100001680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.60.114",nocase; classtype:trojan-activity; sid:100001681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.161.72",nocase; classtype:trojan-activity; sid:100001682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.212.157",nocase; classtype:trojan-activity; sid:100001683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.238.141.250",nocase; classtype:trojan-activity; sid:100001684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.56.15.227",nocase; classtype:trojan-activity; sid:100001685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.61.99.155",nocase; classtype:trojan-activity; sid:100001686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.82.217.241",nocase; classtype:trojan-activity; sid:100001687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.230.207.204",nocase; classtype:trojan-activity; sid:100001688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.241.106.183",nocase; classtype:trojan-activity; sid:100001689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.252.8.94",nocase; classtype:trojan-activity; sid:100001690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.203.192",nocase; classtype:trojan-activity; sid:100001691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.135.134.228",nocase; classtype:trojan-activity; sid:100001692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.178",nocase; classtype:trojan-activity; sid:100001693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.182",nocase; classtype:trojan-activity; sid:100001694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.204",nocase; classtype:trojan-activity; sid:100001695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.224.165",nocase; classtype:trojan-activity; sid:100001696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.141.84.184",nocase; classtype:trojan-activity; sid:100001697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.118",nocase; classtype:trojan-activity; sid:100001698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.135",nocase; classtype:trojan-activity; sid:100001699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.213",nocase; classtype:trojan-activity; sid:100001700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.27",nocase; classtype:trojan-activity; sid:100001701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.47",nocase; classtype:trojan-activity; sid:100001702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.94",nocase; classtype:trojan-activity; sid:100001703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.248",nocase; classtype:trojan-activity; sid:100001704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.109.205",nocase; classtype:trojan-activity; sid:100001705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.110.146",nocase; classtype:trojan-activity; sid:100001706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.130",nocase; classtype:trojan-activity; sid:100001707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.22.209.58",nocase; classtype:trojan-activity; sid:100001708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.229.53.148",nocase; classtype:trojan-activity; sid:100001709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.27.253.137",nocase; classtype:trojan-activity; sid:100001710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.51.104.59",nocase; classtype:trojan-activity; sid:100001711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.85.90.131",nocase; classtype:trojan-activity; sid:100001712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.9.148.37",nocase; classtype:trojan-activity; sid:100001713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.92.108.35",nocase; classtype:trojan-activity; sid:100001714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.95.169.143",nocase; classtype:trojan-activity; sid:100001715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.95.169.147",nocase; classtype:trojan-activity; sid:100001716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.95.169.153",nocase; classtype:trojan-activity; sid:100001717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.172.75.231",nocase; classtype:trojan-activity; sid:100001718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.182.173.247",nocase; classtype:trojan-activity; sid:100001719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.20.63.218",nocase; classtype:trojan-activity; sid:100001720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.214.27.4",nocase; classtype:trojan-activity; sid:100001721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.214.35.50",nocase; classtype:trojan-activity; sid:100001722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.236.65.83",nocase; classtype:trojan-activity; sid:100001723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.24.130.254",nocase; classtype:trojan-activity; sid:100001724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.241.120.165",nocase; classtype:trojan-activity; sid:100001725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.243.179.115",nocase; classtype:trojan-activity; sid:100001726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.249.33.79",nocase; classtype:trojan-activity; sid:100001727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.25.242.211",nocase; classtype:trojan-activity; sid:100001728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.118.86",nocase; classtype:trojan-activity; sid:100001729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.86.128",nocase; classtype:trojan-activity; sid:100001730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.97.76.242",nocase; classtype:trojan-activity; sid:100001731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.145.152.26",nocase; classtype:trojan-activity; sid:100001732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.151.23.172",nocase; classtype:trojan-activity; sid:100001733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.157.97.71",nocase; classtype:trojan-activity; sid:100001734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.16.131.51",nocase; classtype:trojan-activity; sid:100001735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.21.202.98",nocase; classtype:trojan-activity; sid:100001736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.46.231.38",nocase; classtype:trojan-activity; sid:100001737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.162.113",nocase; classtype:trojan-activity; sid:100001738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.87.36",nocase; classtype:trojan-activity; sid:100001739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.143.43.93",nocase; classtype:trojan-activity; sid:100001740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.156.35.166",nocase; classtype:trojan-activity; sid:100001741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.158.201.200",nocase; classtype:trojan-activity; sid:100001742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.158.201.218",nocase; classtype:trojan-activity; sid:100001743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.20.121",nocase; classtype:trojan-activity; sid:100001744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.21.3",nocase; classtype:trojan-activity; sid:100001745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.174.182.99",nocase; classtype:trojan-activity; sid:100001746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.170.49",nocase; classtype:trojan-activity; sid:100001747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.178.183",nocase; classtype:trojan-activity; sid:100001748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.179.129",nocase; classtype:trojan-activity; sid:100001749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.14.122.233",nocase; classtype:trojan-activity; sid:100001750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.188.62.111",nocase; classtype:trojan-activity; sid:100001751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.95.226.154",nocase; classtype:trojan-activity; sid:100001752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.115.174.106",nocase; classtype:trojan-activity; sid:100001753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.121.91.255",nocase; classtype:trojan-activity; sid:100001754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.247.83.66",nocase; classtype:trojan-activity; sid:100001755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.252.47.29",nocase; classtype:trojan-activity; sid:100001756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"51.89.77.2",nocase; classtype:trojan-activity; sid:100001757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.114.136",nocase; classtype:trojan-activity; sid:100001758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.180.122",nocase; classtype:trojan-activity; sid:100001759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.114.246.26",nocase; classtype:trojan-activity; sid:100001760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.162.92",nocase; classtype:trojan-activity; sid:100001761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.174.4",nocase; classtype:trojan-activity; sid:100001762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.125.191.4",nocase; classtype:trojan-activity; sid:100001763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.126.247.118",nocase; classtype:trojan-activity; sid:100001764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.141.122.109",nocase; classtype:trojan-activity; sid:100001765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.166.120",nocase; classtype:trojan-activity; sid:100001766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.200.124",nocase; classtype:trojan-activity; sid:100001767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.218.67.253",nocase; classtype:trojan-activity; sid:100001768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.22.212.107",nocase; classtype:trojan-activity; sid:100001769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.226.129.29",nocase; classtype:trojan-activity; sid:100001770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.230.89.42",nocase; classtype:trojan-activity; sid:100001771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.237.125.4",nocase; classtype:trojan-activity; sid:100001772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.238.42.192",nocase; classtype:trojan-activity; sid:100001773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.240.147.97",nocase; classtype:trojan-activity; sid:100001774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.241.78.55",nocase; classtype:trojan-activity; sid:100001775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.242.91.219",nocase; classtype:trojan-activity; sid:100001776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.73.208",nocase; classtype:trojan-activity; sid:100001777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.75.128",nocase; classtype:trojan-activity; sid:100001778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.80.36",nocase; classtype:trojan-activity; sid:100001779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.252.176.140",nocase; classtype:trojan-activity; sid:100001780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.253.15.184",nocase; classtype:trojan-activity; sid:100001781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.51.219.200",nocase; classtype:trojan-activity; sid:100001782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.153",nocase; classtype:trojan-activity; sid:100001783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.39",nocase; classtype:trojan-activity; sid:100001784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.0.211.161",nocase; classtype:trojan-activity; sid:100001785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.102.168.189",nocase; classtype:trojan-activity; sid:100001786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.126.26.220",nocase; classtype:trojan-activity; sid:100001787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.202.3",nocase; classtype:trojan-activity; sid:100001788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.214.4",nocase; classtype:trojan-activity; sid:100001789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.237.51",nocase; classtype:trojan-activity; sid:100001790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.246.125",nocase; classtype:trojan-activity; sid:100001791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.173.135.51",nocase; classtype:trojan-activity; sid:100001792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.175.63.177",nocase; classtype:trojan-activity; sid:100001793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.23.114.97",nocase; classtype:trojan-activity; sid:100001794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.26.181.228",nocase; classtype:trojan-activity; sid:100001795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.30.12.254",nocase; classtype:trojan-activity; sid:100001796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.60.117.163",nocase; classtype:trojan-activity; sid:100001797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.13.61.12",nocase; classtype:trojan-activity; sid:100001798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.122.57",nocase; classtype:trojan-activity; sid:100001799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.216.23",nocase; classtype:trojan-activity; sid:100001800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.233.94",nocase; classtype:trojan-activity; sid:100001801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.6.112",nocase; classtype:trojan-activity; sid:100001802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.100.83",nocase; classtype:trojan-activity; sid:100001803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.111.39",nocase; classtype:trojan-activity; sid:100001804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.206.246",nocase; classtype:trojan-activity; sid:100001805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.218.31",nocase; classtype:trojan-activity; sid:100001806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.220.167",nocase; classtype:trojan-activity; sid:100001807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.254.178",nocase; classtype:trojan-activity; sid:100001808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.83.55",nocase; classtype:trojan-activity; sid:100001809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.214.85.149",nocase; classtype:trojan-activity; sid:100001810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.177.196",nocase; classtype:trojan-activity; sid:100001811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.86.208",nocase; classtype:trojan-activity; sid:100001812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.220.159.240",nocase; classtype:trojan-activity; sid:100001813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.15.104",nocase; classtype:trojan-activity; sid:100001814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.39.88",nocase; classtype:trojan-activity; sid:100001815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.4.72",nocase; classtype:trojan-activity; sid:100001816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.51.127",nocase; classtype:trojan-activity; sid:100001817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.60.174",nocase; classtype:trojan-activity; sid:100001818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.8.81",nocase; classtype:trojan-activity; sid:100001819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.254.36.135",nocase; classtype:trojan-activity; sid:100001820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.10.121",nocase; classtype:trojan-activity; sid:100001821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.8.43",nocase; classtype:trojan-activity; sid:100001822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.146.108.150",nocase; classtype:trojan-activity; sid:100001823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.91.194",nocase; classtype:trojan-activity; sid:100001824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.247.224.66",nocase; classtype:trojan-activity; sid:100001825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.101.143",nocase; classtype:trojan-activity; sid:100001826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.241.252",nocase; classtype:trojan-activity; sid:100001827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.57.40",nocase; classtype:trojan-activity; sid:100001828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.9.166",nocase; classtype:trojan-activity; sid:100001829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.98.43",nocase; classtype:trojan-activity; sid:100001830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.99.161",nocase; classtype:trojan-activity; sid:100001831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.117.152",nocase; classtype:trojan-activity; sid:100001832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.249.58",nocase; classtype:trojan-activity; sid:100001833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.74.236",nocase; classtype:trojan-activity; sid:100001834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.103.56",nocase; classtype:trojan-activity; sid:100001835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.180.67",nocase; classtype:trojan-activity; sid:100001836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.181.7",nocase; classtype:trojan-activity; sid:100001837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.57.96.116",nocase; classtype:trojan-activity; sid:100001838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.170.60",nocase; classtype:trojan-activity; sid:100001839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.73.220",nocase; classtype:trojan-activity; sid:100001840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.61.218.23",nocase; classtype:trojan-activity; sid:100001841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.65.172.121",nocase; classtype:trojan-activity; sid:100001842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.0.22",nocase; classtype:trojan-activity; sid:100001843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.104.46",nocase; classtype:trojan-activity; sid:100001844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.110.59",nocase; classtype:trojan-activity; sid:100001845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.195",nocase; classtype:trojan-activity; sid:100001846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.255.60",nocase; classtype:trojan-activity; sid:100001847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.45.130",nocase; classtype:trojan-activity; sid:100001848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.98.144.75",nocase; classtype:trojan-activity; sid:100001849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.1.98.131",nocase; classtype:trojan-activity; sid:100001850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.141.73.58",nocase; classtype:trojan-activity; sid:100001851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.131.205",nocase; classtype:trojan-activity; sid:100001852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.143.46",nocase; classtype:trojan-activity; sid:100001853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.31.126.33",nocase; classtype:trojan-activity; sid:100001854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.149.66",nocase; classtype:trojan-activity; sid:100001855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.43.207.148",nocase; classtype:trojan-activity; sid:100001856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.90.165.236",nocase; classtype:trojan-activity; sid:100001857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"63.245.122.93",nocase; classtype:trojan-activity; sid:100001858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"64.233.154.99",nocase; classtype:trojan-activity; sid:100001859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.125.128.196",nocase; classtype:trojan-activity; sid:100001860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.26.155.131",nocase; classtype:trojan-activity; sid:100001861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.35.61.255",nocase; classtype:trojan-activity; sid:100001862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.108.199.144",nocase; classtype:trojan-activity; sid:100001863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.57.55.210",nocase; classtype:trojan-activity; sid:100001864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.74.7.197",nocase; classtype:trojan-activity; sid:100001865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.91.21.31",nocase; classtype:trojan-activity; sid:100001866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.97.181.196",nocase; classtype:trojan-activity; sid:100001867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.245.151.203",nocase; classtype:trojan-activity; sid:100001868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.8.138.101",nocase; classtype:trojan-activity; sid:100001869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.83.49.234",nocase; classtype:trojan-activity; sid:100001870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.84.138.165",nocase; classtype:trojan-activity; sid:100001871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.148.103.248",nocase; classtype:trojan-activity; sid:100001872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.174.182.226",nocase; classtype:trojan-activity; sid:100001873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.175.107.153",nocase; classtype:trojan-activity; sid:100001874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.188.144.143",nocase; classtype:trojan-activity; sid:100001875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.204.88.29",nocase; classtype:trojan-activity; sid:100001876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.119.241",nocase; classtype:trojan-activity; sid:100001877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.78.33.33",nocase; classtype:trojan-activity; sid:100001878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.115.37.205",nocase; classtype:trojan-activity; sid:100001879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.120.237.255",nocase; classtype:trojan-activity; sid:100001880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.123.245.151",nocase; classtype:trojan-activity; sid:100001881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.124.231.110",nocase; classtype:trojan-activity; sid:100001882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.127.214.47",nocase; classtype:trojan-activity; sid:100001883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.146.232.34",nocase; classtype:trojan-activity; sid:100001884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.165.173.49",nocase; classtype:trojan-activity; sid:100001885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.196.158.227",nocase; classtype:trojan-activity; sid:100001886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.222.157.166",nocase; classtype:trojan-activity; sid:100001887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.229.0.133",nocase; classtype:trojan-activity; sid:100001888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.63.73.234",nocase; classtype:trojan-activity; sid:100001889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.115.194",nocase; classtype:trojan-activity; sid:100001890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.227.186",nocase; classtype:trojan-activity; sid:100001891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.76.240.206",nocase; classtype:trojan-activity; sid:100001892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.115.31.30",nocase; classtype:trojan-activity; sid:100001893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.118.240.88",nocase; classtype:trojan-activity; sid:100001894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.167.10.180",nocase; classtype:trojan-activity; sid:100001895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.236.190.250",nocase; classtype:trojan-activity; sid:100001896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.25.5.105",nocase; classtype:trojan-activity; sid:100001897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.93.129.118",nocase; classtype:trojan-activity; sid:100001898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.127.148.69",nocase; classtype:trojan-activity; sid:100001899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.146.190.91",nocase; classtype:trojan-activity; sid:100001900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.204.63.239",nocase; classtype:trojan-activity; sid:100001901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.34.191.213",nocase; classtype:trojan-activity; sid:100001902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.40.234.166",nocase; classtype:trojan-activity; sid:100001903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.106.142",nocase; classtype:trojan-activity; sid:100001904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.2.122",nocase; classtype:trojan-activity; sid:100001905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.235.106",nocase; classtype:trojan-activity; sid:100001906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.47.133.58",nocase; classtype:trojan-activity; sid:100001907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.71.60.69",nocase; classtype:trojan-activity; sid:100001908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.85.106.211",nocase; classtype:trojan-activity; sid:100001909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.17.22.30",nocase; classtype:trojan-activity; sid:100001910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.180.98",nocase; classtype:trojan-activity; sid:100001911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.200.62",nocase; classtype:trojan-activity; sid:100001912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.202.249.109",nocase; classtype:trojan-activity; sid:100001913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.214.69.226",nocase; classtype:trojan-activity; sid:100001914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.229.230.118",nocase; classtype:trojan-activity; sid:100001915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.31.40.122",nocase; classtype:trojan-activity; sid:100001916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.112.123.203",nocase; classtype:trojan-activity; sid:100001917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.204.216.103",nocase; classtype:trojan-activity; sid:100001918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.31.139.77",nocase; classtype:trojan-activity; sid:100001919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.70.164.42",nocase; classtype:trojan-activity; sid:100001920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.101.1.159",nocase; classtype:trojan-activity; sid:100001921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.108.224.112",nocase; classtype:trojan-activity; sid:100001922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.195.115.176",nocase; classtype:trojan-activity; sid:100001923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.199.84.77",nocase; classtype:trojan-activity; sid:100001924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.64.139.223",nocase; classtype:trojan-activity; sid:100001925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.75.165.81",nocase; classtype:trojan-activity; sid:100001926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.127.141.52",nocase; classtype:trojan-activity; sid:100001927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.99.213.61",nocase; classtype:trojan-activity; sid:100001928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.170.11.82",nocase; classtype:trojan-activity; sid:100001929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.178.22.145",nocase; classtype:trojan-activity; sid:100001930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.217.92.231",nocase; classtype:trojan-activity; sid:100001931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.250.199.133",nocase; classtype:trojan-activity; sid:100001932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.254.129.227",nocase; classtype:trojan-activity; sid:100001933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.84.134.33",nocase; classtype:trojan-activity; sid:100001934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.89.107.69",nocase; classtype:trojan-activity; sid:100001935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.95.12.137",nocase; classtype:trojan-activity; sid:100001936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.111.182.31",nocase; classtype:trojan-activity; sid:100001937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.237.25.210",nocase; classtype:trojan-activity; sid:100001938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.50.153",nocase; classtype:trojan-activity; sid:100001939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.89.203.238",nocase; classtype:trojan-activity; sid:100001940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77st.net",nocase; classtype:trojan-activity; sid:100001941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.138.98.134",nocase; classtype:trojan-activity; sid:100001942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.145.224.45",nocase; classtype:trojan-activity; sid:100001943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.141.144",nocase; classtype:trojan-activity; sid:100001944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.41.200",nocase; classtype:trojan-activity; sid:100001945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.106.235",nocase; classtype:trojan-activity; sid:100001946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.168.64",nocase; classtype:trojan-activity; sid:100001947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.188.141",nocase; classtype:trojan-activity; sid:100001948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.104.157",nocase; classtype:trojan-activity; sid:100001949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.176.163",nocase; classtype:trojan-activity; sid:100001950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.27.157",nocase; classtype:trojan-activity; sid:100001951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.23.172.81",nocase; classtype:trojan-activity; sid:100001952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.8.225.77",nocase; classtype:trojan-activity; sid:100001953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.11.195.121",nocase; classtype:trojan-activity; sid:100001954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.147.123.48",nocase; classtype:trojan-activity; sid:100001955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.175.42.244",nocase; classtype:trojan-activity; sid:100001956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.21.84.63",nocase; classtype:trojan-activity; sid:100001957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.7.170.58",nocase; classtype:trojan-activity; sid:100001958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.79.58.94",nocase; classtype:trojan-activity; sid:100001959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.8.70.162",nocase; classtype:trojan-activity; sid:100001960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.9.88.185",nocase; classtype:trojan-activity; sid:100001961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.107.89.207",nocase; classtype:trojan-activity; sid:100001962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.19.101.218",nocase; classtype:trojan-activity; sid:100001963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.211.181.77",nocase; classtype:trojan-activity; sid:100001964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.217.12.7",nocase; classtype:trojan-activity; sid:100001965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.99.128.61",nocase; classtype:trojan-activity; sid:100001966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.136.146.213",nocase; classtype:trojan-activity; sid:100001967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.165.44.109",nocase; classtype:trojan-activity; sid:100001968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.191.40.58",nocase; classtype:trojan-activity; sid:100001969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.198.7.22",nocase; classtype:trojan-activity; sid:100001970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.141.184",nocase; classtype:trojan-activity; sid:100001971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.215.199.29",nocase; classtype:trojan-activity; sid:100001972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.187.113",nocase; classtype:trojan-activity; sid:100001973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.195.216",nocase; classtype:trojan-activity; sid:100001974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.229.230.103",nocase; classtype:trojan-activity; sid:100001975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.244.219.41",nocase; classtype:trojan-activity; sid:100001976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.246.225.203",nocase; classtype:trojan-activity; sid:100001977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.30.177.68",nocase; classtype:trojan-activity; sid:100001978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.92.36.96",nocase; classtype:trojan-activity; sid:100001979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.103.108.72",nocase; classtype:trojan-activity; sid:100001980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.135.196.130",nocase; classtype:trojan-activity; sid:100001981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.212.178",nocase; classtype:trojan-activity; sid:100001982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.85.112",nocase; classtype:trojan-activity; sid:100001983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.207.61.194",nocase; classtype:trojan-activity; sid:100001984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.209.250.155",nocase; classtype:trojan-activity; sid:100001985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.211.156.38",nocase; classtype:trojan-activity; sid:100001986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.59.31.181",nocase; classtype:trojan-activity; sid:100001987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.110.252",nocase; classtype:trojan-activity; sid:100001988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.53.77",nocase; classtype:trojan-activity; sid:100001989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.138.72",nocase; classtype:trojan-activity; sid:100001990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.139.92",nocase; classtype:trojan-activity; sid:100001991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.154.214",nocase; classtype:trojan-activity; sid:100001992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.187.109",nocase; classtype:trojan-activity; sid:100001993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.100.54",nocase; classtype:trojan-activity; sid:100001994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.102.84",nocase; classtype:trojan-activity; sid:100001995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.106.65",nocase; classtype:trojan-activity; sid:100001996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.108.172",nocase; classtype:trojan-activity; sid:100001997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.131.158",nocase; classtype:trojan-activity; sid:100001998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.134.66",nocase; classtype:trojan-activity; sid:100001999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.19.42",nocase; classtype:trojan-activity; sid:100002000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.197.254",nocase; classtype:trojan-activity; sid:100002001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.215.149",nocase; classtype:trojan-activity; sid:100002002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.232.68",nocase; classtype:trojan-activity; sid:100002003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.234.195",nocase; classtype:trojan-activity; sid:100002004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.246.96",nocase; classtype:trojan-activity; sid:100002005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.28.57",nocase; classtype:trojan-activity; sid:100002006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.4.57",nocase; classtype:trojan-activity; sid:100002007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.55.84",nocase; classtype:trojan-activity; sid:100002008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.73.245",nocase; classtype:trojan-activity; sid:100002009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.98.51",nocase; classtype:trojan-activity; sid:100002010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.165.237.163",nocase; classtype:trojan-activity; sid:100002011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.147.99",nocase; classtype:trojan-activity; sid:100002012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.218.42",nocase; classtype:trojan-activity; sid:100002013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.242.253.154",nocase; classtype:trojan-activity; sid:100002014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.252.9.37",nocase; classtype:trojan-activity; sid:100002015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.210.219.213",nocase; classtype:trojan-activity; sid:100002016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.50.118",nocase; classtype:trojan-activity; sid:100002017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.95.204",nocase; classtype:trojan-activity; sid:100002018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.238.24.35",nocase; classtype:trojan-activity; sid:100002019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.247.83.74",nocase; classtype:trojan-activity; sid:100002020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.254.39.129",nocase; classtype:trojan-activity; sid:100002021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.33.111.227",nocase; classtype:trojan-activity; sid:100002022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.40.127.242",nocase; classtype:trojan-activity; sid:100002023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.42.20.217",nocase; classtype:trojan-activity; sid:100002024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com",nocase; classtype:trojan-activity; sid:100002025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.11.216",nocase; classtype:trojan-activity; sid:100002026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.123.251",nocase; classtype:trojan-activity; sid:100002027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.135.187",nocase; classtype:trojan-activity; sid:100002028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.180.33",nocase; classtype:trojan-activity; sid:100002029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.208.25",nocase; classtype:trojan-activity; sid:100002030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.224.141",nocase; classtype:trojan-activity; sid:100002031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.241.2",nocase; classtype:trojan-activity; sid:100002032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.108.133.19",nocase; classtype:trojan-activity; sid:100002033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.214.149.236",nocase; classtype:trojan-activity; sid:100002034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.241.39.182",nocase; classtype:trojan-activity; sid:100002035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.64.181.50",nocase; classtype:trojan-activity; sid:100002036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.74.215.180",nocase; classtype:trojan-activity; sid:100002037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.130.227",nocase; classtype:trojan-activity; sid:100002038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"86.35.43.220",nocase; classtype:trojan-activity; sid:100002039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.172.19.130",nocase; classtype:trojan-activity; sid:100002040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87du.vip",nocase; classtype:trojan-activity; sid:100002041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.119.171.253",nocase; classtype:trojan-activity; sid:100002042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.129.208.43",nocase; classtype:trojan-activity; sid:100002043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.208.71",nocase; classtype:trojan-activity; sid:100002044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.219.179",nocase; classtype:trojan-activity; sid:100002045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.218.17.149",nocase; classtype:trojan-activity; sid:100002046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.225.222.128",nocase; classtype:trojan-activity; sid:100002047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.247.96.19",nocase; classtype:trojan-activity; sid:100002048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.51.139",nocase; classtype:trojan-activity; sid:100002049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.249.13.164",nocase; classtype:trojan-activity; sid:100002050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.249.244.180",nocase; classtype:trojan-activity; sid:100002051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.204.12",nocase; classtype:trojan-activity; sid:100002052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.226.26",nocase; classtype:trojan-activity; sid:100002053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.240.245",nocase; classtype:trojan-activity; sid:100002054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.254.90",nocase; classtype:trojan-activity; sid:100002055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.122.183.130",nocase; classtype:trojan-activity; sid:100002056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.136.197.170",nocase; classtype:trojan-activity; sid:100002057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.22.152.244",nocase; classtype:trojan-activity; sid:100002058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.237.84.19",nocase; classtype:trojan-activity; sid:100002059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.248.112.202",nocase; classtype:trojan-activity; sid:100002060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.29.213.33",nocase; classtype:trojan-activity; sid:100002061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.85.166",nocase; classtype:trojan-activity; sid:100002062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.87.5",nocase; classtype:trojan-activity; sid:100002063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8poieq.bn.files.1drv.com",nocase; classtype:trojan-activity; sid:100002064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"90.152.144.139",nocase; classtype:trojan-activity; sid:100002065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.132.197.39",nocase; classtype:trojan-activity; sid:100002066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.138.215.5",nocase; classtype:trojan-activity; sid:100002067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.177.139.132",nocase; classtype:trojan-activity; sid:100002068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.187.103.32",nocase; classtype:trojan-activity; sid:100002069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.212.150.241",nocase; classtype:trojan-activity; sid:100002070; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.217.104.185",nocase; classtype:trojan-activity; sid:100002071; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.233.112.188",nocase; classtype:trojan-activity; sid:100002072; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.234.60.94",nocase; classtype:trojan-activity; sid:100002073; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.244.169.139",nocase; classtype:trojan-activity; sid:100002074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.92.16.244",nocase; classtype:trojan-activity; sid:100002075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.114.191.82",nocase; classtype:trojan-activity; sid:100002076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.241.78.114",nocase; classtype:trojan-activity; sid:100002077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.27.246.202",nocase; classtype:trojan-activity; sid:100002078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.54.237.237",nocase; classtype:trojan-activity; sid:100002079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.83.62.139",nocase; classtype:trojan-activity; sid:100002080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.85.18.138",nocase; classtype:trojan-activity; sid:100002081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.159.169.190",nocase; classtype:trojan-activity; sid:100002082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.173.235.110",nocase; classtype:trojan-activity; sid:100002083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.21.224.154",nocase; classtype:trojan-activity; sid:100002084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.39.115.176",nocase; classtype:trojan-activity; sid:100002085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.39.79.41",nocase; classtype:trojan-activity; sid:100002086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.137.16",nocase; classtype:trojan-activity; sid:100002087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.182.249",nocase; classtype:trojan-activity; sid:100002088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.206.56",nocase; classtype:trojan-activity; sid:100002089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.57.43.233",nocase; classtype:trojan-activity; sid:100002090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.73.99.102",nocase; classtype:trojan-activity; sid:100002091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.136.69.199",nocase; classtype:trojan-activity; sid:100002092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.143.53.34",nocase; classtype:trojan-activity; sid:100002093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.17.170",nocase; classtype:trojan-activity; sid:100002094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.200.16.22",nocase; classtype:trojan-activity; sid:100002095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.224.83.208",nocase; classtype:trojan-activity; sid:100002096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.53.120.109",nocase; classtype:trojan-activity; sid:100002097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.85.0.3",nocase; classtype:trojan-activity; sid:100002098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.132.129.250",nocase; classtype:trojan-activity; sid:100002099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.133.158.20",nocase; classtype:trojan-activity; sid:100002100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.154.20.231",nocase; classtype:trojan-activity; sid:100002101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.158.19.130",nocase; classtype:trojan-activity; sid:100002102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.113.227",nocase; classtype:trojan-activity; sid:100002103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.201.34",nocase; classtype:trojan-activity; sid:100002104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.60.146.134",nocase; classtype:trojan-activity; sid:100002105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.66.196.63",nocase; classtype:trojan-activity; sid:100002106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.9.111.51",nocase; classtype:trojan-activity; sid:100002107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.9.120.40",nocase; classtype:trojan-activity; sid:100002108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.239.73.246",nocase; classtype:trojan-activity; sid:100002109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.47.147.169",nocase; classtype:trojan-activity; sid:100002110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.68.140.254",nocase; classtype:trojan-activity; sid:100002111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.96.199.75",nocase; classtype:trojan-activity; sid:100002112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.0.210.218",nocase; classtype:trojan-activity; sid:100002113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.113.239.207",nocase; classtype:trojan-activity; sid:100002114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.116.72.119",nocase; classtype:trojan-activity; sid:100002115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.128.147.115",nocase; classtype:trojan-activity; sid:100002116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.178.242.44",nocase; classtype:trojan-activity; sid:100002117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.30.24.54",nocase; classtype:trojan-activity; sid:100002118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.150.245.203",nocase; classtype:trojan-activity; sid:100002119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.33.195.164",nocase; classtype:trojan-activity; sid:100002120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"a.stro.lo.gy.t.em.r@zytrox.tk",nocase; classtype:trojan-activity; sid:100002121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aatreefelling.co.za",nocase; classtype:trojan-activity; sid:100002122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abcd.bg",nocase; classtype:trojan-activity; sid:100002123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abissnet.net",nocase; classtype:trojan-activity; sid:100002124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aboveandbelow.com.au",nocase; classtype:trojan-activity; sid:100002125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absoftechworld.com",nocase; classtype:trojan-activity; sid:100002126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abyssos.eu",nocase; classtype:trojan-activity; sid:100002127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"academyshademani.com",nocase; classtype:trojan-activity; sid:100002128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acbick.com",nocase; classtype:trojan-activity; sid:100002129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"accesslinksgroup.com",nocase; classtype:trojan-activity; sid:100002130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acellr.co.uk",nocase; classtype:trojan-activity; sid:100002131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acteon.com.ar",nocase; classtype:trojan-activity; sid:100002132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"addahealingmusic.com",nocase; classtype:trojan-activity; sid:100002133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.com",nocase; classtype:trojan-activity; sid:100002134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.memengers.com",nocase; classtype:trojan-activity; sid:100002135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.erapor.smk-alasror.net",nocase; classtype:trojan-activity; sid:100002136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.gentbcn.org",nocase; classtype:trojan-activity; sid:100002137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.grandoceanvilla.com",nocase; classtype:trojan-activity; sid:100002138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admission.kmctartskuttippuram.org",nocase; classtype:trojan-activity; sid:100002139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adventureexplorer.in",nocase; classtype:trojan-activity; sid:100002140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aeropilates.cl",nocase; classtype:trojan-activity; sid:100002141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afnan-amc.com",nocase; classtype:trojan-activity; sid:100002142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afrimedspecialist.com",nocase; classtype:trojan-activity; sid:100002143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agemn.co.za",nocase; classtype:trojan-activity; sid:100002144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenciadigitalwdys.com",nocase; classtype:trojan-activity; sid:100002145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenda.gmelloinformatica.com.br",nocase; classtype:trojan-activity; sid:100002146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agentt.ac.ug",nocase; classtype:trojan-activity; sid:100002147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agile8studio.com",nocase; classtype:trojan-activity; sid:100002148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aiecons.com",nocase; classtype:trojan-activity; sid:100002149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aiqtest.com",nocase; classtype:trojan-activity; sid:100002150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajpharmaholding.com",nocase; classtype:trojan-activity; sid:100002151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"akdvidyalaya.com",nocase; classtype:trojan-activity; sid:100002152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alasdemariposas.org",nocase; classtype:trojan-activity; sid:100002153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alberts.diamondrelationscrm.us",nocase; classtype:trojan-activity; sid:100002154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alemelektronik.com",nocase; classtype:trojan-activity; sid:100002155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alena1971.es",nocase; classtype:trojan-activity; sid:100002156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alexdubai.com.aldiabsteel.com",nocase; classtype:trojan-activity; sid:100002157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alka.institute",nocase; classtype:trojan-activity; sid:100002158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"allforcreative.com.au",nocase; classtype:trojan-activity; sid:100002159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alltheway.travel",nocase; classtype:trojan-activity; sid:100002160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alpaylar.com.tr",nocase; classtype:trojan-activity; sid:100002161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alumni.hildred.ibbott@46.249.33.79",nocase; classtype:trojan-activity; sid:100002162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"am-concepts.ca",nocase; classtype:trojan-activity; sid:100002163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarresdeamorymaestroshechiceros.com",nocase; classtype:trojan-activity; sid:100002164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarteargentina.com.ar",nocase; classtype:trojan-activity; sid:100002165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amos524.org",nocase; classtype:trojan-activity; sid:100002166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ams.alvinasschools.org.ng",nocase; classtype:trojan-activity; sid:100002167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anadelgbt.org",nocase; classtype:trojan-activity; sid:100002168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anantam.net.in",nocase; classtype:trojan-activity; sid:100002169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreelapeyre.com",nocase; classtype:trojan-activity; sid:100002170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andremaraisbeleggings.co.za",nocase; classtype:trojan-activity; sid:100002171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ac.ug",nocase; classtype:trojan-activity; sid:100002172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ug",nocase; classtype:trojan-activity; sid:100002173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreshconcejal.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelsdetour.com",nocase; classtype:trojan-activity; sid:100002175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anurontv.com",nocase; classtype:trojan-activity; sid:100002176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anysbergbiltong.co.za",nocase; classtype:trojan-activity; sid:100002177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apartamentoscitta.com",nocase; classtype:trojan-activity; sid:100002178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api-ms.cobainaja.id",nocase; classtype:trojan-activity; sid:100002179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.cstdevs.com",nocase; classtype:trojan-activity; sid:100002180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apoolcondo.com",nocase; classtype:trojan-activity; sid:100002181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.adsensearticle.com",nocase; classtype:trojan-activity; sid:100002182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.explicitsurveys.co.uk",nocase; classtype:trojan-activity; sid:100002183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.prerana.info",nocase; classtype:trojan-activity; sid:100002184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apps.saintsoporte.com",nocase; classtype:trojan-activity; sid:100002185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aps-scribe.com",nocase; classtype:trojan-activity; sid:100002186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aps-sv.com",nocase; classtype:trojan-activity; sid:100002187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"artedibujoyarquitectura.com",nocase; classtype:trojan-activity; sid:100002188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"arwenyapi.com",nocase; classtype:trojan-activity; sid:100002189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ask-regard.call-save.biz",nocase; classtype:trojan-activity; sid:100002190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"asucssa.live",nocase; classtype:trojan-activity; sid:100002191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atfile.com",nocase; classtype:trojan-activity; sid:100002192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"athenacapsg.com",nocase; classtype:trojan-activity; sid:100002193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atlasconcreteworks.com",nocase; classtype:trojan-activity; sid:100002194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"attach.66rpg.com",nocase; classtype:trojan-activity; sid:100002195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atteuqpotentialunlimited.com",nocase; classtype:trojan-activity; sid:100002196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"augustair.com",nocase; classtype:trojan-activity; sid:100002197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aulist.com",nocase; classtype:trojan-activity; sid:100002198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"australianpga.com.au",nocase; classtype:trojan-activity; sid:100002199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"automaticrefreshments.com",nocase; classtype:trojan-activity; sid:100002200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"avadhanagames.com",nocase; classtype:trojan-activity; sid:100002201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aventuramotorhome.com",nocase; classtype:trojan-activity; sid:100002202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ayahuascasp.com.br",nocase; classtype:trojan-activity; sid:100002203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ayamallah.com",nocase; classtype:trojan-activity; sid:100002204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aycconsultoriaempresarial.com",nocase; classtype:trojan-activity; sid:100002205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azmeasurement.com",nocase; classtype:trojan-activity; sid:100002206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azraktours.com",nocase; classtype:trojan-activity; sid:100002207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"b.r.uce.lee.b.es.t@zytrox.tk",nocase; classtype:trojan-activity; sid:100002208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"b2b.toptanakaryakit.com.tr",nocase; classtype:trojan-activity; sid:100002209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"backgrounds.pk",nocase; classtype:trojan-activity; sid:100002210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"badeggdesign.com",nocase; classtype:trojan-activity; sid:100002211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"balealgodon.mx",nocase; classtype:trojan-activity; sid:100002212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bangkok-orchids.com",nocase; classtype:trojan-activity; sid:100002213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bangladeshunbound.com",nocase; classtype:trojan-activity; sid:100002214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bary.sz4h.com",nocase; classtype:trojan-activity; sid:100002215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bash.givemexyz.in",nocase; classtype:trojan-activity; sid:100002216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk",nocase; classtype:trojan-activity; sid:100002217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bavhome.com",nocase; classtype:trojan-activity; sid:100002218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bbia.co.uk",nocase; classtype:trojan-activity; sid:100002219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcmt.elin.co.za",nocase; classtype:trojan-activity; sid:100002220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcrg.co.za",nocase; classtype:trojan-activity; sid:100002221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bdnextrend.xyz",nocase; classtype:trojan-activity; sid:100002222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beanx88.xyz",nocase; classtype:trojan-activity; sid:100002223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bearcatpumps.com.cn",nocase; classtype:trojan-activity; sid:100002224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beautincollagen.rs",nocase; classtype:trojan-activity; sid:100002225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beautymomentsgt.de",nocase; classtype:trojan-activity; sid:100002226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bekape.co.id",nocase; classtype:trojan-activity; sid:100002227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beor360.com",nocase; classtype:trojan-activity; sid:100002228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bespokeweddings.ie",nocase; classtype:trojan-activity; sid:100002229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bestcarenepal.com",nocase; classtype:trojan-activity; sid:100002230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betone.co.kr",nocase; classtype:trojan-activity; sid:100002231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betycopaints.com",nocase; classtype:trojan-activity; sid:100002232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beveragesmiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bhavaniengineering.com",nocase; classtype:trojan-activity; sid:100002234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bigmikesupplies.co.za",nocase; classtype:trojan-activity; sid:100002235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilbosaquet.ug",nocase; classtype:trojan-activity; sid:100002236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilhen.co.za",nocase; classtype:trojan-activity; sid:100002237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"billing.rahitechnosoft.com",nocase; classtype:trojan-activity; sid:100002238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"binoy.stalphonsamissionva.org",nocase; classtype:trojan-activity; sid:100002239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"biometrico.gpotecnosystems.com",nocase; classtype:trojan-activity; sid:100002240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bioskey.com",nocase; classtype:trojan-activity; sid:100002241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birdi.elin.co.za",nocase; classtype:trojan-activity; sid:100002242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birminghamlink.org",nocase; classtype:trojan-activity; sid:100002243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bizztradingbot.nl",nocase; classtype:trojan-activity; sid:100002244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bl4n3.zadns.co.za",nocase; classtype:trojan-activity; sid:100002245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.callensaxen.com",nocase; classtype:trojan-activity; sid:100002246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.difusodesign.com",nocase; classtype:trojan-activity; sid:100002247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.oyinblogs.com",nocase; classtype:trojan-activity; sid:100002248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.takbelit.com",nocase; classtype:trojan-activity; sid:100002249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bmlifestyle.co.uk",nocase; classtype:trojan-activity; sid:100002250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"boatpecas.com.br",nocase; classtype:trojan-activity; sid:100002251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bodenstein.co.za",nocase; classtype:trojan-activity; sid:100002252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bodylanguage.santulan.co.in",nocase; classtype:trojan-activity; sid:100002253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"booksearch.com",nocase; classtype:trojan-activity; sid:100002254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bophelocare.co.za",nocase; classtype:trojan-activity; sid:100002255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bounces.mi-fs.com",nocase; classtype:trojan-activity; sid:100002256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"boutiqueofferte.com",nocase; classtype:trojan-activity; sid:100002257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bpo.correct.go.th",nocase; classtype:trojan-activity; sid:100002258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bradleyinstitute.co.za",nocase; classtype:trojan-activity; sid:100002259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brandtrust.com.pk",nocase; classtype:trojan-activity; sid:100002260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"braunfinancial.com.au",nocase; classtype:trojan-activity; sid:100002261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brendanquine.com",nocase; classtype:trojan-activity; sid:100002262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brideofmessiah.com",nocase; classtype:trojan-activity; sid:100002263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightaffiliatesales.org",nocase; classtype:trojan-activity; sid:100002264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightmega.com",nocase; classtype:trojan-activity; sid:100002265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightstarshop.com",nocase; classtype:trojan-activity; sid:100002266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"browardinsurancemiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bt2.elin.co.za",nocase; classtype:trojan-activity; sid:100002268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"btdapi.robotake.com",nocase; classtype:trojan-activity; sid:100002269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buigiaphat.com.vn",nocase; classtype:trojan-activity; sid:100002270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bullseyemedia.in",nocase; classtype:trojan-activity; sid:100002271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"busandvanrentalmalaysia.com",nocase; classtype:trojan-activity; sid:100002272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buscascolegios.diit.cl",nocase; classtype:trojan-activity; sid:100002273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"business.softberg.ro",nocase; classtype:trojan-activity; sid:100002274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"business2.softberg.ro",nocase; classtype:trojan-activity; sid:100002275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c.ompact.i.o.np.d.yu@zytrox.tk",nocase; classtype:trojan-activity; sid:100002276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c.oooooooooo.ga",nocase; classtype:trojan-activity; sid:100002277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c0140529.ferozo.com",nocase; classtype:trojan-activity; sid:100002278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"caballo.com.au",nocase; classtype:trojan-activity; sid:100002279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cacaoprojects.com",nocase; classtype:trojan-activity; sid:100002280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"calgaryautorepairservice.com",nocase; classtype:trojan-activity; sid:100002281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"callbury.in",nocase; classtype:trojan-activity; sid:100002282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"camminachetipassa.it",nocase; classtype:trojan-activity; sid:100002283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"canadianwork.cc",nocase; classtype:trojan-activity; sid:100002284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capitalgroup-kw.com",nocase; classtype:trojan-activity; sid:100002285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capoeiraventrelivre.com",nocase; classtype:trojan-activity; sid:100002286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cashyinvestment.org",nocase; classtype:trojan-activity; sid:100002287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"catchpoolshetlands.co.uk",nocase; classtype:trojan-activity; sid:100002288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cazyacustomfurniture.com",nocase; classtype:trojan-activity; sid:100002289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cbn.hypervoizd.com",nocase; classtype:trojan-activity; sid:100002290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ccauthority.net",nocase; classtype:trojan-activity; sid:100002291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdaonline.com.ar",nocase; classtype:trojan-activity; sid:100002292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn-10049480.file.myqcloud.com",nocase; classtype:trojan-activity; sid:100002293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cec.asso.ac-amiens.fr",nocase; classtype:trojan-activity; sid:100002294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cellas.sk",nocase; classtype:trojan-activity; sid:100002295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cendekiabinaaksara.com",nocase; classtype:trojan-activity; sid:100002296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cfs5.tistory.com",nocase; classtype:trojan-activity; sid:100002297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ch.rmu.ac.th",nocase; classtype:trojan-activity; sid:100002298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"changematterscounselling.com",nocase; classtype:trojan-activity; sid:100002299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chardhamdodham.com",nocase; classtype:trojan-activity; sid:100002300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chezalice.co.za",nocase; classtype:trojan-activity; sid:100002301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"childselect.com",nocase; classtype:trojan-activity; sid:100002302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile.myvnc.com",nocase; classtype:trojan-activity; sid:100002303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile80.myvnc.com",nocase; classtype:trojan-activity; sid:100002304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cible-energy.com",nocase; classtype:trojan-activity; sid:100002305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cifeer.net",nocase; classtype:trojan-activity; sid:100002306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citihits.lk",nocase; classtype:trojan-activity; sid:100002307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citssolutions.co.za",nocase; classtype:trojan-activity; sid:100002308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citycapproperty.ru",nocase; classtype:trojan-activity; sid:100002309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cityglobalgospel.com",nocase; classtype:trojan-activity; sid:100002310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"civi.istmejia.com",nocase; classtype:trojan-activity; sid:100002311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cleanbydesignllc.com",nocase; classtype:trojan-activity; sid:100002312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloud.fc.co.mz",nocase; classtype:trojan-activity; sid:100002313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cnc.tacobelllover.tk",nocase; classtype:trojan-activity; sid:100002314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codsambal.com",nocase; classtype:trojan-activity; sid:100002315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colinde.pricesne.com",nocase; classtype:trojan-activity; sid:100002316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colorpak.pl",nocase; classtype:trojan-activity; sid:100002317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"community.reimclub.com",nocase; classtype:trojan-activity; sid:100002318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"competancy.indigoconsult.net",nocase; classtype:trojan-activity; sid:100002319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"conceptimagine.ro",nocase; classtype:trojan-activity; sid:100002320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"config.cqhbkjzx.com",nocase; classtype:trojan-activity; sid:100002321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"connectcapital.com.br",nocase; classtype:trojan-activity; sid:100002322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"constructoralyon.com",nocase; classtype:trojan-activity; sid:100002323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"consulateins.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"contributeindustry.com",nocase; classtype:trojan-activity; sid:100002325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"copelandscapes.com",nocase; classtype:trojan-activity; sid:100002326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"coulsongraphics.com",nocase; classtype:trojan-activity; sid:100002327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"count.mail.163.com.impactmedfoundation.com",nocase; classtype:trojan-activity; sid:100002328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"covid19.cyberschool.or.id",nocase; classtype:trojan-activity; sid:100002329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cr-sq.com",nocase; classtype:trojan-activity; sid:100002330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"craftech.nxtnet.ga",nocase; classtype:trojan-activity; sid:100002331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crearechile.cl",nocase; classtype:trojan-activity; sid:100002332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"creationskateboards.com",nocase; classtype:trojan-activity; sid:100002333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crecerco.com",nocase; classtype:trojan-activity; sid:100002334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crittersbythebay.com",nocase; classtype:trojan-activity; sid:100002335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crm.notariavieitoyvelamazan.com",nocase; classtype:trojan-activity; sid:100002336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crmfarko.manivelasst.com",nocase; classtype:trojan-activity; sid:100002337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crmroche.manivelasst.com",nocase; classtype:trojan-activity; sid:100002338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crscorretordeimoveis.com.br",nocase; classtype:trojan-activity; sid:100002339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cse-engineer.com",nocase; classtype:trojan-activity; sid:100002340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"csnserver.com",nocase; classtype:trojan-activity; sid:100002341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cubescargoexpress.com",nocase; classtype:trojan-activity; sid:100002342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"curasoles.co.za",nocase; classtype:trojan-activity; sid:100002343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"currantmedia.com",nocase; classtype:trojan-activity; sid:100002344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cwa.mx",nocase; classtype:trojan-activity; sid:100002345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cyclomove.com",nocase; classtype:trojan-activity; sid:100002346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cynkon.kairoscs.net",nocase; classtype:trojan-activity; sid:100002347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"czsl.91756.cn",nocase; classtype:trojan-activity; sid:100002348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d.powerofwish.com",nocase; classtype:trojan-activity; sid:100002349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d9.99ddd.com",nocase; classtype:trojan-activity; sid:100002350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"da.alibuf.com",nocase; classtype:trojan-activity; sid:100002351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"danaevara.com",nocase; classtype:trojan-activity; sid:100002352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dartoonpictures.com",nocase; classtype:trojan-activity; sid:100002353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.cdevelop.org",nocase; classtype:trojan-activity; sid:100002354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.over-blog-kiwi.com",nocase; classtype:trojan-activity; sid:100002355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datapolish.com",nocase; classtype:trojan-activity; sid:100002356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dating.khokhas.co.za",nocase; classtype:trojan-activity; sid:100002357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datsom.vn",nocase; classtype:trojan-activity; sid:100002358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davethompson.me.uk",nocase; classtype:trojan-activity; sid:100002359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davidmcguinness.info",nocase; classtype:trojan-activity; sid:100002360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dayspringdaisies.com",nocase; classtype:trojan-activity; sid:100002361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dd.qiyuea.cn",nocase; classtype:trojan-activity; sid:100002362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"de.gsearch.com.de",nocase; classtype:trojan-activity; sid:100002363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"decifrar.com.br",nocase; classtype:trojan-activity; sid:100002364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deigratia2.elin.co.za",nocase; classtype:trojan-activity; sid:100002365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dekovizyon.com",nocase; classtype:trojan-activity; sid:100002366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo-cliente.mindcreative.com.br",nocase; classtype:trojan-activity; sid:100002367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo.glassforcars.com.au",nocase; classtype:trojan-activity; sid:100002368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo6.hiites.com",nocase; classtype:trojan-activity; sid:100002369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dent-estet.com",nocase; classtype:trojan-activity; sid:100002370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dental.xiaoxiao.media",nocase; classtype:trojan-activity; sid:100002371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dentalalliance.se",nocase; classtype:trojan-activity; sid:100002372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"desertlandtrd.com",nocase; classtype:trojan-activity; sid:100002373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"designerliving.co.za",nocase; classtype:trojan-activity; sid:100002374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"despertaresi.com.br",nocase; classtype:trojan-activity; sid:100002375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"destinymc.co.za",nocase; classtype:trojan-activity; sid:100002376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"detorre.es",nocase; classtype:trojan-activity; sid:100002377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.sebpo.net",nocase; classtype:trojan-activity; sid:100002378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.watch-store.eu",nocase; classtype:trojan-activity; sid:100002379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dezcom.com",nocase; classtype:trojan-activity; sid:100002380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfcf.91756.cn",nocase; classtype:trojan-activity; sid:100002381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"diamantenegro.mi-fs.com",nocase; classtype:trojan-activity; sid:100002382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dienmayminhhung.com",nocase; classtype:trojan-activity; sid:100002383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digilib.dianhusada.ac.id",nocase; classtype:trojan-activity; sid:100002384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digisails.org",nocase; classtype:trojan-activity; sid:100002385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"disinfection-cleaning.co.za",nocase; classtype:trojan-activity; sid:100002386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"djking.f3322.net",nocase; classtype:trojan-activity; sid:100002387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.1003b.56a.com",nocase; classtype:trojan-activity; sid:100002388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.198424.com",nocase; classtype:trojan-activity; sid:100002389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.installcdn-aws.com",nocase; classtype:trojan-activity; sid:100002390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.packetstormsecurity.net",nocase; classtype:trojan-activity; sid:100002391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.rina-roleplay.com",nocase; classtype:trojan-activity; sid:100002392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dnn.alibuf.com",nocase; classtype:trojan-activity; sid:100002393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dns.alibuf.com",nocase; classtype:trojan-activity; sid:100002394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dockerupdate.anondns.net",nocase; classtype:trojan-activity; sid:100002395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docman.orientalservices.in",nocase; classtype:trojan-activity; sid:100002396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dodsonimaging.com",nocase; classtype:trojan-activity; sid:100002397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"doitunlimited.com",nocase; classtype:trojan-activity; sid:100002398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dokan.blueberrytec.com",nocase; classtype:trojan-activity; sid:100002399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom.daf.free.fr",nocase; classtype:trojan-activity; sid:100002400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"doncedyhall.com",nocase; classtype:trojan-activity; sid:100002401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donghobinhminh.com",nocase; classtype:trojan-activity; sid:100002402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dongphuctop.com",nocase; classtype:trojan-activity; sid:100002403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosman.pl",nocase; classtype:trojan-activity; sid:100002404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dovberger.com",nocase; classtype:trojan-activity; sid:100002405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.pcclear.com",nocase; classtype:trojan-activity; sid:100002406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.udashi.com",nocase; classtype:trojan-activity; sid:100002407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.webbora.com",nocase; classtype:trojan-activity; sid:100002408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down1.arpun.com",nocase; classtype:trojan-activity; sid:100002409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.caihong.com",nocase; classtype:trojan-activity; sid:100002410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.doumaibiji.cn",nocase; classtype:trojan-activity; sid:100002411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.exrnybuf.cn",nocase; classtype:trojan-activity; sid:100002412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.kaobeitu.com",nocase; classtype:trojan-activity; sid:100002413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.pdf00.cn",nocase; classtype:trojan-activity; sid:100002414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.rising.com.cn",nocase; classtype:trojan-activity; sid:100002415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.skycn.com",nocase; classtype:trojan-activity; sid:100002416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.zjsyawqj.cn",nocase; classtype:trojan-activity; sid:100002417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dragonsknot.com",nocase; classtype:trojan-activity; sid:100002418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drbaby.com.sa",nocase; classtype:trojan-activity; sid:100002419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dream.pics",nocase; classtype:trojan-activity; sid:100002420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drgroup.co.za",nocase; classtype:trojan-activity; sid:100002421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drools-moved.46999.n3.nabble.com",nocase; classtype:trojan-activity; sid:100002422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drsha.innovativesolutions.mobi",nocase; classtype:trojan-activity; sid:100002423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsenterprize.co.za",nocase; classtype:trojan-activity; sid:100002424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsspainting.com",nocase; classtype:trojan-activity; sid:100002425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"du-wizards.com",nocase; classtype:trojan-activity; sid:100002426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duque.guantanameratravel.com",nocase; classtype:trojan-activity; sid:100002427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dutapp.wisolve.co.za",nocase; classtype:trojan-activity; sid:100002428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duvalcharter.dekitout.com",nocase; classtype:trojan-activity; sid:100002429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dw2.co.id",nocase; classtype:trojan-activity; sid:100002430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dx.qqyewu.com",nocase; classtype:trojan-activity; sid:100002431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dzinestudio87.co.uk",nocase; classtype:trojan-activity; sid:100002432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-commerce.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100002433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e.sldov.ru",nocase; classtype:trojan-activity; sid:100002434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eandgdesign.com.ng",nocase; classtype:trojan-activity; sid:100002435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ebruyatkin.com",nocase; classtype:trojan-activity; sid:100002436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"edu.saicraftsman.com",nocase; classtype:trojan-activity; sid:100002437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"efficientegroup.com",nocase; classtype:trojan-activity; sid:100002438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"elbauldenora.com",nocase; classtype:trojan-activity; sid:100002439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"emaids.co.za",nocase; classtype:trojan-activity; sid:100002440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"emaz.pk",nocase; classtype:trojan-activity; sid:100002441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"en.baoend.com",nocase; classtype:trojan-activity; sid:100002442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enc-tech.com",nocase; classtype:trojan-activity; sid:100002443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"endurotanzania.co.tz",nocase; classtype:trojan-activity; sid:100002444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ennovate.elin.co.za",nocase; classtype:trojan-activity; sid:100002445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"equimination.ee",nocase; classtype:trojan-activity; sid:100002446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"erp.nanotechproautocare.com",nocase; classtype:trojan-activity; sid:100002447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"escola.probommar.org.br",nocase; classtype:trojan-activity; sid:100002448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eservices.immigration.gov.lk",nocase; classtype:trojan-activity; sid:100002449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"esnconsultants.com",nocase; classtype:trojan-activity; sid:100002450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"essentia.org.br",nocase; classtype:trojan-activity; sid:100002451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ethereality.info",nocase; classtype:trojan-activity; sid:100002452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eubanks7.com",nocase; classtype:trojan-activity; sid:100002453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"europeanzonexxi.com",nocase; classtype:trojan-activity; sid:100002454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exilum.com",nocase; classtype:trojan-activity; sid:100002455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exitoalfaomega.co",nocase; classtype:trojan-activity; sid:100002456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"extrovertoffers.com",nocase; classtype:trojan-activity; sid:100002457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"f1sol.com",nocase; classtype:trojan-activity; sid:100002458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"familydentist.site",nocase; classtype:trojan-activity; sid:100002459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"faveraprojects.com",nocase; classtype:trojan-activity; sid:100002460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fc.co.mz",nocase; classtype:trojan-activity; sid:100002461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"felicienne.nl",nocase; classtype:trojan-activity; sid:100002462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.martellexpress.us",nocase; classtype:trojan-activity; sid:100002463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files6.uludagbilisim.com",nocase; classtype:trojan-activity; sid:100002464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"final.makkahkmcc.com",nocase; classtype:trojan-activity; sid:100002465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fineartgallerym.com",nocase; classtype:trojan-activity; sid:100002466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fisconline.bar",nocase; classtype:trojan-activity; sid:100002467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fisconline.casa",nocase; classtype:trojan-activity; sid:100002468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fix-america-now.org",nocase; classtype:trojan-activity; sid:100002469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fixauto.illumetechnology.com",nocase; classtype:trojan-activity; sid:100002470; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flexypay.dsquaregroup.com",nocase; classtype:trojan-activity; sid:100002471; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flintspin.com",nocase; classtype:trojan-activity; sid:100002472; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flyingbuddhadesign.com",nocase; classtype:trojan-activity; sid:100002473; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fmjplastering.co.uk",nocase; classtype:trojan-activity; sid:100002474; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"follower.instantcashback.in",nocase; classtype:trojan-activity; sid:100002475; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foothills.com.br",nocase; classtype:trojan-activity; sid:100002476; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"footweardirect.elin.co.za",nocase; classtype:trojan-activity; sid:100002477; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"forum.mdb.nu",nocase; classtype:trojan-activity; sid:100002478; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fotoobjetivo.com",nocase; classtype:trojan-activity; sid:100002479; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foundationrepairhoustontx.net",nocase; classtype:trojan-activity; sid:100002480; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foxeps.com.br",nocase; classtype:trojan-activity; sid:100002481; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freecnetdownload.com",nocase; classtype:trojan-activity; sid:100002482; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freisites.com.br",nocase; classtype:trojan-activity; sid:100002483; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ftp.n3twork30cm.ml",nocase; classtype:trojan-activity; sid:100002484; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fullelectronica.com.ar",nocase; classtype:trojan-activity; sid:100002485; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"funletters.net",nocase; classtype:trojan-activity; sid:100002486; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fusionfiresolutions.com",nocase; classtype:trojan-activity; sid:100002487; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"futbolpr.com",nocase; classtype:trojan-activity; sid:100002488; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"futuregraphics.com.ar",nocase; classtype:trojan-activity; sid:100002489; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"g.pinmonkey.xyz",nocase; classtype:trojan-activity; sid:100002490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gaditastour.com",nocase; classtype:trojan-activity; sid:100002491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gametwogame.com",nocase; classtype:trojan-activity; sid:100002492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garciadogshow.com",nocase; classtype:trojan-activity; sid:100002493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow.myvnc.com",nocase; classtype:trojan-activity; sid:100002494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow4.myvnc.com",nocase; classtype:trojan-activity; sid:100002495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gastoudergonny.nl",nocase; classtype:trojan-activity; sid:100002496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gbbulls.co.uk",nocase; classtype:trojan-activity; sid:100002497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gcpc.co.id.chronoscurtain.com",nocase; classtype:trojan-activity; sid:100002498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"generaldeviales.com",nocase; classtype:trojan-activity; sid:100002499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfmodd1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100002500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfold1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100002501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghettohub.co.za",nocase; classtype:trojan-activity; sid:100002502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghislain.dartois.pagesperso-orange.fr",nocase; classtype:trojan-activity; sid:100002503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giadungg7.com",nocase; classtype:trojan-activity; sid:100002504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giddos.ga",nocase; classtype:trojan-activity; sid:100002505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giteletropical.com",nocase; classtype:trojan-activity; sid:100002506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"glowinmedia.co.ke",nocase; classtype:trojan-activity; sid:100002507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmtransformationacademy.com",nocase; classtype:trojan-activity; sid:100002508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmvadmission.org",nocase; classtype:trojan-activity; sid:100002509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnimelf.net",nocase; classtype:trojan-activity; sid:100002510; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnscrew.ro",nocase; classtype:trojan-activity; sid:100002511; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gold.investforex.id",nocase; classtype:trojan-activity; sid:100002512; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcake.co.id",nocase; classtype:trojan-activity; sid:100002513; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com",nocase; classtype:trojan-activity; sid:100002514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com.au",nocase; classtype:trojan-activity; sid:100002515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"golden-memories-funerals.yourpageserver.com",nocase; classtype:trojan-activity; sid:100002516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldenasiacapital.com",nocase; classtype:trojan-activity; sid:100002517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldmen.in",nocase; classtype:trojan-activity; sid:100002518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gpotecnosystems.com",nocase; classtype:trojan-activity; sid:100002519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gracejukes.com",nocase; classtype:trojan-activity; sid:100002520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"greataccesstoserver.com",nocase; classtype:trojan-activity; sid:100002521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"grupoinmare.com",nocase; classtype:trojan-activity; sid:100002522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gruposelt.000webhostapp.com",nocase; classtype:trojan-activity; sid:100002523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gs.monerorx.com",nocase; classtype:trojan-activity; sid:100002524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"guide-to-cell-phones.com",nocase; classtype:trojan-activity; sid:100002525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gulfac-house.com",nocase; classtype:trojan-activity; sid:100002526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gvpcdpgc.edu.in",nocase; classtype:trojan-activity; sid:100002527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"h.epelcdn.com",nocase; classtype:trojan-activity; sid:100002528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"habbotips.free.fr",nocase; classtype:trojan-activity; sid:100002529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hagebakken.no",nocase; classtype:trojan-activity; sid:100002530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hamptonpartyoffive.com",nocase; classtype:trojan-activity; sid:100002531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hashmati.com",nocase; classtype:trojan-activity; sid:100002532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hassanproduct.com",nocase; classtype:trojan-activity; sid:100002533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hchfug.org",nocase; classtype:trojan-activity; sid:100002534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hd11315.com",nocase; classtype:trojan-activity; sid:100002535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hdkamera2003.hu",nocase; classtype:trojan-activity; sid:100002536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hds.sz4h.com",nocase; classtype:trojan-activity; sid:100002537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hellogorgeous.com.au",nocase; classtype:trojan-activity; sid:100002538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"help.hizuko.com",nocase; classtype:trojan-activity; sid:100002539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"helpdeskserver.epelcdn.com",nocase; classtype:trojan-activity; sid:100002540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"herchinfitout.com.sg",nocase; classtype:trojan-activity; sid:100002541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hhaward.org",nocase; classtype:trojan-activity; sid:100002542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandroadcoc.com",nocase; classtype:trojan-activity; sid:100002543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandslasvegas.atakdev.com",nocase; classtype:trojan-activity; sid:100002544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hindi.factsriver.com",nocase; classtype:trojan-activity; sid:100002545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hiptool.net",nocase; classtype:trojan-activity; sid:100002546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitpe.com",nocase; classtype:trojan-activity; sid:100002547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitstation.nl",nocase; classtype:trojan-activity; sid:100002548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hmpmall.co.kr",nocase; classtype:trojan-activity; sid:100002549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoagietesting10.com",nocase; classtype:trojan-activity; sid:100002550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoayeuthuong-my.sharepoint.com",nocase; classtype:trojan-activity; sid:100002551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"holmesservices.mobiledevsite.co",nocase; classtype:trojan-activity; sid:100002552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"homefindersolutions.com",nocase; classtype:trojan-activity; sid:100002553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hometownchick.com",nocase; classtype:trojan-activity; sid:100002554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hongluosi.com",nocase; classtype:trojan-activity; sid:100002555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hookedupboatclub.com",nocase; classtype:trojan-activity; sid:100002556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostingparacolombia.com",nocase; classtype:trojan-activity; sid:100002557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostzaa.com",nocase; classtype:trojan-activity; sid:100002558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"houstonshutters.site",nocase; classtype:trojan-activity; sid:100002559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hr2019.vrcom7.com",nocase; classtype:trojan-activity; sid:100002560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hseda.com",nocase; classtype:trojan-activity; sid:100002561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsmwebapp.com",nocase; classtype:trojan-activity; sid:100002562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"htownbars.com",nocase; classtype:trojan-activity; sid:100002563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hubtech.co.za",nocase; classtype:trojan-activity; sid:100002564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"huellacero.cl",nocase; classtype:trojan-activity; sid:100002565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hunchomusichub.com",nocase; classtype:trojan-activity; sid:100002566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hunggiang.vn",nocase; classtype:trojan-activity; sid:100002567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"husamiyahschool.com",nocase; classtype:trojan-activity; sid:100002568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"i.n.t.e.rloca.l.qs.j.y@jfas.top",nocase; classtype:trojan-activity; sid:100002569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iabmixx2020.rayadigital.online",nocase; classtype:trojan-activity; sid:100002570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iam313.com",nocase; classtype:trojan-activity; sid:100002571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"icon.shatangmu.cn",nocase; classtype:trojan-activity; sid:100002572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idea-secure-login.com",nocase; classtype:trojan-activity; sid:100002573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idilsoft.com",nocase; classtype:trojan-activity; sid:100002574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idj.no",nocase; classtype:trojan-activity; sid:100002575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idvindia.com",nocase; classtype:trojan-activity; sid:100002576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ieclb.com.br",nocase; classtype:trojan-activity; sid:100002577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ikexpert.com",nocase; classtype:trojan-activity; sid:100002578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ilrafrica.com",nocase; classtype:trojan-activity; sid:100002579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"images.jermiau.com",nocase; classtype:trojan-activity; sid:100002580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"imbueautoworx.co.za",nocase; classtype:trojan-activity; sid:100002581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"in-tune2016.com",nocase; classtype:trojan-activity; sid:100002582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incrediblepixels.com",nocase; classtype:trojan-activity; sid:100002583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incredicole.com",nocase; classtype:trojan-activity; sid:100002584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indrasbikaner.com",nocase; classtype:trojan-activity; sid:100002585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infair.vn",nocase; classtype:trojan-activity; sid:100002586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infovator.com",nocase; classtype:trojan-activity; sid:100002587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"initialnetworks.com",nocase; classtype:trojan-activity; sid:100002588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inodesthetotaldesigners.com",nocase; classtype:trojan-activity; sid:100002589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inrajahmundry.co.in",nocase; classtype:trojan-activity; sid:100002590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"instantindialoan.com",nocase; classtype:trojan-activity; sid:100002591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intersel-idf.org",nocase; classtype:trojan-activity; sid:100002592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intuitiveideas.com.my",nocase; classtype:trojan-activity; sid:100002593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inversiones.arrayanfinanciero.cl",nocase; classtype:trojan-activity; sid:100002594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"invest.xpcorporative.com.br",nocase; classtype:trojan-activity; sid:100002595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ipmes.ma",nocase; classtype:trojan-activity; sid:100002596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iremart.es",nocase; classtype:trojan-activity; sid:100002597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iris101.co.uk",nocase; classtype:trojan-activity; sid:100002598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isaac.mikhailmotoringschool.com",nocase; classtype:trojan-activity; sid:100002599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iscamenabe.com",nocase; classtype:trojan-activity; sid:100002600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isiphephelocon.co.za",nocase; classtype:trojan-activity; sid:100002601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ismf.com.ng",nocase; classtype:trojan-activity; sid:100002602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iso-dubai.net",nocase; classtype:trojan-activity; sid:100002603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"israrulhaq.me",nocase; classtype:trojan-activity; sid:100002604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isrorg.com",nocase; classtype:trojan-activity; sid:100002605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isso.ps",nocase; classtype:trojan-activity; sid:100002606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"it123.ru",nocase; classtype:trojan-activity; sid:100002607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"italiandirezione.casa",nocase; classtype:trojan-activity; sid:100002608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itc-demo.softgig.co.ke",nocase; classtype:trojan-activity; sid:100002609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamiekaylive.com",nocase; classtype:trojan-activity; sid:100002610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamshed.pk",nocase; classtype:trojan-activity; sid:100002611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jansen-heesch.nl",nocase; classtype:trojan-activity; sid:100002612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jathra.co.uk",nocase; classtype:trojan-activity; sid:100002613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jay.diamondrelationscrm.us",nocase; classtype:trojan-activity; sid:100002614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jebs.net.au",nocase; classtype:trojan-activity; sid:100002615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jeffdahlke.com",nocase; classtype:trojan-activity; sid:100002616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jfas.top",nocase; classtype:trojan-activity; sid:100002617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jhayesconsulting.com",nocase; classtype:trojan-activity; sid:100002618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jiaoyuzixun.cn",nocase; classtype:trojan-activity; sid:100002619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jing-da.com.tw",nocase; classtype:trojan-activity; sid:100002620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jmtc.91756.cn",nocase; classtype:trojan-activity; sid:100002621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jnanbharati.com",nocase; classtype:trojan-activity; sid:100002622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jobs.thebeessolution.com",nocase; classtype:trojan-activity; sid:100002623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"joelbonissilver.com",nocase; classtype:trojan-activity; sid:100002624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"join.cl8movement.co.za",nocase; classtype:trojan-activity; sid:100002625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"josegene.com",nocase; classtype:trojan-activity; sid:100002626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jpwoodfordco.com",nocase; classtype:trojan-activity; sid:100002627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jumpmanualjacobhiller.com",nocase; classtype:trojan-activity; sid:100002628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jupiter.toxsl.in",nocase; classtype:trojan-activity; sid:100002629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"justinscott.com.au",nocase; classtype:trojan-activity; sid:100002630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kadigital.co.uk",nocase; classtype:trojan-activity; sid:100002631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalawatihomes.com",nocase; classtype:trojan-activity; sid:100002632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalogirosfinance.com",nocase; classtype:trojan-activity; sid:100002633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kaptaanchapal.com",nocase; classtype:trojan-activity; sid:100002634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karer.by",nocase; classtype:trojan-activity; sid:100002635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"katanvetov.co.il",nocase; classtype:trojan-activity; sid:100002636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kensingtondriving.com",nocase; classtype:trojan-activity; sid:100002637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ketofitnessexpert.com",nocase; classtype:trojan-activity; sid:100002638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kevinjewelry.com.co",nocase; classtype:trojan-activity; sid:100002639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"keywatch.yourpageserver.com",nocase; classtype:trojan-activity; sid:100002640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kihn-delaney30gn.ru.com",nocase; classtype:trojan-activity; sid:100002641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kingssa.co.za",nocase; classtype:trojan-activity; sid:100002642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kjcpromo.com",nocase; classtype:trojan-activity; sid:100002643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kleinendeli.co.za",nocase; classtype:trojan-activity; sid:100002644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"korrectconceptservices.com",nocase; classtype:trojan-activity; sid:100002645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"krisbadminton.com",nocase; classtype:trojan-activity; sid:100002646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ktb.sch.id",nocase; classtype:trojan-activity; sid:100002647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kubatoglubaklava.com.tr",nocase; classtype:trojan-activity; sid:100002648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kullumanalitours.com",nocase; classtype:trojan-activity; sid:100002649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kumaralok.in",nocase; classtype:trojan-activity; sid:100002650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kwanfromhongkong.com",nocase; classtype:trojan-activity; sid:100002651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kz.sldov.ru",nocase; classtype:trojan-activity; sid:100002652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"l.oc.atevur.c@zytrox.tk",nocase; classtype:trojan-activity; sid:100002653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lacasadelosalebrijes.com",nocase; classtype:trojan-activity; sid:100002654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lameguard.ru",nocase; classtype:trojan-activity; sid:100002655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laodongnhat.vn",nocase; classtype:trojan-activity; sid:100002656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laravel.pointersoftwares.com.br",nocase; classtype:trojan-activity; sid:100002657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lasermobilesounds.co.uk",nocase; classtype:trojan-activity; sid:100002658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lauratomismith.com",nocase; classtype:trojan-activity; sid:100002659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lautarosanmiguel.com",nocase; classtype:trojan-activity; sid:100002660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lawforall.edu.lk",nocase; classtype:trojan-activity; sid:100002661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lawschoolideas.xyz",nocase; classtype:trojan-activity; sid:100002662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lceventos.net",nocase; classtype:trojan-activity; sid:100002663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ld.mediaget.com",nocase; classtype:trojan-activity; sid:100002664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ldgcorp.com",nocase; classtype:trojan-activity; sid:100002665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"learning.real-academy.net",nocase; classtype:trojan-activity; sid:100002666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leasiacherise.com",nocase; classtype:trojan-activity; sid:100002667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leczkregoslup.acelero.pl",nocase; classtype:trojan-activity; sid:100002668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"legend.nu",nocase; classtype:trojan-activity; sid:100002669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leluibuffet.com.br",nocase; classtype:trojan-activity; sid:100002670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lestesteux.ca",nocase; classtype:trojan-activity; sid:100002671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.arihantmbainstitute.ac.in",nocase; classtype:trojan-activity; sid:100002672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.uib.ac.id",nocase; classtype:trojan-activity; sid:100002673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lidoraggiodisole.it",nocase; classtype:trojan-activity; sid:100002674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lifebeam.elin.co.za",nocase; classtype:trojan-activity; sid:100002675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lindnerelektroanlagen.de",nocase; classtype:trojan-activity; sid:100002676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linkintec.cn",nocase; classtype:trojan-activity; sid:100002677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"liquidaz.casa",nocase; classtype:trojan-activity; sid:100002678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"livetrack.in",nocase; classtype:trojan-activity; sid:100002679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lloydsindian.co.uk",nocase; classtype:trojan-activity; sid:100002680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lm.stagingarea.co.za",nocase; classtype:trojan-activity; sid:100002681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lmaancha.co.il",nocase; classtype:trojan-activity; sid:100002682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.cstdevs.com",nocase; classtype:trojan-activity; sid:100002683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.login2.in",nocase; classtype:trojan-activity; sid:100002684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"location-voitures.ma",nocase; classtype:trojan-activity; sid:100002685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"login.trezor.com.stockfootagesindia.com",nocase; classtype:trojan-activity; sid:100002686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"logotypfabriken.se",nocase; classtype:trojan-activity; sid:100002687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotix.de",nocase; classtype:trojan-activity; sid:100002688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotusanddragonfly.com",nocase; classtype:trojan-activity; sid:100002689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.definerisco.com",nocase; classtype:trojan-activity; sid:100002690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.difusodesign.com",nocase; classtype:trojan-activity; sid:100002691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ltc.typoten.com",nocase; classtype:trojan-activity; sid:100002692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luckybrownie.com",nocase; classtype:trojan-activity; sid:100002693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luminouspneuma.com",nocase; classtype:trojan-activity; sid:100002694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luxomodels.com",nocase; classtype:trojan-activity; sid:100002695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m-technics.kz",nocase; classtype:trojan-activity; sid:100002696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m.estudiomoros.com.ar",nocase; classtype:trojan-activity; sid:100002697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"madicon.co.za",nocase; classtype:trojan-activity; sid:100002698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"magianegramagiablancayamarres.com",nocase; classtype:trojan-activity; sid:100002699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.bs-eiendomme.co.za",nocase; classtype:trojan-activity; sid:100002700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.golimoapp.com",nocase; classtype:trojan-activity; sid:100002701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.jeffsono.org",nocase; classtype:trojan-activity; sid:100002702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maksi.feb.unib.ac.id",nocase; classtype:trojan-activity; sid:100002703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malaya.tv",nocase; classtype:trojan-activity; sid:100002704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malwarecoding.github.io",nocase; classtype:trojan-activity; sid:100002705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managed.oss-cn-beijing.aliyuncs.com",nocase; classtype:trojan-activity; sid:100002706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managemysalon.in",nocase; classtype:trojan-activity; sid:100002707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manantialesdelnorte.uy",nocase; classtype:trojan-activity; sid:100002708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manhtien.net",nocase; classtype:trojan-activity; sid:100002709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marcapinyo.ru",nocase; classtype:trojan-activity; sid:100002710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mario-sunjic.com",nocase; classtype:trojan-activity; sid:100002711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariobrown.net",nocase; classtype:trojan-activity; sid:100002712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariotessarollo.com",nocase; classtype:trojan-activity; sid:100002713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketinfosales.com",nocase; classtype:trojan-activity; sid:100002714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketing.enexusgroup.com.au",nocase; classtype:trojan-activity; sid:100002715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marksidfgs.ug",nocase; classtype:trojan-activity; sid:100002716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"masjidhabeebiyarazviya.mysunni.com",nocase; classtype:trojan-activity; sid:100002717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mastersofclientretention.com.au",nocase; classtype:trojan-activity; sid:100002718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"materialescantu.com",nocase; classtype:trojan-activity; sid:100002719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"matruchhaya.co.in",nocase; classtype:trojan-activity; sid:100002720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxtox.com.pk",nocase; classtype:trojan-activity; sid:100002721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbgrm.com",nocase; classtype:trojan-activity; sid:100002722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbjtimes.com",nocase; classtype:trojan-activity; sid:100002723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbsolutions.ge",nocase; classtype:trojan-activity; sid:100002724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mdasa.elin.co.za",nocase; classtype:trojan-activity; sid:100002725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medevlb.org",nocase; classtype:trojan-activity; sid:100002726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"media-server.skyinternet.com.pk",nocase; classtype:trojan-activity; sid:100002727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medianews.ge",nocase; classtype:trojan-activity; sid:100002728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mediawaysnews.com",nocase; classtype:trojan-activity; sid:100002729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medistaffconsulting.com",nocase; classtype:trojan-activity; sid:100002730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meeweb.com",nocase; classtype:trojan-activity; sid:100002731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"megagynreformas.com.br",nocase; classtype:trojan-activity; sid:100002732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"megamart.afnan-amc.com",nocase; classtype:trojan-activity; sid:100002733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mehainteriors.com",nocase; classtype:trojan-activity; sid:100002734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"merkathink.com",nocase; classtype:trojan-activity; sid:100002735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mertlog.com",nocase; classtype:trojan-activity; sid:100002736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"metalin-cr.com",nocase; classtype:trojan-activity; sid:100002737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mettaanand.org",nocase; classtype:trojan-activity; sid:100002738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meuoculosnanet.com.br",nocase; classtype:trojan-activity; sid:100002739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mfevr.com",nocase; classtype:trojan-activity; sid:100002740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot.myvnc.com",nocase; classtype:trojan-activity; sid:100002741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot80.myvnc.com",nocase; classtype:trojan-activity; sid:100002742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"micalle.com.au",nocase; classtype:trojan-activity; sid:100002743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michaelphilip.com",nocase; classtype:trojan-activity; sid:100002744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michimal2.000webhostapp.com",nocase; classtype:trojan-activity; sid:100002745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microblading.mirliandias.com.br",nocase; classtype:trojan-activity; sid:100002746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microcomm-group.com",nocase; classtype:trojan-activity; sid:100002747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mikhailmotoringschool.com",nocase; classtype:trojan-activity; sid:100002748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mingguanwms.com",nocase; classtype:trojan-activity; sid:100002749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minuevavida.org",nocase; classtype:trojan-activity; sid:100002750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mirror.mypage.sk",nocase; classtype:trojan-activity; sid:100002751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mis.nbcc.ac.th",nocase; classtype:trojan-activity; sid:100002752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"misterson.com",nocase; classtype:trojan-activity; sid:100002753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mkontakt.az",nocase; classtype:trojan-activity; sid:100002754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mktf.mx",nocase; classtype:trojan-activity; sid:100002755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mmdx.com",nocase; classtype:trojan-activity; sid:100002756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mmogollon.com.mx",nocase; classtype:trojan-activity; sid:100002757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mncarteam.com",nocase; classtype:trojan-activity; sid:100002758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modelhouseturkey.com",nocase; classtype:trojan-activity; sid:100002759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modernmanna.org",nocase; classtype:trojan-activity; sid:100002760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"monetization.business",nocase; classtype:trojan-activity; sid:100002761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moninediy.com",nocase; classtype:trojan-activity; sid:100002762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moreirawag.ac.ug",nocase; classtype:trojan-activity; sid:100002763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"motorcomunicacion.com",nocase; classtype:trojan-activity; sid:100002764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"msacontabil.com.br",nocase; classtype:trojan-activity; sid:100002765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mumgee.co.za",nocase; classtype:trojan-activity; sid:100002766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"muzimbiti.xigubo.co.mz",nocase; classtype:trojan-activity; sid:100002767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mvb.kz",nocase; classtype:trojan-activity; sid:100002768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mxpiqw.am.files.1drv.com",nocase; classtype:trojan-activity; sid:100002769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mydatebook.in",nocase; classtype:trojan-activity; sid:100002770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mymlql.com",nocase; classtype:trojan-activity; sid:100002771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myritz.vettickal.com",nocase; classtype:trojan-activity; sid:100002772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mysalons.in",nocase; classtype:trojan-activity; sid:100002773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myscape.in",nocase; classtype:trojan-activity; sid:100002774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mysura.it",nocase; classtype:trojan-activity; sid:100002775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"naeemacademy.com",nocase; classtype:trojan-activity; sid:100002776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"namnyak.co.ke",nocase; classtype:trojan-activity; sid:100002777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nap.mgsservers.com",nocase; classtype:trojan-activity; sid:100002778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"navayurveda.in",nocase; classtype:trojan-activity; sid:100002779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nec-i.com",nocase; classtype:trojan-activity; sid:100002780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nelitrianggraeni.000webhostapp.com",nocase; classtype:trojan-activity; sid:100002781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nerve.untergrund.net",nocase; classtype:trojan-activity; sid:100002782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nettube.com.br",nocase; classtype:trojan-activity; sid:100002783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"networkwheels.co.za",nocase; classtype:trojan-activity; sid:100002784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newfuture.fr",nocase; classtype:trojan-activity; sid:100002785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newinfinitysynergy.com",nocase; classtype:trojan-activity; sid:100002786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newtreedesign.co.uk",nocase; classtype:trojan-activity; sid:100002787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newvisionopticallab.com",nocase; classtype:trojan-activity; sid:100002788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newxing.com",nocase; classtype:trojan-activity; sid:100002789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nextdigitalday.ru",nocase; classtype:trojan-activity; sid:100002790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ngdaycare.co.za",nocase; classtype:trojan-activity; sid:100002791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nguyenkekhuyen.com",nocase; classtype:trojan-activity; sid:100002792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhorangtreem.com",nocase; classtype:trojan-activity; sid:100002793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nicolas.ug",nocase; classtype:trojan-activity; sid:100002794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nidhi.iexist.in",nocase; classtype:trojan-activity; sid:100002795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nikanpolimer.ir",nocase; classtype:trojan-activity; sid:100002796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilehouse.co.ug",nocase; classtype:trojan-activity; sid:100002797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilinkeji.com",nocase; classtype:trojan-activity; sid:100002798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nimboohomes.com",nocase; classtype:trojan-activity; sid:100002799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"njtiledesigncenter.com",nocase; classtype:trojan-activity; sid:100002800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nobius.org",nocase; classtype:trojan-activity; sid:100002801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nocalnoodle.elin.co.za",nocase; classtype:trojan-activity; sid:100002802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nomadicbees.com",nocase; classtype:trojan-activity; sid:100002803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"northnodegroup.com.au",nocase; classtype:trojan-activity; sid:100002804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"notamuzikaletleri.com",nocase; classtype:trojan-activity; sid:100002805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ns1.the-widyantos.com",nocase; classtype:trojan-activity; sid:100002806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nsb.org.uk",nocase; classtype:trojan-activity; sid:100002807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nurmarkaz.org",nocase; classtype:trojan-activity; sid:100002808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nxtnet.ga",nocase; classtype:trojan-activity; sid:100002809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nyasabigbullets.com",nocase; classtype:trojan-activity; sid:100002810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nyeh2o.com.au",nocase; classtype:trojan-activity; sid:100002811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"obseques-conseils.com",nocase; classtype:trojan-activity; sid:100002812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oecteam.com",nocase; classtype:trojan-activity; sid:100002813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohsewgorgeous.co.uk",nocase; classtype:trojan-activity; sid:100002814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oleholeh.memangbeda.website",nocase; classtype:trojan-activity; sid:100002815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaia.org",nocase; classtype:trojan-activity; sid:100002816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaromatic.com",nocase; classtype:trojan-activity; sid:100002817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omega.az",nocase; classtype:trojan-activity; sid:100002818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oms.pappai.com",nocase; classtype:trojan-activity; sid:100002819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omscoc.pappai.com",nocase; classtype:trojan-activity; sid:100002820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedigitalcard.granvizionnecorp.com",nocase; classtype:trojan-activity; sid:100002821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.listifyapp.co",nocase; classtype:trojan-activity; sid:100002822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"online.creedglobal.in",nocase; classtype:trojan-activity; sid:100002823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"open.rawntech.com",nocase; classtype:trojan-activity; sid:100002824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"open.warehousesaas.co.uk",nocase; classtype:trojan-activity; sid:100002825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opolis.io",nocase; classtype:trojan-activity; sid:100002826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"optimus.com.sg",nocase; classtype:trojan-activity; sid:100002827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"order.bizpeed.com",nocase; classtype:trojan-activity; sid:100002828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orientgatewayltd.com",nocase; classtype:trojan-activity; sid:100002829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orion445.com",nocase; classtype:trojan-activity; sid:100002830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orlina.be",nocase; classtype:trojan-activity; sid:100002831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oserve.pk",nocase; classtype:trojan-activity; sid:100002832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ot.weenets.com",nocase; classtype:trojan-activity; sid:100002833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ozemag.com",nocase; classtype:trojan-activity; sid:100002834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p1.lingpao8.com",nocase; classtype:trojan-activity; sid:100002835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p3.zbjimg.com",nocase; classtype:trojan-activity; sid:100002836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p6.zbjimg.com",nocase; classtype:trojan-activity; sid:100002837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pablobrothel.com.ar",nocase; classtype:trojan-activity; sid:100002838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacificgroup.ws",nocase; classtype:trojan-activity; sid:100002839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacwebdesigns.com",nocase; classtype:trojan-activity; sid:100002840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pagos.krayem.com.mx",nocase; classtype:trojan-activity; sid:100002841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"palochusvet.szm.com",nocase; classtype:trojan-activity; sid:100002842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"panslimiterd.com",nocase; classtype:trojan-activity; sid:100002843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parallel.rockvideos.at",nocase; classtype:trojan-activity; sid:100002844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parejasfelices.mi-fs.com",nocase; classtype:trojan-activity; sid:100002845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parkhussion.com",nocase; classtype:trojan-activity; sid:100002846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastorpaulocosta.com",nocase; classtype:trojan-activity; sid:100002847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.51lg.com",nocase; classtype:trojan-activity; sid:100002848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.99ddd.com",nocase; classtype:trojan-activity; sid:100002849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch3.99ddd.com",nocase; classtype:trojan-activity; sid:100002850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paths.elin.co.za",nocase; classtype:trojan-activity; sid:100002851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patriotsupremehemp.com",nocase; classtype:trojan-activity; sid:100002852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paulmercier.biz",nocase; classtype:trojan-activity; sid:100002853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payerrealty.com",nocase; classtype:trojan-activity; sid:100002854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payments.atifsiddiqui.me",nocase; classtype:trojan-activity; sid:100002855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pcsoori.com",nocase; classtype:trojan-activity; sid:100002856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pd.oceaniarp.net",nocase; classtype:trojan-activity; sid:100002857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pemdodo.com",nocase; classtype:trojan-activity; sid:100002858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perfumeriamontes.es",nocase; classtype:trojan-activity; sid:100002859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"periodiche.bar",nocase; classtype:trojan-activity; sid:100002860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpus.onlineman7-jombang.sch.id",nocase; classtype:trojan-activity; sid:100002861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpustekim.untirta.ac.id",nocase; classtype:trojan-activity; sid:100002862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pestoclean.co.uk",nocase; classtype:trojan-activity; sid:100002863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"petercollie.com",nocase; classtype:trojan-activity; sid:100002864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ph4s.ru",nocase; classtype:trojan-activity; sid:100002865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phasdesign.com",nocase; classtype:trojan-activity; sid:100002866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phenhuong.sanpham.online",nocase; classtype:trojan-activity; sid:100002867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phittc.com",nocase; classtype:trojan-activity; sid:100002868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"photo360.kubooking.com",nocase; classtype:trojan-activity; sid:100002869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pink99.com",nocase; classtype:trojan-activity; sid:100002870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"plasfan.ind.br",nocase; classtype:trojan-activity; sid:100002871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"playground2.grupoaliadasca.com",nocase; classtype:trojan-activity; sid:100002872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pmglance.startwriteup.com",nocase; classtype:trojan-activity; sid:100002873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pokojewewladyslawowie.pl",nocase; classtype:trojan-activity; sid:100002874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pole.com.vc",nocase; classtype:trojan-activity; sid:100002875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pool.phxdir.com",nocase; classtype:trojan-activity; sid:100002876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pooltablemoversdenver.net",nocase; classtype:trojan-activity; sid:100002877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"posmicrosystems.com",nocase; classtype:trojan-activity; sid:100002878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"poulman.panagiotopoulos-tours.gr",nocase; classtype:trojan-activity; sid:100002879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ppdb.smk-ciptaskill.sch.id",nocase; classtype:trojan-activity; sid:100002880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestasicash.com.ar",nocase; classtype:trojan-activity; sid:100002881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestigehomeautomation.net",nocase; classtype:trojan-activity; sid:100002882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"preview2.behalen.com",nocase; classtype:trojan-activity; sid:100002883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prishaartcreations.com",nocase; classtype:trojan-activity; sid:100002884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"production.sparshims.com",nocase; classtype:trojan-activity; sid:100002885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"programaoperadoronline.com.br",nocase; classtype:trojan-activity; sid:100002886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"project.exquitec.com",nocase; classtype:trojan-activity; sid:100002887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promotoradescomplica.com.br",nocase; classtype:trojan-activity; sid:100002888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promoversdubai.com",nocase; classtype:trojan-activity; sid:100002889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq.elin.co.za",nocase; classtype:trojan-activity; sid:100002890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq2.elin.co.za",nocase; classtype:trojan-activity; sid:100002891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosoc.nl",nocase; classtype:trojan-activity; sid:100002892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosyarmakassar.com",nocase; classtype:trojan-activity; sid:100002893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"provence.elin.co.za",nocase; classtype:trojan-activity; sid:100002894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prox.realunix.cc",nocase; classtype:trojan-activity; sid:100002895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pujashoppe.in",nocase; classtype:trojan-activity; sid:100002896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punchdialogues.com",nocase; classtype:trojan-activity; sid:100002897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punjabdevelopersassociation.com.pk",nocase; classtype:trojan-activity; sid:100002898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qadir.tickfa.ir",nocase; classtype:trojan-activity; sid:100002899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qatarglobalconsulting.com",nocase; classtype:trojan-activity; sid:100002900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qmsled.com",nocase; classtype:trojan-activity; sid:100002901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qu.o.t.ev.v.n.r@zytrox.tk",nocase; classtype:trojan-activity; sid:100002902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quartier-midi.be",nocase; classtype:trojan-activity; sid:100002903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"querocar.com",nocase; classtype:trojan-activity; sid:100002904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rachmat-assuhaimi.my.id",nocase; classtype:trojan-activity; sid:100002905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"radioafifense.deploys.live",nocase; classtype:trojan-activity; sid:100002906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rainbowisp.info",nocase; classtype:trojan-activity; sid:100002907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rajeshtailang.com",nocase; classtype:trojan-activity; sid:100002908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rakeshkhatri.in",nocase; classtype:trojan-activity; sid:100002909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raodigitalmedia.com",nocase; classtype:trojan-activity; sid:100002910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raquelhelena.com.br",nocase; classtype:trojan-activity; sid:100002911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rarlabarchiver.ac",nocase; classtype:trojan-activity; sid:100002912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rasadbar.ir",nocase; classtype:trojan-activity; sid:100002913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rashika.ascarvalho.co.za",nocase; classtype:trojan-activity; sid:100002914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ratemyfenancialadvisor.com",nocase; classtype:trojan-activity; sid:100002915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ravenproductionsltd.com",nocase; classtype:trojan-activity; sid:100002916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ravo.net.au",nocase; classtype:trojan-activity; sid:100002917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rc.ixiaoyang.cn",nocase; classtype:trojan-activity; sid:100002918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rcmesilva.charbelsales.com.br",nocase; classtype:trojan-activity; sid:100002919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reacredit.com.br",nocase; classtype:trojan-activity; sid:100002920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"readwrite26.nl",nocase; classtype:trojan-activity; sid:100002921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"readymmade.com",nocase; classtype:trojan-activity; sid:100002922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"recyclethesurplus.com",nocase; classtype:trojan-activity; sid:100002923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redbats.co.in",nocase; classtype:trojan-activity; sid:100002924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redchillicrackers.com",nocase; classtype:trojan-activity; sid:100002925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reifenquick.de",nocase; classtype:trojan-activity; sid:100002926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"relaxindulge.co.nz",nocase; classtype:trojan-activity; sid:100002927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"renehavis.com.ua",nocase; classtype:trojan-activity; sid:100002928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"repatriacioncolombia.com",nocase; classtype:trojan-activity; sid:100002929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.uf1.cn",nocase; classtype:trojan-activity; sid:100002930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reseller.digimitra.in",nocase; classtype:trojan-activity; sid:100002931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reseller.itechbrasil.com",nocase; classtype:trojan-activity; sid:100002932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"resuco.net",nocase; classtype:trojan-activity; sid:100002933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"revolet-sa.com",nocase; classtype:trojan-activity; sid:100002934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rezkabum.ru",nocase; classtype:trojan-activity; sid:100002935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rhema.com.sg",nocase; classtype:trojan-activity; sid:100002936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richmondminerals.co.zm",nocase; classtype:trojan-activity; sid:100002937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinaefoundation.org.za",nocase; classtype:trojan-activity; sid:100002938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinkaisystem-ht.com",nocase; classtype:trojan-activity; sid:100002939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"riverfox.co.za",nocase; classtype:trojan-activity; sid:100002940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkcable.co.in",nocase; classtype:trojan-activity; sid:100002941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkverify.securestudies.com",nocase; classtype:trojan-activity; sid:100002942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertmcardle.com",nocase; classtype:trojan-activity; sid:100002943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertsinclair.net",nocase; classtype:trojan-activity; sid:100002944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"romanianpoints.com",nocase; classtype:trojan-activity; sid:100002945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ronnietucker.co.uk",nocase; classtype:trojan-activity; sid:100002946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roomsvc.servegate.kr",nocase; classtype:trojan-activity; sid:100002947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roshnijewellery.com",nocase; classtype:trojan-activity; sid:100002948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rsgym.net",nocase; classtype:trojan-activity; sid:100002949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubazar.pro",nocase; classtype:trojan-activity; sid:100002950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubycityvietnam.com",nocase; classtype:trojan-activity; sid:100002951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruisgood.ru",nocase; classtype:trojan-activity; sid:100002952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruwadalkuwait.com",nocase; classtype:trojan-activity; sid:100002953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.51shijuan.com",nocase; classtype:trojan-activity; sid:100002954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.hu.d.es.h.d.u.e54.78.16247@46.249.33.79",nocase; classtype:trojan-activity; sid:100002955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.thechinesemuslim.com",nocase; classtype:trojan-activity; sid:100002956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sacredscentsonline.com",nocase; classtype:trojan-activity; sid:100002957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sadmahfuneralservices.co.za",nocase; classtype:trojan-activity; sid:100002958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safcol-colors.com",nocase; classtype:trojan-activity; sid:100002959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safehubsecurity.ca",nocase; classtype:trojan-activity; sid:100002960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safety.nanotechproautocare.com",nocase; classtype:trojan-activity; sid:100002961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sahathaikasetpan.com",nocase; classtype:trojan-activity; sid:100002962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sainzim.co.za",nocase; classtype:trojan-activity; sid:100002963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"saisoftwareinc.com",nocase; classtype:trojan-activity; sid:100002964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"salecorner.yourpageserver.com",nocase; classtype:trojan-activity; sid:100002965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"salonsaifa.com",nocase; classtype:trojan-activity; sid:100002966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"samriddhijyotish.com",nocase; classtype:trojan-activity; sid:100002967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sandovalgraphics.com",nocase; classtype:trojan-activity; sid:100002968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"santyago.org",nocase; classtype:trojan-activity; sid:100002969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sasystemsuk.com",nocase; classtype:trojan-activity; sid:100002970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scarfaceindustries.com",nocase; classtype:trojan-activity; sid:100002971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scglobal.co.th",nocase; classtype:trojan-activity; sid:100002972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schalke04rss.de",nocase; classtype:trojan-activity; sid:100002973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scheff.com",nocase; classtype:trojan-activity; sid:100002974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schoolbustracker.softgig.co.ke",nocase; classtype:trojan-activity; sid:100002975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sculetus.nl",nocase; classtype:trojan-activity; sid:100002976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"secure-doc-reader.com",nocase; classtype:trojan-activity; sid:100002977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"segalsmetals.elin.co.za",nocase; classtype:trojan-activity; sid:100002978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sellmyphonela.com",nocase; classtype:trojan-activity; sid:100002979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"selltechtoday.com",nocase; classtype:trojan-activity; sid:100002980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"senbiaojita.com",nocase; classtype:trojan-activity; sid:100002981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sentierodelviandante.ml",nocase; classtype:trojan-activity; sid:100002982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serendibsourcing.com",nocase; classtype:trojan-activity; sid:100002983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sericaasia.com",nocase; classtype:trojan-activity; sid:100002984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd.myvnc.com",nocase; classtype:trojan-activity; sid:100002985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd80.myvnc.com",nocase; classtype:trojan-activity; sid:100002986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sexologistpakistan.net",nocase; classtype:trojan-activity; sid:100002987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sgessy.com.br",nocase; classtype:trojan-activity; sid:100002988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shaheentbfoundation.com",nocase; classtype:trojan-activity; sid:100002989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shahikhana.cstdevs.com",nocase; classtype:trojan-activity; sid:100002990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shahu66.com",nocase; classtype:trojan-activity; sid:100002991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shalombaptistchapel.com",nocase; classtype:trojan-activity; sid:100002992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharkrigs.com",nocase; classtype:trojan-activity; sid:100002993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharpelevators.in",nocase; classtype:trojan-activity; sid:100002994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shembefoundation.com",nocase; classtype:trojan-activity; sid:100002995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shidditourism.com",nocase; classtype:trojan-activity; sid:100002996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shivakunwar.com.np",nocase; classtype:trojan-activity; sid:100002997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shoblasaathitrust.org",nocase; classtype:trojan-activity; sid:100002998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shomalhouse.com",nocase; classtype:trojan-activity; sid:100002999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shooka-co.com",nocase; classtype:trojan-activity; sid:100003000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shop.goldspot.agency",nocase; classtype:trojan-activity; sid:100003001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shopsofe.com",nocase; classtype:trojan-activity; sid:100003002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sibernetix.fr",nocase; classtype:trojan-activity; sid:100003003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sige.brisainformatica.com.br",nocase; classtype:trojan-activity; sid:100003004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"signatureads.co.in",nocase; classtype:trojan-activity; sid:100003005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siili.net",nocase; classtype:trojan-activity; sid:100003006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simoneporzi.it",nocase; classtype:trojan-activity; sid:100003007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simorsint.com",nocase; classtype:trojan-activity; sid:100003008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simplithy.co.uk",nocase; classtype:trojan-activity; sid:100003009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindicato1ucm.cl",nocase; classtype:trojan-activity; sid:100003010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindpol.tiejuris.com.br",nocase; classtype:trojan-activity; sid:100003011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sipahielektrik.com",nocase; classtype:trojan-activity; sid:100003012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sistelligent.com",nocase; classtype:trojan-activity; sid:100003013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyflyfares.com",nocase; classtype:trojan-activity; sid:100003014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyscan.com",nocase; classtype:trojan-activity; sid:100003015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"slot0.gamoruz.com",nocase; classtype:trojan-activity; sid:100003016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smarthouseforum.ru",nocase; classtype:trojan-activity; sid:100003017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smartzedu.com",nocase; classtype:trojan-activity; sid:100003018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smokesolutionindia.com",nocase; classtype:trojan-activity; sid:100003019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smritiphotography.in",nocase; classtype:trojan-activity; sid:100003020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sobariko.com",nocase; classtype:trojan-activity; sid:100003021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sobethuacademy.com",nocase; classtype:trojan-activity; sid:100003022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.110route.com",nocase; classtype:trojan-activity; sid:100003023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.officelabo.net",nocase; classtype:trojan-activity; sid:100003024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sogecoenergy.com",nocase; classtype:trojan-activity; sid:100003025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sohs.conceptechs.info",nocase; classtype:trojan-activity; sid:100003026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"solar.amazingtribe.lk",nocase; classtype:trojan-activity; sid:100003027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somcorbera.cat",nocase; classtype:trojan-activity; sid:100003028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somir.com.mx",nocase; classtype:trojan-activity; sid:100003029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soralapps.com",nocase; classtype:trojan-activity; sid:100003030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sota-france.fr",nocase; classtype:trojan-activity; sid:100003031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"space.proactint.org",nocase; classtype:trojan-activity; sid:100003032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spaceframe.mobi.space-frame.co.za",nocase; classtype:trojan-activity; sid:100003033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"special-key.cf",nocase; classtype:trojan-activity; sid:100003034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spent.com.pl",nocase; classtype:trojan-activity; sid:100003035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spetsesyachtcharter.gr",nocase; classtype:trojan-activity; sid:100003036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spititourism.com",nocase; classtype:trojan-activity; sid:100003037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spittinfire.com",nocase; classtype:trojan-activity; sid:100003038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"springbedspetroleum.com",nocase; classtype:trojan-activity; sid:100003039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"src1.minibai.com",nocase; classtype:trojan-activity; sid:100003040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sreenivasapaintingworks.com",nocase; classtype:trojan-activity; sid:100003041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sriglobalit.com",nocase; classtype:trojan-activity; sid:100003042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"srilankamovies.com",nocase; classtype:trojan-activity; sid:100003043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"srvmanos.no-ip.info",nocase; classtype:trojan-activity; sid:100003044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ss.monita.co.id",nocase; classtype:trojan-activity; sid:100003045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"st.devcodin.com",nocase; classtype:trojan-activity; sid:100003046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"staging.apparelpunch.com",nocase; classtype:trojan-activity; sid:100003047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"starcountry.net",nocase; classtype:trojan-activity; sid:100003048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"static.3001.net",nocase; classtype:trojan-activity; sid:100003049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stiau.iuc.ac",nocase; classtype:trojan-activity; sid:100003050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sticker.jewsjuice.com",nocase; classtype:trojan-activity; sid:100003051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stiepancasetia.ac.id",nocase; classtype:trojan-activity; sid:100003052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stlukesohag.com",nocase; classtype:trojan-activity; sid:100003053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"store.ericalgarin.com",nocase; classtype:trojan-activity; sid:100003054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stott-thompson.co.uk",nocase; classtype:trojan-activity; sid:100003055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"streetdemo.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"suboldesign.com",nocase; classtype:trojan-activity; sid:100003057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sumerians.org",nocase; classtype:trojan-activity; sid:100003058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunaryem.com.tr",nocase; classtype:trojan-activity; sid:100003059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunmarkholidays.com",nocase; classtype:trojan-activity; sid:100003060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support-4-free.com",nocase; classtype:trojan-activity; sid:100003061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support.clz.kr",nocase; classtype:trojan-activity; sid:100003062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supportit.online",nocase; classtype:trojan-activity; sid:100003063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sw.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweaty.dk",nocase; classtype:trojan-activity; sid:100003065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweet-diet.com",nocase; classtype:trojan-activity; sid:100003066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swiftlogisticseg.com",nocase; classtype:trojan-activity; sid:100003067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swwbia.com",nocase; classtype:trojan-activity; sid:100003068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"syracusecoffee.com",nocase; classtype:trojan-activity; sid:100003069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sytraders.co",nocase; classtype:trojan-activity; sid:100003070; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"t.honker.info",nocase; classtype:trojan-activity; sid:100003071; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tadoo.ca",nocase; classtype:trojan-activity; sid:100003072; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tafsantoursandtravels.com",nocase; classtype:trojan-activity; sid:100003073; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tajushariya.com",nocase; classtype:trojan-activity; sid:100003074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tallyinvoicecustomization.com",nocase; classtype:trojan-activity; sid:100003075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taltus.co.uk",nocase; classtype:trojan-activity; sid:100003076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tapalkoedacoffee.com",nocase; classtype:trojan-activity; sid:100003077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tarravalleyfoods.com.au",nocase; classtype:trojan-activity; sid:100003078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taurus.ug",nocase; classtype:trojan-activity; sid:100003079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tc.snpsresidential.com",nocase; classtype:trojan-activity; sid:100003080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tcy.198424.com",nocase; classtype:trojan-activity; sid:100003081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tdsp.yngw518.com",nocase; classtype:trojan-activity; sid:100003082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"techgms.com",nocase; classtype:trojan-activity; sid:100003083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teduae.com",nocase; classtype:trojan-activity; sid:100003084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teleargentina.com",nocase; classtype:trojan-activity; sid:100003085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"telescopelms.com",nocase; classtype:trojan-activity; sid:100003086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"temptmag.com",nocase; classtype:trojan-activity; sid:100003087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tencoconsulting.com",nocase; classtype:trojan-activity; sid:100003088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teneth.co.za",nocase; classtype:trojan-activity; sid:100003089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tentandoserfitness.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tessrobins.com",nocase; classtype:trojan-activity; sid:100003091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.adventser.com",nocase; classtype:trojan-activity; sid:100003092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.letraele.es",nocase; classtype:trojan-activity; sid:100003093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.lubrico.in",nocase; classtype:trojan-activity; sid:100003094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.protocsconnectes.eu",nocase; classtype:trojan-activity; sid:100003095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.typoten.com",nocase; classtype:trojan-activity; sid:100003096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.wanepghana.org",nocase; classtype:trojan-activity; sid:100003097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.asistencia247.com",nocase; classtype:trojan-activity; sid:100003098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.milenial.id",nocase; classtype:trojan-activity; sid:100003099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.tenplusone.my",nocase; classtype:trojan-activity; sid:100003100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.basis-web.com",nocase; classtype:trojan-activity; sid:100003101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.marrenconstruction.ie",nocase; classtype:trojan-activity; sid:100003102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.clickitsolutionsmw.com",nocase; classtype:trojan-activity; sid:100003103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.thinkingcorp.in",nocase; classtype:trojan-activity; sid:100003104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testnew.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teteaffiche.stephanebillon.com",nocase; classtype:trojan-activity; sid:100003106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tewoerd.eu",nocase; classtype:trojan-activity; sid:100003107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"textile.softberg.ro",nocase; classtype:trojan-activity; sid:100003108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tharringtonsponsorship.com",nocase; classtype:trojan-activity; sid:100003109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecleaningladiespdx.com",nocase; classtype:trojan-activity; sid:100003110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecreativecafe.co.uk",nocase; classtype:trojan-activity; sid:100003111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thedesertship.com",nocase; classtype:trojan-activity; sid:100003112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thefamouscurrybazaar.co.uk",nocase; classtype:trojan-activity; sid:100003113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thefuturelife.in",nocase; classtype:trojan-activity; sid:100003114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thehighlightinterior.com",nocase; classtype:trojan-activity; sid:100003115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thekassia.co.uk",nocase; classtype:trojan-activity; sid:100003116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"themansionkasauli.com",nocase; classtype:trojan-activity; sid:100003117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theprofinn.com",nocase; classtype:trojan-activity; sid:100003118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thesummitpc.net",nocase; classtype:trojan-activity; sid:100003119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theurbantutors.com",nocase; classtype:trojan-activity; sid:100003120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thosewebbs.com",nocase; classtype:trojan-activity; sid:100003121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thriveink.com",nocase; classtype:trojan-activity; sid:100003122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tianangdep.com",nocase; classtype:trojan-activity; sid:100003123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickfoods.tickme.lk",nocase; classtype:trojan-activity; sid:100003124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tidymasters.com.au",nocase; classtype:trojan-activity; sid:100003125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"timegonebuy.com",nocase; classtype:trojan-activity; sid:100003126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tksb.net",nocase; classtype:trojan-activity; sid:100003127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tlcc.com.gt",nocase; classtype:trojan-activity; sid:100003128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"todoapp.cstdevs.com",nocase; classtype:trojan-activity; sid:100003129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonydong.com",nocase; classtype:trojan-activity; sid:100003130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonyzone.com",nocase; classtype:trojan-activity; sid:100003131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tooba.tenplusone.my",nocase; classtype:trojan-activity; sid:100003132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tools.reimclub.com",nocase; classtype:trojan-activity; sid:100003133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topcell9.com",nocase; classtype:trojan-activity; sid:100003134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toplevel.com.br",nocase; classtype:trojan-activity; sid:100003135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topmask.co.za",nocase; classtype:trojan-activity; sid:100003136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"torresquinterocorp.com",nocase; classtype:trojan-activity; sid:100003137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"towme.services",nocase; classtype:trojan-activity; sid:100003138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toyotacollege.ac.th",nocase; classtype:trojan-activity; sid:100003139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpke.hu",nocase; classtype:trojan-activity; sid:100003140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"translaterjemah.com",nocase; classtype:trojan-activity; sid:100003141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"travelwithmanta.co.za",nocase; classtype:trojan-activity; sid:100003142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trendyshoes.co.za",nocase; classtype:trojan-activity; sid:100003143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trezors.io.mahlongwa.com",nocase; classtype:trojan-activity; sid:100003144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trimestre.bar",nocase; classtype:trojan-activity; sid:100003145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"troki.com.co",nocase; classtype:trojan-activity; sid:100003146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tropics.codeleek.net",nocase; classtype:trojan-activity; sid:100003147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trudelfavreau.com",nocase; classtype:trojan-activity; sid:100003148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsd.jxwan.com",nocase; classtype:trojan-activity; sid:100003149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tulli.info",nocase; classtype:trojan-activity; sid:100003150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tupperware.michaelroberge.ca",nocase; classtype:trojan-activity; sid:100003151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"turanggaresources.com",nocase; classtype:trojan-activity; sid:100003152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uat.indianfilmzone.com",nocase; classtype:trojan-activity; sid:100003153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ublretailerdemo.cstdevs.com",nocase; classtype:trojan-activity; sid:100003154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uc-56.ru",nocase; classtype:trojan-activity; sid:100003155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uisusa.uisusa.com",nocase; classtype:trojan-activity; sid:100003156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ultimate-24.de",nocase; classtype:trojan-activity; sid:100003157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"umwelt-kirchhof.de",nocase; classtype:trojan-activity; sid:100003158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unicorpbrunei.com",nocase; classtype:trojan-activity; sid:100003159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uniengrisb.com",nocase; classtype:trojan-activity; sid:100003160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"union.jctrip.cn",nocase; classtype:trojan-activity; sid:100003161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unyazitelecom.com",nocase; classtype:trojan-activity; sid:100003162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"up.llw0.com",nocase; classtype:trojan-activity; sid:100003163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"upcbpta.com",nocase; classtype:trojan-activity; sid:100003164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"used-jeans.fr",nocase; classtype:trojan-activity; sid:100003165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"useformoney.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uss.ac.th",nocase; classtype:trojan-activity; sid:100003167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uzzepay.com.br",nocase; classtype:trojan-activity; sid:100003168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vanzare.cabanabrazi2.ro",nocase; classtype:trojan-activity; sid:100003169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vbcargo.hu",nocase; classtype:trojan-activity; sid:100003170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vcah.co.uk",nocase; classtype:trojan-activity; sid:100003171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vectarts.com",nocase; classtype:trojan-activity; sid:100003172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vegadelcasero.cl",nocase; classtype:trojan-activity; sid:100003173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"velma-harber30ku.com",nocase; classtype:trojan-activity; sid:100003174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vendas.lidiacarmeli.com.br",nocase; classtype:trojan-activity; sid:100003175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"veterinariadrpopui.com",nocase; classtype:trojan-activity; sid:100003176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vfocus.net",nocase; classtype:trojan-activity; sid:100003177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vienen.gblix.srv.br",nocase; classtype:trojan-activity; sid:100003178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vilaart.rs",nocase; classtype:trojan-activity; sid:100003179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villamarand.com",nocase; classtype:trojan-activity; sid:100003180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villatera.com",nocase; classtype:trojan-activity; sid:100003181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"violinstop.com",nocase; classtype:trojan-activity; sid:100003182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"virtuleverage.com",nocase; classtype:trojan-activity; sid:100003183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visions.alnisamart.com",nocase; classtype:trojan-activity; sid:100003184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visualhome.cl",nocase; classtype:trojan-activity; sid:100003185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vivationdesign.com",nocase; classtype:trojan-activity; sid:100003186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"viveirodoiscorregos.com.br",nocase; classtype:trojan-activity; sid:100003187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vksales.com",nocase; classtype:trojan-activity; sid:100003188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vocalterra.com",nocase; classtype:trojan-activity; sid:100003189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vokasi.ub.ac.id",nocase; classtype:trojan-activity; sid:100003190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vologroup.com.br",nocase; classtype:trojan-activity; sid:100003191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"voteyouramerica.dekitout.com",nocase; classtype:trojan-activity; sid:100003192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vpts.co.za",nocase; classtype:trojan-activity; sid:100003193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vstsample.com",nocase; classtype:trojan-activity; sid:100003194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vtube.fadlymotivator.com",nocase; classtype:trojan-activity; sid:100003195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vvsskmodinationalschool.com",nocase; classtype:trojan-activity; sid:100003196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu",nocase; classtype:trojan-activity; sid:100003197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepliberia.org",nocase; classtype:trojan-activity; sid:100003198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepniger.org",nocase; classtype:trojan-activity; sid:100003199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weareactum.com",nocase; classtype:trojan-activity; sid:100003200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.eng.ubu.ac.th",nocase; classtype:trojan-activity; sid:100003201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geomegasoft.net",nocase; classtype:trojan-activity; sid:100003202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.newinnovationtechnology.com",nocase; classtype:trojan-activity; sid:100003203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.smarts-works.com",nocase; classtype:trojan-activity; sid:100003204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.thebeessolution.com",nocase; classtype:trojan-activity; sid:100003205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webgis.perumdasolo.com",nocase; classtype:trojan-activity; sid:100003206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webpresario.com",nocase; classtype:trojan-activity; sid:100003207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weinsteincounseling.com",nocase; classtype:trojan-activity; sid:100003208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wfinance.com.br",nocase; classtype:trojan-activity; sid:100003209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whcms.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteresponse.com",nocase; classtype:trojan-activity; sid:100003211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wi522012.ferozo.com",nocase; classtype:trojan-activity; sid:100003212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikalen.co.za",nocase; classtype:trojan-activity; sid:100003213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildnights.co.uk",nocase; classtype:trojan-activity; sid:100003214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildtrust.mediadevstaging.com",nocase; classtype:trojan-activity; sid:100003215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"willow-nettica.com",nocase; classtype:trojan-activity; sid:100003216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wimbamusica.com",nocase; classtype:trojan-activity; sid:100003217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"windcomtechnologies.com",nocase; classtype:trojan-activity; sid:100003218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wishesconcierge.com",nocase; classtype:trojan-activity; sid:100003219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woezon.agency",nocase; classtype:trojan-activity; sid:100003220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wolfgang-brodte.de",nocase; classtype:trojan-activity; sid:100003221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woodsytech.com",nocase; classtype:trojan-activity; sid:100003222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wordpress.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100003223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wozata.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wp.readhere.in",nocase; classtype:trojan-activity; sid:100003225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wpdemo.101clients.com.au",nocase; classtype:trojan-activity; sid:100003226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"writtendeer.com",nocase; classtype:trojan-activity; sid:100003227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ws5588.f3322.net",nocase; classtype:trojan-activity; sid:100003228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wyklej.pl",nocase; classtype:trojan-activity; sid:100003229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"x2vn.com",nocase; classtype:trojan-activity; sid:100003230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xia.beihaixue.com",nocase; classtype:trojan-activity; sid:100003231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xixaoclothing.com",nocase; classtype:trojan-activity; sid:100003232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xk.996is.com",nocase; classtype:trojan-activity; sid:100003233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--polimerbizmimarlk-rvc.com",nocase; classtype:trojan-activity; sid:100003234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ybom.urbanolab.com",nocase; classtype:trojan-activity; sid:100003235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yeichner.com",nocase; classtype:trojan-activity; sid:100003236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yeq.i.u.j.ia.n.3@zytrox.tk",nocase; classtype:trojan-activity; sid:100003237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ylfpremium.com",nocase; classtype:trojan-activity; sid:100003238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yoast.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yummyyogaudaipur.com",nocase; classtype:trojan-activity; sid:100003240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yzkzixun.com",nocase; classtype:trojan-activity; sid:100003241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ziyker4gaming@zytrox.tk",nocase; classtype:trojan-activity; sid:100003242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zmedcoach.com",nocase; classtype:trojan-activity; sid:100003243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zytrox.tk",nocase; classtype:trojan-activity; sid:100003244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zz.690tx.com",nocase; classtype:trojan-activity; sid:100003245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100003246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/86.exe",nocase; classtype:trojan-activity; sid:100003247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amumufree.weebly.com",nocase; http_uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe",nocase; classtype:trojan-activity; sid:100003248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"analogx.com",nocase; http_uri; content:"/files/proxyi.exe",nocase; classtype:trojan-activity; sid:100003249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe",nocase; classtype:trojan-activity; sid:100003250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/dvdfv/anjj/downloads/jami.exe",nocase; classtype:trojan-activity; sid:100003251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/heyhoeee/heyhoename1/downloads/1234.exe",nocase; classtype:trojan-activity; sid:100003252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/4.exe",nocase; classtype:trojan-activity; sid:100003253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/6.exe",nocase; classtype:trojan-activity; sid:100003254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/labesoftware/update/downloads/boost-fps.exe",nocase; classtype:trojan-activity; sid:100003255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/labesoftware/update/downloads/install_plugin_x64_x86.exe",nocase; classtype:trojan-activity; sid:100003256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/labesoftware/update/downloads/vpn_free.exe",nocase; classtype:trojan-activity; sid:100003257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/clr.exe",nocase; classtype:trojan-activity; sid:100003258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/dianthus.exe",nocase; classtype:trojan-activity; sid:100003259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/n.exe",nocase; classtype:trojan-activity; sid:100003260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/newred.exe",nocase; classtype:trojan-activity; sid:100003261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/omar.exe",nocase; classtype:trojan-activity; sid:100003262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/serv.exe",nocase; classtype:trojan-activity; sid:100003263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/test.exe",nocase; classtype:trojan-activity; sid:100003264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updachrome.exe",nocase; classtype:trojan-activity; sid:100003265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatedata.exe",nocase; classtype:trojan-activity; sid:100003266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatev.exe",nocase; classtype:trojan-activity; sid:100003267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/work.exe",nocase; classtype:trojan-activity; sid:100003268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/component.exe",nocase; classtype:trojan-activity; sid:100003269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe",nocase; classtype:trojan-activity; sid:100003270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/regsvc.exe",nocase; classtype:trojan-activity; sid:100003271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/skygaming/updates/downloads/update.exe",nocase; classtype:trojan-activity; sid:100003272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/001.txt",nocase; classtype:trojan-activity; sid:100003273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1488.txt",nocase; classtype:trojan-activity; sid:100003274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1_cr.txt",nocase; classtype:trojan-activity; sid:100003275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1cr.txt",nocase; classtype:trojan-activity; sid:100003276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1fc2d.txt",nocase; classtype:trojan-activity; sid:100003277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/26a5.txt",nocase; classtype:trojan-activity; sid:100003278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt",nocase; classtype:trojan-activity; sid:100003279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/abjects.txt",nocase; classtype:trojan-activity; sid:100003280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/attached.txt",nocase; classtype:trojan-activity; sid:100003281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/b7f2c.exe",nocase; classtype:trojan-activity; sid:100003282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/battletext.txt",nocase; classtype:trojan-activity; sid:100003283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe",nocase; classtype:trojan-activity; sid:100003284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe",nocase; classtype:trojan-activity; sid:100003285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build.txt",nocase; classtype:trojan-activity; sid:100003286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_makros.exe",nocase; classtype:trojan-activity; sid:100003287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_silent.txt",nocase; classtype:trojan-activity; sid:100003288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_sup.txt",nocase; classtype:trojan-activity; sid:100003289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe",nocase; classtype:trojan-activity; sid:100003290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt",nocase; classtype:trojan-activity; sid:100003291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcr.txt",nocase; classtype:trojan-activity; sid:100003292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildss.txt",nocase; classtype:trojan-activity; sid:100003293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientnik.txt",nocase; classtype:trojan-activity; sid:100003294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientrevers.txt",nocase; classtype:trojan-activity; sid:100003295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dcrat.exe",nocase; classtype:trojan-activity; sid:100003296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices.exe",nocase; classtype:trojan-activity; sid:100003297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices2.exe",nocase; classtype:trojan-activity; sid:100003298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe",nocase; classtype:trojan-activity; sid:100003299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hans.txt",nocase; classtype:trojan-activity; sid:100003300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hulu.txt",nocase; classtype:trojan-activity; sid:100003301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfive.txt",nocase; classtype:trojan-activity; sid:100003302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfour.txt",nocase; classtype:trojan-activity; sid:100003303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelone.txt",nocase; classtype:trojan-activity; sid:100003304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelthree.txt",nocase; classtype:trojan-activity; sid:100003305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/inteltwo.txt",nocase; classtype:trojan-activity; sid:100003306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe",nocase; classtype:trojan-activity; sid:100003307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/kleiman.exe",nocase; classtype:trojan-activity; sid:100003308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe",nocase; classtype:trojan-activity; sid:100003309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/notepadplus.txt",nocase; classtype:trojan-activity; sid:100003310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe",nocase; classtype:trojan-activity; sid:100003311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.exe",nocase; classtype:trojan-activity; sid:100003312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.txt",nocase; classtype:trojan-activity; sid:100003313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt",nocase; classtype:trojan-activity; sid:100003314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/putty.txt",nocase; classtype:trojan-activity; sid:100003315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/rockethcd.txt",nocase; classtype:trojan-activity; sid:100003316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/scvhost900.exe",nocase; classtype:trojan-activity; sid:100003317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/sessionwin.exe",nocase; classtype:trojan-activity; sid:100003318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/siliculose.txt",nocase; classtype:trojan-activity; sid:100003319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/statemobi.txt",nocase; classtype:trojan-activity; sid:100003320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers.exe",nocase; classtype:trojan-activity; sid:100003321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers2.exe",nocase; classtype:trojan-activity; sid:100003322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stgedo.exe",nocase; classtype:trojan-activity; sid:100003323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/svcperf.txt",nocase; classtype:trojan-activity; sid:100003324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe",nocase; classtype:trojan-activity; sid:100003325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurjok.txt",nocase; classtype:trojan-activity; sid:100003326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurusbabac.exe",nocase; classtype:trojan-activity; sid:100003327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/telekiller.exe",nocase; classtype:trojan-activity; sid:100003328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateanddr.txt",nocase; classtype:trojan-activity; sid:100003329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateandr.txt",nocase; classtype:trojan-activity; sid:100003330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/vhajeja.txt",nocase; classtype:trojan-activity; sid:100003331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/word.txt",nocase; classtype:trojan-activity; sid:100003332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/www.txt",nocase; classtype:trojan-activity; sid:100003333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/xlsd.txt",nocase; classtype:trojan-activity; sid:100003334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin",nocase; classtype:trojan-activity; sid:100003335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin",nocase; classtype:trojan-activity; sid:100003336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cd.textfiles.com",nocase; http_uri; content:"/hmatrix/data/hack1226.exe",nocase; classtype:trojan-activity; sid:100003337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/712408764354920490/829413679866839120/echelon_protected.exe",nocase; classtype:trojan-activity; sid:100003338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq",nocase; classtype:trojan-activity; sid:100003339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/816070119281131570/816070273254162442/all.txt",nocase; classtype:trojan-activity; sid:100003340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/826848185246023750/loaddd.exe",nocase; classtype:trojan-activity; sid:100003341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/826848348342059008/zeppelin.exe",nocase; classtype:trojan-activity; sid:100003342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/826848405258633277/build.exe",nocase; classtype:trojan-activity; sid:100003343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/826198252025675816/826537386485612574/china.png",nocase; classtype:trojan-activity; sid:100003344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin",nocase; classtype:trojan-activity; sid:100003345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe",nocase; classtype:trojan-activity; sid:100003346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/829721030112182363/829724335526510622/dcratbuild.exe",nocase; classtype:trojan-activity; sid:100003347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chiptune.com",nocase; http_uri; content:"/razor/rzr-winner_intro.zip",nocase; classtype:trojan-activity; sid:100003348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz",nocase; classtype:trojan-activity; sid:100003349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar",nocase; classtype:trojan-activity; sid:100003350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codeload.github.com",nocase; http_uri; content:"/meteoradminz/hidden-tear/zip/master",nocase; classtype:trojan-activity; sid:100003351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colfincas.com",nocase; http_uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/",nocase; classtype:trojan-activity; sid:100003352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?export=download&id=1ktcghnmcwws43wzscphukbfnwtuaxidx&revid=0b8z0b7_i5sirk2xrtehmstg0vxvit3b4n3lmbdrdrjrodndrpq",nocase; classtype:trojan-activity; sid:100003353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?export=download&id=1qze6qzzh1uf7iaj4rqixttznx6u1--gc&revid=0b45wwmcofx7fuvnmdhpkt1d0k3rhzldyoffnuc83auzkslvrpq",nocase; classtype:trojan-activity; sid:100003354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com.it-barcelona.com",nocase; http_uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe",nocase; classtype:trojan-activity; sid:100003355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm",nocase; classtype:trojan-activity; sid:100003356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=11idvvx22jx_1lw-hxnpmlwuvjgdyp63g",nocase; classtype:trojan-activity; sid:100003357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=12khl-unz2np4q54b2jgpwlsh6cuz0pss",nocase; classtype:trojan-activity; sid:100003358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch",nocase; classtype:trojan-activity; sid:100003359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox",nocase; classtype:trojan-activity; sid:100003360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=16yyvhney9_-nygeipjqgnlcmwfoyiaxo",nocase; classtype:trojan-activity; sid:100003361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=17pl-4i0otjbyxwrtrdagxxebirdh2wl8",nocase; classtype:trojan-activity; sid:100003362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig",nocase; classtype:trojan-activity; sid:100003363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn",nocase; classtype:trojan-activity; sid:100003364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1br5iufkkmmfeipqo3ecviqykbcdgcnio",nocase; classtype:trojan-activity; sid:100003365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1bwtwpqmeqdvctbcqcc2gil5xzjf28c0z",nocase; classtype:trojan-activity; sid:100003366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv",nocase; classtype:trojan-activity; sid:100003367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben",nocase; classtype:trojan-activity; sid:100003368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1d0ij6qkgrf6irywv6ftk1m7p5l3weh3a",nocase; classtype:trojan-activity; sid:100003369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1gprlk2mcrl6law-zk5r0pjogaqrxwepd",nocase; classtype:trojan-activity; sid:100003370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei",nocase; classtype:trojan-activity; sid:100003371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr",nocase; classtype:trojan-activity; sid:100003372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1jdqcxydqvz3bjodp66ieiocbjcz8foi6",nocase; classtype:trojan-activity; sid:100003373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1l5urks5wzib2zcb16bfsk76bjrdsejms",nocase; classtype:trojan-activity; sid:100003374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ldxaekbcbzb-zfdix-ucj4rilobnbswx",nocase; classtype:trojan-activity; sid:100003375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ljz-kmuibyiehba6blw37guu_yr799y0",nocase; classtype:trojan-activity; sid:100003376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1lsv4sko083sywwjndgqnsh_6sgqodqtu",nocase; classtype:trojan-activity; sid:100003377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y",nocase; classtype:trojan-activity; sid:100003378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd",nocase; classtype:trojan-activity; sid:100003379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw",nocase; classtype:trojan-activity; sid:100003380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1oek6vmzbv15nyho_uqcbk4_vaq1ezowv",nocase; classtype:trojan-activity; sid:100003381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ph-lri07dohowhmuczrrvjwrtsvmnu9s",nocase; classtype:trojan-activity; sid:100003382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej",nocase; classtype:trojan-activity; sid:100003383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1r1flwyfwtyziyr47y5sk3q821r6_tgsl",nocase; classtype:trojan-activity; sid:100003384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1r9f9irwhutxozsbp2h9erd_a7fa2pwko",nocase; classtype:trojan-activity; sid:100003385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1s221a6wpx6i7nfrztnhh9priojtybuxq",nocase; classtype:trojan-activity; sid:100003386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1sutnyikgc4qw-tbvnnvzm8uz9thch0vz",nocase; classtype:trojan-activity; sid:100003387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn",nocase; classtype:trojan-activity; sid:100003388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1taubixyqiqdgfbhmc2rv_aitvkbqhzwz",nocase; classtype:trojan-activity; sid:100003389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1tpd_qbnl_mtmhfsv4a-qtfsnuiimyoy6",nocase; classtype:trojan-activity; sid:100003390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t",nocase; classtype:trojan-activity; sid:100003391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vjq92eqivh01yxmal20whl2es3ld6nxb",nocase; classtype:trojan-activity; sid:100003392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1voqnsh0cmxl5hty4zpc18pgnkud5rtvy",nocase; classtype:trojan-activity; sid:100003393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vy1nx5zefluh5ewihr-6pcndlyex7xcm",nocase; classtype:trojan-activity; sid:100003394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1wpqa2nnnktbhzs4j0r-erosvgyaagi_a",nocase; classtype:trojan-activity; sid:100003395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e",nocase; classtype:trojan-activity; sid:100003396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi",nocase; classtype:trojan-activity; sid:100003397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58",nocase; classtype:trojan-activity; sid:100003398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi",nocase; classtype:trojan-activity; sid:100003399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ywkgalidldb32pio6ywmbyvdk7oar3yy",nocase; classtype:trojan-activity; sid:100003400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr",nocase; classtype:trojan-activity; sid:100003401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0",nocase; classtype:trojan-activity; sid:100003402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/1zilg/",nocase; classtype:trojan-activity; sid:100003403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/qcgfmfvh/",nocase; classtype:trojan-activity; sid:100003404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-mudhra.com",nocase; http_uri; content:"/downloads/emclick.zip",nocase; classtype:trojan-activity; sid:100003405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evertkok.nl",nocase; http_uri; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe",nocase; classtype:trojan-activity; sid:100003406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evertkok.nl",nocase; http_uri; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe",nocase; classtype:trojan-activity; sid:100003407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/",nocase; classtype:trojan-activity; sid:100003408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/",nocase; classtype:trojan-activity; sid:100003409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/x/",nocase; classtype:trojan-activity; sid:100003410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/",nocase; classtype:trojan-activity; sid:100003411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//",nocase; classtype:trojan-activity; sid:100003412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///",nocase; classtype:trojan-activity; sid:100003413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////",nocase; classtype:trojan-activity; sid:100003414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"file.elecfans.com",nocase; http_uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe",nocase; classtype:trojan-activity; sid:100003415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls",nocase; classtype:trojan-activity; sid:100003416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx",nocase; classtype:trojan-activity; sid:100003417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gist.githubusercontent.com",nocase; http_uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe",nocase; classtype:trojan-activity; sid:100003418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hqdecig.com",nocase; http_uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/",nocase; classtype:trojan-activity; sid:100003419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsecaravans.co.uk",nocase; http_uri; content:"/wp-admin/suy/",nocase; classtype:trojan-activity; sid:100003420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ia801802.us.archive.org",nocase; http_uri; content:"/19/items/startup_20210219/startup.txt",nocase; classtype:trojan-activity; sid:100003421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ie-best.net",nocase; http_uri; content:"/online-timer-kvhxz/ilxl/",nocase; classtype:trojan-activity; sid:100003422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100003423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jcedu.org",nocase; http_uri; content:"/ebook/cs17.exe",nocase; classtype:trojan-activity; sid:100003424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1",nocase; classtype:trojan-activity; sid:100003425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2",nocase; classtype:trojan-activity; sid:100003426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3",nocase; classtype:trojan-activity; sid:100003427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karmakoincodes.weebly.com",nocase; http_uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe",nocase; classtype:trojan-activity; sid:100003428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kautilyaclasses.com",nocase; http_uri; content:"/ds/index.html",nocase; classtype:trojan-activity; sid:100003429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kotakwarna.co.id",nocase; http_uri; content:"/dg/etrac/nf4emwz/",nocase; classtype:trojan-activity; sid:100003430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ksh.hu",nocase; http_uri; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe",nocase; classtype:trojan-activity; sid:100003431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kuaizip.com",nocase; http_uri; content:"/down/affiliate/kuaizip_setup_10029.exe",nocase; classtype:trojan-activity; sid:100003432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linuxforensicsbook.com.s3.amazonaws.com",nocase; http_uri; content:"/linuxforensicscode.zip",nocase; classtype:trojan-activity; sid:100003433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lojavirtual.top",nocase; http_uri; content:"/dl8.exe",nocase; classtype:trojan-activity; sid:100003434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lojavirtual.top",nocase; http_uri; content:"/dl8v2.exe",nocase; classtype:trojan-activity; sid:100003435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minpic.de",nocase; http_uri; content:"/k/big5/1giof6/",nocase; classtype:trojan-activity; sid:100003436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"morrobaydrugandgift.com",nocase; http_uri; content:"/wp-contentbak/t9m/",nocase; classtype:trojan-activity; sid:100003437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"my.cloudme.com",nocase; http_uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe",nocase; classtype:trojan-activity; sid:100003438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/aacenc.exe",nocase; classtype:trojan-activity; sid:100003439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/doxillionsetup.exe",nocase; classtype:trojan-activity; sid:100003440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newyarlfm.weebly.com",nocase; http_uri; content:"/uploads/4/1/6/6/4166984/keygen.exe",nocase; classtype:trojan-activity; sid:100003441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhipcauytevietnhat.com",nocase; http_uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/",nocase; classtype:trojan-activity; sid:100003442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"note.youdao.com",nocase; http_uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a",nocase; classtype:trojan-activity; sid:100003443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oldschoolvalue.s3.amazonaws.com",nocase; http_uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe",nocase; classtype:trojan-activity; sid:100003444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20cid=ba02d68febf523dc&resid=ba02d68febf523dc!1431&authkey=afbifi7o9ywbjpm",nocase; classtype:trojan-activity; sid:100003445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20cid=ba02d68febf523dc&resid=ba02d68febf523dc%211431&authkey=afbifi7o9ywbjpm",nocase; classtype:trojan-activity; sid:100003446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa",nocase; classtype:trojan-activity; sid:100003447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq",nocase; classtype:trojan-activity; sid:100003448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe",nocase; classtype:trojan-activity; sid:100003449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg",nocase; classtype:trojan-activity; sid:100003450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0",nocase; classtype:trojan-activity; sid:100003451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g",nocase; classtype:trojan-activity; sid:100003452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140",nocase; classtype:trojan-activity; sid:100003453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130",nocase; classtype:trojan-activity; sid:100003454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135",nocase; classtype:trojan-activity; sid:100003455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732",nocase; classtype:trojan-activity; sid:100003456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4",nocase; classtype:trojan-activity; sid:100003457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100003458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0",nocase; classtype:trojan-activity; sid:100003459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100003460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100003461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100003462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100003463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc",nocase; classtype:trojan-activity; sid:100003464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq",nocase; classtype:trojan-activity; sid:100003465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko",nocase; classtype:trojan-activity; sid:100003466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw",nocase; classtype:trojan-activity; sid:100003467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma",nocase; classtype:trojan-activity; sid:100003468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48",nocase; classtype:trojan-activity; sid:100003469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq",nocase; classtype:trojan-activity; sid:100003470; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg",nocase; classtype:trojan-activity; sid:100003471; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw",nocase; classtype:trojan-activity; sid:100003472; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq",nocase; classtype:trojan-activity; sid:100003473; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d!184&authkey=ackbiiarirejcam",nocase; classtype:trojan-activity; sid:100003474; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d%21184&authkey=ackbiiarirejcam",nocase; classtype:trojan-activity; sid:100003475; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100003476; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100003477; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100003478; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100003479; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0!1667&authkey=an8otd7jzc7xgho",nocase; classtype:trojan-activity; sid:100003480; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0%211667&authkey=an8otd7jzc7xgho",nocase; classtype:trojan-activity; sid:100003481; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4",nocase; classtype:trojan-activity; sid:100003482; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100003483; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100003484; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw",nocase; classtype:trojan-activity; sid:100003485; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0",nocase; classtype:trojan-activity; sid:100003486; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a",nocase; classtype:trojan-activity; sid:100003487; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo",nocase; classtype:trojan-activity; sid:100003488; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=15d9646f4dbf9553&resid=15d9646f4dbf9553%21110&authkey=ag0eg1lha_lwgi0",nocase; classtype:trojan-activity; sid:100003489; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100003490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100003491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100003492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100003493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100003494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100003495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100003496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100003497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve",nocase; classtype:trojan-activity; sid:100003498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w",nocase; classtype:trojan-activity; sid:100003499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100003500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100003501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg",nocase; classtype:trojan-activity; sid:100003502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60",nocase; classtype:trojan-activity; sid:100003503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg",nocase; classtype:trojan-activity; sid:100003504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4",nocase; classtype:trojan-activity; sid:100003505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c",nocase; classtype:trojan-activity; sid:100003506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba!112&authkey=afjxmbcllibdbvo",nocase; classtype:trojan-activity; sid:100003507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba!114&authkey=adecqvkvvvadznc",nocase; classtype:trojan-activity; sid:100003508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba%21112&authkey=afjxmbcllibdbvo",nocase; classtype:trojan-activity; sid:100003509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba%21114&authkey=adecqvkvvvadznc",nocase; classtype:trojan-activity; sid:100003510; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=216ef243e34992b8&resid=216ef243e34992b8!330&authkey=apiugomnim7heom",nocase; classtype:trojan-activity; sid:100003511; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=216ef243e34992b8&resid=216ef243e34992b8%21330&authkey=apiugomnim7heom",nocase; classtype:trojan-activity; sid:100003512; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=23423a594eafc2de&resid=23423a594eafc2de%21130&authkey=aeh1dm0c-5hp44a",nocase; classtype:trojan-activity; sid:100003513; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po",nocase; classtype:trojan-activity; sid:100003514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe",nocase; classtype:trojan-activity; sid:100003515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk",nocase; classtype:trojan-activity; sid:100003516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100003517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100003518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu",nocase; classtype:trojan-activity; sid:100003519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k",nocase; classtype:trojan-activity; sid:100003520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo",nocase; classtype:trojan-activity; sid:100003521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga",nocase; classtype:trojan-activity; sid:100003522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b!287&authkey=advpfy_0ry8upmi",nocase; classtype:trojan-activity; sid:100003523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b!288&authkey=aembucxemjjo3bk",nocase; classtype:trojan-activity; sid:100003524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b%21287&authkey=advpfy_0ry8upmi",nocase; classtype:trojan-activity; sid:100003525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b%21288&authkey=aembucxemjjo3bk",nocase; classtype:trojan-activity; sid:100003526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0",nocase; classtype:trojan-activity; sid:100003527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620",nocase; classtype:trojan-activity; sid:100003528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo",nocase; classtype:trojan-activity; sid:100003529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e",nocase; classtype:trojan-activity; sid:100003530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100003531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100003532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4",nocase; classtype:trojan-activity; sid:100003533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w",nocase; classtype:trojan-activity; sid:100003534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100003535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8",nocase; classtype:trojan-activity; sid:100003536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100003537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw",nocase; classtype:trojan-activity; sid:100003538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3004cdd743a543f5&resid=3004cdd743a543f5%21170&authkey=ao8vz-4rkwuiyn8",nocase; classtype:trojan-activity; sid:100003539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100003540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100003541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100003542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100003543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq",nocase; classtype:trojan-activity; sid:100003544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o",nocase; classtype:trojan-activity; sid:100003545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1!223&authkey=aajr842bzum0yg8",nocase; classtype:trojan-activity; sid:100003546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8",nocase; classtype:trojan-activity; sid:100003547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc",nocase; classtype:trojan-activity; sid:100003548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0",nocase; classtype:trojan-activity; sid:100003549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8",nocase; classtype:trojan-activity; sid:100003550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus",nocase; classtype:trojan-activity; sid:100003551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100003552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100003553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100003554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100003555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100003556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100003557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100003558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100003559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk",nocase; classtype:trojan-activity; sid:100003560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4",nocase; classtype:trojan-activity; sid:100003561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4",nocase; classtype:trojan-activity; sid:100003562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge",nocase; classtype:trojan-activity; sid:100003563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs",nocase; classtype:trojan-activity; sid:100003564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3ee68228c34c236d&resid=3ee68228c34c236d%21129&authkey=apll6hu3-xetzxu",nocase; classtype:trojan-activity; sid:100003565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100003566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100003567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100003568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100003569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0",nocase; classtype:trojan-activity; sid:100003570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100003571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100003572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik",nocase; classtype:trojan-activity; sid:100003573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq",nocase; classtype:trojan-activity; sid:100003574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy",nocase; classtype:trojan-activity; sid:100003575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21141&authkey=aazwaw2xjms24o0",nocase; classtype:trojan-activity; sid:100003576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21145&authkey=aaenjqj018fjmc0",nocase; classtype:trojan-activity; sid:100003577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100003578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100003579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y",nocase; classtype:trojan-activity; sid:100003580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100003581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100003582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100003583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100003584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo",nocase; classtype:trojan-activity; sid:100003585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4",nocase; classtype:trojan-activity; sid:100003586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm",nocase; classtype:trojan-activity; sid:100003587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu",nocase; classtype:trojan-activity; sid:100003588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100003589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100003590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc",nocase; classtype:trojan-activity; sid:100003591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y",nocase; classtype:trojan-activity; sid:100003592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8",nocase; classtype:trojan-activity; sid:100003593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0",nocase; classtype:trojan-activity; sid:100003594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc",nocase; classtype:trojan-activity; sid:100003595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs",nocase; classtype:trojan-activity; sid:100003596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts",nocase; classtype:trojan-activity; sid:100003597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc",nocase; classtype:trojan-activity; sid:100003598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg",nocase; classtype:trojan-activity; sid:100003599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y",nocase; classtype:trojan-activity; sid:100003600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday",nocase; classtype:trojan-activity; sid:100003601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0",nocase; classtype:trojan-activity; sid:100003602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas",nocase; classtype:trojan-activity; sid:100003603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve",nocase; classtype:trojan-activity; sid:100003604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy",nocase; classtype:trojan-activity; sid:100003605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14",nocase; classtype:trojan-activity; sid:100003606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i",nocase; classtype:trojan-activity; sid:100003607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa",nocase; classtype:trojan-activity; sid:100003608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu",nocase; classtype:trojan-activity; sid:100003609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c",nocase; classtype:trojan-activity; sid:100003610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy",nocase; classtype:trojan-activity; sid:100003611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q",nocase; classtype:trojan-activity; sid:100003612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm",nocase; classtype:trojan-activity; sid:100003613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4",nocase; classtype:trojan-activity; sid:100003614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho",nocase; classtype:trojan-activity; sid:100003615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18",nocase; classtype:trojan-activity; sid:100003616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q",nocase; classtype:trojan-activity; sid:100003617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm",nocase; classtype:trojan-activity; sid:100003618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na",nocase; classtype:trojan-activity; sid:100003619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk",nocase; classtype:trojan-activity; sid:100003620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe",nocase; classtype:trojan-activity; sid:100003621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi",nocase; classtype:trojan-activity; sid:100003622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc",nocase; classtype:trojan-activity; sid:100003623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc",nocase; classtype:trojan-activity; sid:100003624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100003625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100003626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100003627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100003628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100003629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100003630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100003631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100003632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100003633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100003634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100003635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100003636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4",nocase; classtype:trojan-activity; sid:100003637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu",nocase; classtype:trojan-activity; sid:100003638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi",nocase; classtype:trojan-activity; sid:100003639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8",nocase; classtype:trojan-activity; sid:100003640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8",nocase; classtype:trojan-activity; sid:100003641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100003642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100003643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8",nocase; classtype:trojan-activity; sid:100003644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100003645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100003646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100003647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100003648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g",nocase; classtype:trojan-activity; sid:100003649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum",nocase; classtype:trojan-activity; sid:100003650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi",nocase; classtype:trojan-activity; sid:100003651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy",nocase; classtype:trojan-activity; sid:100003652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o",nocase; classtype:trojan-activity; sid:100003653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa",nocase; classtype:trojan-activity; sid:100003654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100003655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100003656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc",nocase; classtype:trojan-activity; sid:100003657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk",nocase; classtype:trojan-activity; sid:100003658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea",nocase; classtype:trojan-activity; sid:100003659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100003660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100003661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100003662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100003663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100003664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100003665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo",nocase; classtype:trojan-activity; sid:100003666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva",nocase; classtype:trojan-activity; sid:100003667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc",nocase; classtype:trojan-activity; sid:100003668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles",nocase; classtype:trojan-activity; sid:100003669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg",nocase; classtype:trojan-activity; sid:100003670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100003671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100003672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100003673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100003674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw",nocase; classtype:trojan-activity; sid:100003675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8",nocase; classtype:trojan-activity; sid:100003676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq",nocase; classtype:trojan-activity; sid:100003677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug",nocase; classtype:trojan-activity; sid:100003678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe",nocase; classtype:trojan-activity; sid:100003679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i",nocase; classtype:trojan-activity; sid:100003680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa",nocase; classtype:trojan-activity; sid:100003681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe",nocase; classtype:trojan-activity; sid:100003682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m",nocase; classtype:trojan-activity; sid:100003683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi",nocase; classtype:trojan-activity; sid:100003684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi",nocase; classtype:trojan-activity; sid:100003685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e",nocase; classtype:trojan-activity; sid:100003686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100003687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c",nocase; classtype:trojan-activity; sid:100003688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100003689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c",nocase; classtype:trojan-activity; sid:100003690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk",nocase; classtype:trojan-activity; sid:100003691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4",nocase; classtype:trojan-activity; sid:100003692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo",nocase; classtype:trojan-activity; sid:100003693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100003694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100003695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg",nocase; classtype:trojan-activity; sid:100003696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70",nocase; classtype:trojan-activity; sid:100003697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc",nocase; classtype:trojan-activity; sid:100003698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100003699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100003700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100003701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100003702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw",nocase; classtype:trojan-activity; sid:100003703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq",nocase; classtype:trojan-activity; sid:100003704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm",nocase; classtype:trojan-activity; sid:100003705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100003706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100003707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100003708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100003709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu",nocase; classtype:trojan-activity; sid:100003710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i",nocase; classtype:trojan-activity; sid:100003711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam",nocase; classtype:trojan-activity; sid:100003712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble",nocase; classtype:trojan-activity; sid:100003713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60",nocase; classtype:trojan-activity; sid:100003714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k",nocase; classtype:trojan-activity; sid:100003715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8",nocase; classtype:trojan-activity; sid:100003716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg",nocase; classtype:trojan-activity; sid:100003717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte",nocase; classtype:trojan-activity; sid:100003718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34",nocase; classtype:trojan-activity; sid:100003719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w",nocase; classtype:trojan-activity; sid:100003720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta",nocase; classtype:trojan-activity; sid:100003721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em",nocase; classtype:trojan-activity; sid:100003722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100003723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100003724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100003725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100003726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm",nocase; classtype:trojan-activity; sid:100003727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100003728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100003729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100003730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100003731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100003732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100003733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs",nocase; classtype:trojan-activity; sid:100003734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c",nocase; classtype:trojan-activity; sid:100003735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0",nocase; classtype:trojan-activity; sid:100003736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq",nocase; classtype:trojan-activity; sid:100003737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda",nocase; classtype:trojan-activity; sid:100003738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm",nocase; classtype:trojan-activity; sid:100003739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=855b20b0e8399717&resid=855b20b0e8399717%21110&authkey=afhxx21ztsd7hbm",nocase; classtype:trojan-activity; sid:100003740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk",nocase; classtype:trojan-activity; sid:100003741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4",nocase; classtype:trojan-activity; sid:100003742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c",nocase; classtype:trojan-activity; sid:100003743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100003744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100003745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4",nocase; classtype:trojan-activity; sid:100003746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk",nocase; classtype:trojan-activity; sid:100003747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk",nocase; classtype:trojan-activity; sid:100003748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0",nocase; classtype:trojan-activity; sid:100003749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s",nocase; classtype:trojan-activity; sid:100003750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my",nocase; classtype:trojan-activity; sid:100003751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc",nocase; classtype:trojan-activity; sid:100003752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby",nocase; classtype:trojan-activity; sid:100003753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo",nocase; classtype:trojan-activity; sid:100003754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti",nocase; classtype:trojan-activity; sid:100003755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!112&authkey=af43qpcgl0t2f5o",nocase; classtype:trojan-activity; sid:100003756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8",nocase; classtype:trojan-activity; sid:100003757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o",nocase; classtype:trojan-activity; sid:100003758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8",nocase; classtype:trojan-activity; sid:100003759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m",nocase; classtype:trojan-activity; sid:100003760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w",nocase; classtype:trojan-activity; sid:100003761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100003762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100003763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k",nocase; classtype:trojan-activity; sid:100003764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue",nocase; classtype:trojan-activity; sid:100003765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc",nocase; classtype:trojan-activity; sid:100003766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w",nocase; classtype:trojan-activity; sid:100003767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm",nocase; classtype:trojan-activity; sid:100003768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0",nocase; classtype:trojan-activity; sid:100003769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy",nocase; classtype:trojan-activity; sid:100003770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm",nocase; classtype:trojan-activity; sid:100003771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi",nocase; classtype:trojan-activity; sid:100003772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi",nocase; classtype:trojan-activity; sid:100003773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8",nocase; classtype:trojan-activity; sid:100003774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100003775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100003776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o",nocase; classtype:trojan-activity; sid:100003777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4",nocase; classtype:trojan-activity; sid:100003778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi",nocase; classtype:trojan-activity; sid:100003779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100003780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100003781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo",nocase; classtype:trojan-activity; sid:100003782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq",nocase; classtype:trojan-activity; sid:100003783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi",nocase; classtype:trojan-activity; sid:100003784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs",nocase; classtype:trojan-activity; sid:100003785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw",nocase; classtype:trojan-activity; sid:100003786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o",nocase; classtype:trojan-activity; sid:100003787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs",nocase; classtype:trojan-activity; sid:100003788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw",nocase; classtype:trojan-activity; sid:100003789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu",nocase; classtype:trojan-activity; sid:100003790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21256&authkey=aapnly5qifymcvw",nocase; classtype:trojan-activity; sid:100003791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100003792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100003793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi",nocase; classtype:trojan-activity; sid:100003794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc",nocase; classtype:trojan-activity; sid:100003795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy",nocase; classtype:trojan-activity; sid:100003796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc",nocase; classtype:trojan-activity; sid:100003797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey",nocase; classtype:trojan-activity; sid:100003798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg",nocase; classtype:trojan-activity; sid:100003799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui",nocase; classtype:trojan-activity; sid:100003800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818!129&authkey=aesewk3cf5vbrxw",nocase; classtype:trojan-activity; sid:100003801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818%21129&authkey=aesewk3cf5vbrxw",nocase; classtype:trojan-activity; sid:100003802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk",nocase; classtype:trojan-activity; sid:100003803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5!2423&authkey=aoiqjwenlzfiqe0",nocase; classtype:trojan-activity; sid:100003804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212417&authkey=aa2zjoxjz1c83ns",nocase; classtype:trojan-activity; sid:100003805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212418&authkey=akjeumqon_fyj9c",nocase; classtype:trojan-activity; sid:100003806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212423&authkey=aoiqjwenlzfiqe0",nocase; classtype:trojan-activity; sid:100003807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw",nocase; classtype:trojan-activity; sid:100003808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100003809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100003810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e",nocase; classtype:trojan-activity; sid:100003811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100003812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100003813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u",nocase; classtype:trojan-activity; sid:100003814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm",nocase; classtype:trojan-activity; sid:100003815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy",nocase; classtype:trojan-activity; sid:100003816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc",nocase; classtype:trojan-activity; sid:100003817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy",nocase; classtype:trojan-activity; sid:100003818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84",nocase; classtype:trojan-activity; sid:100003819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo",nocase; classtype:trojan-activity; sid:100003820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw",nocase; classtype:trojan-activity; sid:100003821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww",nocase; classtype:trojan-activity; sid:100003822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy",nocase; classtype:trojan-activity; sid:100003823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w",nocase; classtype:trojan-activity; sid:100003824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq",nocase; classtype:trojan-activity; sid:100003825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100003826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100003827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg",nocase; classtype:trojan-activity; sid:100003828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg",nocase; classtype:trojan-activity; sid:100003829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100003830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100003831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m",nocase; classtype:trojan-activity; sid:100003832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8",nocase; classtype:trojan-activity; sid:100003833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ba02d68febf523dc&resid=ba02d68febf523dc%211431&authkey=afbifi7o9ywbjpm",nocase; classtype:trojan-activity; sid:100003834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1047&authkey=aod6jbxyicq2v4g",nocase; classtype:trojan-activity; sid:100003835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211047&authkey=aod6jbxyicq2v4g",nocase; classtype:trojan-activity; sid:100003836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100003837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100003838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq",nocase; classtype:trojan-activity; sid:100003839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm",nocase; classtype:trojan-activity; sid:100003840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai",nocase; classtype:trojan-activity; sid:100003841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk",nocase; classtype:trojan-activity; sid:100003842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c29fdbf45b3d2671&resid=c29fdbf45b3d2671%21608&authkey=aafwhzmybg1czta",nocase; classtype:trojan-activity; sid:100003843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100003844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100003845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100003846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100003847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100003848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100003849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100003850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100003851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100003852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100003853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100003854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100003855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100003856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100003857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100003858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100003859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100003860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100003861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100003862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100003863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8",nocase; classtype:trojan-activity; sid:100003864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc",nocase; classtype:trojan-activity; sid:100003865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc",nocase; classtype:trojan-activity; sid:100003866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs",nocase; classtype:trojan-activity; sid:100003867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m",nocase; classtype:trojan-activity; sid:100003868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga",nocase; classtype:trojan-activity; sid:100003869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk",nocase; classtype:trojan-activity; sid:100003870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!357&authkey=alw3vqqxz6myrle",nocase; classtype:trojan-activity; sid:100003871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!362&authkey=alycl9izrvfl7oc",nocase; classtype:trojan-activity; sid:100003872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21354&authkey=aa_ukeour7rex1s",nocase; classtype:trojan-activity; sid:100003873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21355&authkey=aajjwf_sm4xdqdk",nocase; classtype:trojan-activity; sid:100003874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21357&authkey=alw3vqqxz6myrle",nocase; classtype:trojan-activity; sid:100003875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21362&authkey=alycl9izrvfl7oc",nocase; classtype:trojan-activity; sid:100003876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg",nocase; classtype:trojan-activity; sid:100003877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100003878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100003879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw",nocase; classtype:trojan-activity; sid:100003880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100003881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100003882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100003883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100003884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100003885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100003886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100003887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100003888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100003889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100003890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0",nocase; classtype:trojan-activity; sid:100003891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d4d413b6e7cf7088&resid=d4d413b6e7cf7088%211271&authkey=akz65bxpgvdxjb8",nocase; classtype:trojan-activity; sid:100003892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100003893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100003894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100003895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100003896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy",nocase; classtype:trojan-activity; sid:100003897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe",nocase; classtype:trojan-activity; sid:100003898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq",nocase; classtype:trojan-activity; sid:100003899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4",nocase; classtype:trojan-activity; sid:100003900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq",nocase; classtype:trojan-activity; sid:100003901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100003902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100003903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100003904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100003905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100003906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100003907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw",nocase; classtype:trojan-activity; sid:100003908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0",nocase; classtype:trojan-activity; sid:100003909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4",nocase; classtype:trojan-activity; sid:100003910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs",nocase; classtype:trojan-activity; sid:100003911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0",nocase; classtype:trojan-activity; sid:100003912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q",nocase; classtype:trojan-activity; sid:100003913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2!107&authkey=af-bicrg1c6vgck",nocase; classtype:trojan-activity; sid:100003914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2%21107&authkey=af-bicrg1c6vgck",nocase; classtype:trojan-activity; sid:100003915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co",nocase; classtype:trojan-activity; sid:100003916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co",nocase; classtype:trojan-activity; sid:100003917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc",nocase; classtype:trojan-activity; sid:100003918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc",nocase; classtype:trojan-activity; sid:100003919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0",nocase; classtype:trojan-activity; sid:100003920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c",nocase; classtype:trojan-activity; sid:100003921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg",nocase; classtype:trojan-activity; sid:100003922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100003923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100003924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq",nocase; classtype:trojan-activity; sid:100003925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke",nocase; classtype:trojan-activity; sid:100003926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom",nocase; classtype:trojan-activity; sid:100003927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da",nocase; classtype:trojan-activity; sid:100003928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100003929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100003930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0",nocase; classtype:trojan-activity; sid:100003931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100003932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100003933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai",nocase; classtype:trojan-activity; sid:100003934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc",nocase; classtype:trojan-activity; sid:100003935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8",nocase; classtype:trojan-activity; sid:100003936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns",nocase; classtype:trojan-activity; sid:100003937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8",nocase; classtype:trojan-activity; sid:100003938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100003939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100003940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100003941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100003942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100003943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100003944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0",nocase; classtype:trojan-activity; sid:100003945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw",nocase; classtype:trojan-activity; sid:100003946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e",nocase; classtype:trojan-activity; sid:100003947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu",nocase; classtype:trojan-activity; sid:100003948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq",nocase; classtype:trojan-activity; sid:100003949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k",nocase; classtype:trojan-activity; sid:100003950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie",nocase; classtype:trojan-activity; sid:100003951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c",nocase; classtype:trojan-activity; sid:100003952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g",nocase; classtype:trojan-activity; sid:100003953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta",nocase; classtype:trojan-activity; sid:100003954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22",nocase; classtype:trojan-activity; sid:100003955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100003956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100003957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100003958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100003959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc",nocase; classtype:trojan-activity; sid:100003960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu",nocase; classtype:trojan-activity; sid:100003961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm",nocase; classtype:trojan-activity; sid:100003962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w",nocase; classtype:trojan-activity; sid:100003963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm",nocase; classtype:trojan-activity; sid:100003964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21848&authkey=ag1_e421v-t5r9w",nocase; classtype:trojan-activity; sid:100003965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw",nocase; classtype:trojan-activity; sid:100003966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100003967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100003968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100003969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100003970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100003971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100003972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg",nocase; classtype:trojan-activity; sid:100003973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100003974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm",nocase; classtype:trojan-activity; sid:100003975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100003976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/77jhk0iw",nocase; classtype:trojan-activity; sid:100003977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/89hkc7wb",nocase; classtype:trojan-activity; sid:100003978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/yqvsvlvq",nocase; classtype:trojan-activity; sid:100003979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pierreconsulting.info",nocase; http_uri; content:"/wp-admin/llc/mwcacs65xienqdp/",nocase; classtype:trojan-activity; sid:100003980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skoda22.jpg",nocase; classtype:trojan-activity; sid:100003981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg",nocase; classtype:trojan-activity; sid:100003982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qjbutterflyevents.co.za",nocase; http_uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/",nocase; classtype:trojan-activity; sid:100003983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll",nocase; classtype:trojan-activity; sid:100003984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe",nocase; classtype:trojan-activity; sid:100003985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe",nocase; classtype:trojan-activity; sid:100003986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe",nocase; classtype:trojan-activity; sid:100003987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe",nocase; classtype:trojan-activity; sid:100003988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar",nocase; classtype:trojan-activity; sid:100003989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/myqseeaccount/one/main/one.htm",nocase; classtype:trojan-activity; sid:100003990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp",nocase; classtype:trojan-activity; sid:100003991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe",nocase; classtype:trojan-activity; sid:100003992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe",nocase; classtype:trojan-activity; sid:100003993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/tennc/webshell/master/other/small_shell.txt",nocase; classtype:trojan-activity; sid:100003994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.yeshen.com",nocase; http_uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe",nocase; classtype:trojan-activity; sid:100003995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sendspace.com",nocase; http_uri; content:"/pro/dl/q05z91",nocase; classtype:trojan-activity; sid:100003996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shribharatvatika.com",nocase; http_uri; content:"/ey4lpx8rx.zip",nocase; classtype:trojan-activity; sid:100003997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sites.google.com",nocase; http_uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0",nocase; classtype:trojan-activity; sid:100003998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt",nocase; classtype:trojan-activity; sid:100003999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt",nocase; classtype:trojan-activity; sid:100004000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt",nocase; classtype:trojan-activity; sid:100004001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt",nocase; classtype:trojan-activity; sid:100004002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt",nocase; classtype:trojan-activity; sid:100004003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt",nocase; classtype:trojan-activity; sid:100004004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt",nocase; classtype:trojan-activity; sid:100004005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg",nocase; classtype:trojan-activity; sid:100004006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt",nocase; classtype:trojan-activity; sid:100004007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt",nocase; classtype:trojan-activity; sid:100004008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technologydistilled.com",nocase; http_uri; content:"/a-nurse-ss8d9/z/",nocase; classtype:trojan-activity; sid:100004009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"users.skynet.be",nocase; http_uri; content:"/crisanar/defis/jek_crackme1.7.zip",nocase; classtype:trojan-activity; sid:100004010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/amowvegfrt9ja/",nocase; classtype:trojan-activity; sid:100004011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/",nocase; classtype:trojan-activity; sid:100004012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100004013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100004014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe",nocase; classtype:trojan-activity; sid:100004015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb%5efr_ouverture.exe",nocase; classtype:trojan-activity; sid:100004016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb^fr_ouverture.exe",nocase; classtype:trojan-activity; sid:100004017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe",nocase; classtype:trojan-activity; sid:100004018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/151_155/tidex_-_short_stuff.exe",nocase; classtype:trojan-activity; sid:100004019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikileaks.org",nocase; http_uri; content:"/syria-files/attach/222/222051_instruction.zip",nocase; classtype:trojan-activity; sid:100004020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yp.hnggzyjy.cn",nocase; http_uri; content:"/common/yz.vbs",nocase; classtype:trojan-activity; sid:100004021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.139.242",nocase; classtype:trojan-activity; sid:100001515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.212.209",nocase; classtype:trojan-activity; sid:100001516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.253.149",nocase; classtype:trojan-activity; sid:100001517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.71.243",nocase; classtype:trojan-activity; sid:100001518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.98.242",nocase; classtype:trojan-activity; sid:100001519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.144.66",nocase; classtype:trojan-activity; sid:100001520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.225.28",nocase; classtype:trojan-activity; sid:100001521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.227.95",nocase; classtype:trojan-activity; sid:100001522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.234.98",nocase; classtype:trojan-activity; sid:100001523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.191.58",nocase; classtype:trojan-activity; sid:100001524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.135.3",nocase; classtype:trojan-activity; sid:100001525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.132.71",nocase; classtype:trojan-activity; sid:100001526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.160.112",nocase; classtype:trojan-activity; sid:100001527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.176.72",nocase; classtype:trojan-activity; sid:100001528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.83.244",nocase; classtype:trojan-activity; sid:100001529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.20.66",nocase; classtype:trojan-activity; sid:100001530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.249.0",nocase; classtype:trojan-activity; sid:100001531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.83.170",nocase; classtype:trojan-activity; sid:100001532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.85.168",nocase; classtype:trojan-activity; sid:100001533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.221.239.223",nocase; classtype:trojan-activity; sid:100001534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.221.242.95",nocase; classtype:trojan-activity; sid:100001535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.76.80",nocase; classtype:trojan-activity; sid:100001536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.223.242.164",nocase; classtype:trojan-activity; sid:100001537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.129.198",nocase; classtype:trojan-activity; sid:100001538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.154.13",nocase; classtype:trojan-activity; sid:100001539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.212.124",nocase; classtype:trojan-activity; sid:100001540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.58.5",nocase; classtype:trojan-activity; sid:100001541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.40.79.170",nocase; classtype:trojan-activity; sid:100001542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.36.97",nocase; classtype:trojan-activity; sid:100001543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.0.98.131",nocase; classtype:trojan-activity; sid:100001544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.11.51.57",nocase; classtype:trojan-activity; sid:100001545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.13.23.180",nocase; classtype:trojan-activity; sid:100001546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.124.130",nocase; classtype:trojan-activity; sid:100001547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.146.199",nocase; classtype:trojan-activity; sid:100001548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.16.68",nocase; classtype:trojan-activity; sid:100001549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.179.83",nocase; classtype:trojan-activity; sid:100001550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.184.59",nocase; classtype:trojan-activity; sid:100001551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.191.243",nocase; classtype:trojan-activity; sid:100001552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.194.67",nocase; classtype:trojan-activity; sid:100001553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.216.132",nocase; classtype:trojan-activity; sid:100001554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.219.28",nocase; classtype:trojan-activity; sid:100001555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.24.115",nocase; classtype:trojan-activity; sid:100001556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.30.65",nocase; classtype:trojan-activity; sid:100001557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.65.233",nocase; classtype:trojan-activity; sid:100001558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.79.66",nocase; classtype:trojan-activity; sid:100001559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.94.16",nocase; classtype:trojan-activity; sid:100001560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.179.201.26",nocase; classtype:trojan-activity; sid:100001561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.195.84.250",nocase; classtype:trojan-activity; sid:100001562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.138",nocase; classtype:trojan-activity; sid:100001563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.28.7.159",nocase; classtype:trojan-activity; sid:100001564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.30.119.23",nocase; classtype:trojan-activity; sid:100001565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32.208.157.193",nocase; classtype:trojan-activity; sid:100001566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32792.prolocksmithwinterpark.com",nocase; classtype:trojan-activity; sid:100001567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"34.122.44.188",nocase; classtype:trojan-activity; sid:100001568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"34.126.93.163",nocase; classtype:trojan-activity; sid:100001569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"35.184.169.169",nocase; classtype:trojan-activity; sid:100001570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.108.231.218",nocase; classtype:trojan-activity; sid:100001571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.248.83.98",nocase; classtype:trojan-activity; sid:100001572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.250.203.246",nocase; classtype:trojan-activity; sid:100001573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.157.225",nocase; classtype:trojan-activity; sid:100001574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.18.18",nocase; classtype:trojan-activity; sid:100001575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.51.244",nocase; classtype:trojan-activity; sid:100001576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.255.90.219",nocase; classtype:trojan-activity; sid:100001577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.32.28.18",nocase; classtype:trojan-activity; sid:100001578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.160.167",nocase; classtype:trojan-activity; sid:100001579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.34.150.236",nocase; classtype:trojan-activity; sid:100001580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.65.216.145",nocase; classtype:trojan-activity; sid:100001581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.105.159",nocase; classtype:trojan-activity; sid:100001582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.133.125",nocase; classtype:trojan-activity; sid:100001583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.139.36",nocase; classtype:trojan-activity; sid:100001584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.89.18.133",nocase; classtype:trojan-activity; sid:100001585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.91.89.187",nocase; classtype:trojan-activity; sid:100001586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360.lcy2zzx.pw",nocase; classtype:trojan-activity; sid:100001587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360down7.miiyun.cn",nocase; classtype:trojan-activity; sid:100001588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.222.98.51",nocase; classtype:trojan-activity; sid:100001589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.233.60.68",nocase; classtype:trojan-activity; sid:100001590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.179.221",nocase; classtype:trojan-activity; sid:100001591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.180.172",nocase; classtype:trojan-activity; sid:100001592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.44.238.35",nocase; classtype:trojan-activity; sid:100001593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.116.243",nocase; classtype:trojan-activity; sid:100001594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.14.36",nocase; classtype:trojan-activity; sid:100001595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.245.254",nocase; classtype:trojan-activity; sid:100001596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.98.136",nocase; classtype:trojan-activity; sid:100001597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.114.137.102",nocase; classtype:trojan-activity; sid:100001598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.117.31.162",nocase; classtype:trojan-activity; sid:100001599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.162.104.119",nocase; classtype:trojan-activity; sid:100001600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.162.98.216",nocase; classtype:trojan-activity; sid:100001601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.164.112.139",nocase; classtype:trojan-activity; sid:100001602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.196.34",nocase; classtype:trojan-activity; sid:100001603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.104.83",nocase; classtype:trojan-activity; sid:100001604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.125.186",nocase; classtype:trojan-activity; sid:100001605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.146.60",nocase; classtype:trojan-activity; sid:100001606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.206.228",nocase; classtype:trojan-activity; sid:100001607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.171.125",nocase; classtype:trojan-activity; sid:100001608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.249.255",nocase; classtype:trojan-activity; sid:100001609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.60.61",nocase; classtype:trojan-activity; sid:100001610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.167.202",nocase; classtype:trojan-activity; sid:100001611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.67.64",nocase; classtype:trojan-activity; sid:100001612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.10.198",nocase; classtype:trojan-activity; sid:100001613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.163.231",nocase; classtype:trojan-activity; sid:100001614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.168.234",nocase; classtype:trojan-activity; sid:100001615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.203.225",nocase; classtype:trojan-activity; sid:100001616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.215.212",nocase; classtype:trojan-activity; sid:100001617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.194.65",nocase; classtype:trojan-activity; sid:100001618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.78.251",nocase; classtype:trojan-activity; sid:100001619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.113.201",nocase; classtype:trojan-activity; sid:100001620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.114.45",nocase; classtype:trojan-activity; sid:100001621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.150.203",nocase; classtype:trojan-activity; sid:100001622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.123.189",nocase; classtype:trojan-activity; sid:100001623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.166.31",nocase; classtype:trojan-activity; sid:100001624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.218.46",nocase; classtype:trojan-activity; sid:100001625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.91.244",nocase; classtype:trojan-activity; sid:100001626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.93.171",nocase; classtype:trojan-activity; sid:100001627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.127.214",nocase; classtype:trojan-activity; sid:100001628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.18.140",nocase; classtype:trojan-activity; sid:100001629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.191.137",nocase; classtype:trojan-activity; sid:100001630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.205.255",nocase; classtype:trojan-activity; sid:100001631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.24.54",nocase; classtype:trojan-activity; sid:100001632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.36.151",nocase; classtype:trojan-activity; sid:100001633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.37.182",nocase; classtype:trojan-activity; sid:100001634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.251.0",nocase; classtype:trojan-activity; sid:100001635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.27.15",nocase; classtype:trojan-activity; sid:100001636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.29.231",nocase; classtype:trojan-activity; sid:100001637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.70.88",nocase; classtype:trojan-activity; sid:100001638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.83.185.108",nocase; classtype:trojan-activity; sid:100001639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.83.94.11",nocase; classtype:trojan-activity; sid:100001640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.115.152",nocase; classtype:trojan-activity; sid:100001641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.85.54.4",nocase; classtype:trojan-activity; sid:100001642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.211.20",nocase; classtype:trojan-activity; sid:100001643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.234.187",nocase; classtype:trojan-activity; sid:100001644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.78.244",nocase; classtype:trojan-activity; sid:100001645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.93.109",nocase; classtype:trojan-activity; sid:100001646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.96.227",nocase; classtype:trojan-activity; sid:100001647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.143.176",nocase; classtype:trojan-activity; sid:100001648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.233.131",nocase; classtype:trojan-activity; sid:100001649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.67.238",nocase; classtype:trojan-activity; sid:100001650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.72.9",nocase; classtype:trojan-activity; sid:100001651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.145.11",nocase; classtype:trojan-activity; sid:100001652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.36",nocase; classtype:trojan-activity; sid:100001653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.63.23",nocase; classtype:trojan-activity; sid:100001654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.90.86.212",nocase; classtype:trojan-activity; sid:100001655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"40.88.2.151",nocase; classtype:trojan-activity; sid:100001656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.139.209.46",nocase; classtype:trojan-activity; sid:100001657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.165.130.43",nocase; classtype:trojan-activity; sid:100001658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.193.192.100",nocase; classtype:trojan-activity; sid:100001659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.219.185.171",nocase; classtype:trojan-activity; sid:100001660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.226.60.115",nocase; classtype:trojan-activity; sid:100001661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.72.203.82",nocase; classtype:trojan-activity; sid:100001662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.76.157.2",nocase; classtype:trojan-activity; sid:100001663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.147",nocase; classtype:trojan-activity; sid:100001664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.152",nocase; classtype:trojan-activity; sid:100001665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.38",nocase; classtype:trojan-activity; sid:100001666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.59",nocase; classtype:trojan-activity; sid:100001667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.103",nocase; classtype:trojan-activity; sid:100001668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.197",nocase; classtype:trojan-activity; sid:100001669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.48",nocase; classtype:trojan-activity; sid:100001670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.202.101.181",nocase; classtype:trojan-activity; sid:100001671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.202.101.199",nocase; classtype:trojan-activity; sid:100001672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.171.165",nocase; classtype:trojan-activity; sid:100001673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.176.27",nocase; classtype:trojan-activity; sid:100001674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.254.220",nocase; classtype:trojan-activity; sid:100001675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.4.110",nocase; classtype:trojan-activity; sid:100001676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.222.189",nocase; classtype:trojan-activity; sid:100001677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.225.253",nocase; classtype:trojan-activity; sid:100001678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.40.143",nocase; classtype:trojan-activity; sid:100001679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.143.162",nocase; classtype:trojan-activity; sid:100001680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.233.97.141",nocase; classtype:trojan-activity; sid:100001681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.84.85",nocase; classtype:trojan-activity; sid:100001682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.161.72",nocase; classtype:trojan-activity; sid:100001683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.212.157",nocase; classtype:trojan-activity; sid:100001684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.237.114.80",nocase; classtype:trojan-activity; sid:100001685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.238.141.250",nocase; classtype:trojan-activity; sid:100001686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.61.99.155",nocase; classtype:trojan-activity; sid:100001687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.82.217.241",nocase; classtype:trojan-activity; sid:100001688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.230.207.204",nocase; classtype:trojan-activity; sid:100001689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.241.106.183",nocase; classtype:trojan-activity; sid:100001690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.252.8.94",nocase; classtype:trojan-activity; sid:100001691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.203.192",nocase; classtype:trojan-activity; sid:100001692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.135.134.228",nocase; classtype:trojan-activity; sid:100001693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.178",nocase; classtype:trojan-activity; sid:100001694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.182",nocase; classtype:trojan-activity; sid:100001695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.204",nocase; classtype:trojan-activity; sid:100001696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.224.165",nocase; classtype:trojan-activity; sid:100001697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.141.84.184",nocase; classtype:trojan-activity; sid:100001698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.118",nocase; classtype:trojan-activity; sid:100001699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.135",nocase; classtype:trojan-activity; sid:100001700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.213",nocase; classtype:trojan-activity; sid:100001701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.27",nocase; classtype:trojan-activity; sid:100001702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.47",nocase; classtype:trojan-activity; sid:100001703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.94",nocase; classtype:trojan-activity; sid:100001704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.15.143.191",nocase; classtype:trojan-activity; sid:100001705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.248",nocase; classtype:trojan-activity; sid:100001706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.109.205",nocase; classtype:trojan-activity; sid:100001707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.110.146",nocase; classtype:trojan-activity; sid:100001708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.130",nocase; classtype:trojan-activity; sid:100001709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.22.209.58",nocase; classtype:trojan-activity; sid:100001710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.229.53.148",nocase; classtype:trojan-activity; sid:100001711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.27.253.137",nocase; classtype:trojan-activity; sid:100001712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.51.104.59",nocase; classtype:trojan-activity; sid:100001713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.77.9.151",nocase; classtype:trojan-activity; sid:100001714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.85.90.131",nocase; classtype:trojan-activity; sid:100001715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.9.148.37",nocase; classtype:trojan-activity; sid:100001716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.92.108.35",nocase; classtype:trojan-activity; sid:100001717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.95.169.143",nocase; classtype:trojan-activity; sid:100001718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.95.169.147",nocase; classtype:trojan-activity; sid:100001719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.95.169.153",nocase; classtype:trojan-activity; sid:100001720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.172.75.231",nocase; classtype:trojan-activity; sid:100001721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.182.173.247",nocase; classtype:trojan-activity; sid:100001722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.20.63.218",nocase; classtype:trojan-activity; sid:100001723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.214.27.4",nocase; classtype:trojan-activity; sid:100001724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.214.35.50",nocase; classtype:trojan-activity; sid:100001725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.236.65.83",nocase; classtype:trojan-activity; sid:100001726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.24.130.254",nocase; classtype:trojan-activity; sid:100001727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.241.120.165",nocase; classtype:trojan-activity; sid:100001728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.243.179.115",nocase; classtype:trojan-activity; sid:100001729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.249.33.79",nocase; classtype:trojan-activity; sid:100001730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.25.242.211",nocase; classtype:trojan-activity; sid:100001731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.118.86",nocase; classtype:trojan-activity; sid:100001732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.86.128",nocase; classtype:trojan-activity; sid:100001733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.97.76.242",nocase; classtype:trojan-activity; sid:100001734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.136.96.53",nocase; classtype:trojan-activity; sid:100001735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.145.152.26",nocase; classtype:trojan-activity; sid:100001736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.157.97.71",nocase; classtype:trojan-activity; sid:100001737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.16.131.51",nocase; classtype:trojan-activity; sid:100001738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.21.202.98",nocase; classtype:trojan-activity; sid:100001739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.46.231.38",nocase; classtype:trojan-activity; sid:100001740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.162.113",nocase; classtype:trojan-activity; sid:100001741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.87.36",nocase; classtype:trojan-activity; sid:100001742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.143.43.93",nocase; classtype:trojan-activity; sid:100001743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.156.35.166",nocase; classtype:trojan-activity; sid:100001744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.158.201.200",nocase; classtype:trojan-activity; sid:100001745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.158.201.218",nocase; classtype:trojan-activity; sid:100001746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.20.121",nocase; classtype:trojan-activity; sid:100001747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.21.3",nocase; classtype:trojan-activity; sid:100001748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.174.182.99",nocase; classtype:trojan-activity; sid:100001749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.170.49",nocase; classtype:trojan-activity; sid:100001750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.178.183",nocase; classtype:trojan-activity; sid:100001751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.179.129",nocase; classtype:trojan-activity; sid:100001752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.14.122.233",nocase; classtype:trojan-activity; sid:100001753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.188.62.111",nocase; classtype:trojan-activity; sid:100001754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.95.226.154",nocase; classtype:trojan-activity; sid:100001755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.115.174.103",nocase; classtype:trojan-activity; sid:100001756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.115.174.106",nocase; classtype:trojan-activity; sid:100001757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.121.91.255",nocase; classtype:trojan-activity; sid:100001758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.247.83.66",nocase; classtype:trojan-activity; sid:100001759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.252.47.29",nocase; classtype:trojan-activity; sid:100001760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"51.89.77.2",nocase; classtype:trojan-activity; sid:100001761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.114.136",nocase; classtype:trojan-activity; sid:100001762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.180.122",nocase; classtype:trojan-activity; sid:100001763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.114.246.26",nocase; classtype:trojan-activity; sid:100001764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.162.92",nocase; classtype:trojan-activity; sid:100001765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.174.4",nocase; classtype:trojan-activity; sid:100001766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.125.191.4",nocase; classtype:trojan-activity; sid:100001767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.126.247.118",nocase; classtype:trojan-activity; sid:100001768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.141.122.109",nocase; classtype:trojan-activity; sid:100001769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.166.120",nocase; classtype:trojan-activity; sid:100001770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.200.124",nocase; classtype:trojan-activity; sid:100001771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.218.67.253",nocase; classtype:trojan-activity; sid:100001772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.22.212.107",nocase; classtype:trojan-activity; sid:100001773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.226.129.29",nocase; classtype:trojan-activity; sid:100001774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.230.89.42",nocase; classtype:trojan-activity; sid:100001775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.237.125.4",nocase; classtype:trojan-activity; sid:100001776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.238.42.192",nocase; classtype:trojan-activity; sid:100001777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.240.147.97",nocase; classtype:trojan-activity; sid:100001778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.241.78.55",nocase; classtype:trojan-activity; sid:100001779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.242.91.219",nocase; classtype:trojan-activity; sid:100001780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.22.24",nocase; classtype:trojan-activity; sid:100001781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.75.128",nocase; classtype:trojan-activity; sid:100001782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.75.146",nocase; classtype:trojan-activity; sid:100001783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.77.141",nocase; classtype:trojan-activity; sid:100001784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.80.36",nocase; classtype:trojan-activity; sid:100001785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.253.15.184",nocase; classtype:trojan-activity; sid:100001786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.51.219.200",nocase; classtype:trojan-activity; sid:100001787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.153",nocase; classtype:trojan-activity; sid:100001788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.39",nocase; classtype:trojan-activity; sid:100001789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.0.211.161",nocase; classtype:trojan-activity; sid:100001790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.102.168.189",nocase; classtype:trojan-activity; sid:100001791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.202.3",nocase; classtype:trojan-activity; sid:100001792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.214.4",nocase; classtype:trojan-activity; sid:100001793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.173.135.51",nocase; classtype:trojan-activity; sid:100001794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.175.63.177",nocase; classtype:trojan-activity; sid:100001795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.23.114.97",nocase; classtype:trojan-activity; sid:100001796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.26.181.228",nocase; classtype:trojan-activity; sid:100001797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.30.12.254",nocase; classtype:trojan-activity; sid:100001798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.50.23.23",nocase; classtype:trojan-activity; sid:100001799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.89.242.116",nocase; classtype:trojan-activity; sid:100001800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.217.215",nocase; classtype:trojan-activity; sid:100001801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.218.82",nocase; classtype:trojan-activity; sid:100001802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.21.140",nocase; classtype:trojan-activity; sid:100001803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.21.172",nocase; classtype:trojan-activity; sid:100001804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.94.182.212",nocase; classtype:trojan-activity; sid:100001805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.95.175.49",nocase; classtype:trojan-activity; sid:100001806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.170.146",nocase; classtype:trojan-activity; sid:100001807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.13.61.12",nocase; classtype:trojan-activity; sid:100001808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.122.57",nocase; classtype:trojan-activity; sid:100001809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.216.23",nocase; classtype:trojan-activity; sid:100001810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.233.94",nocase; classtype:trojan-activity; sid:100001811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.6.112",nocase; classtype:trojan-activity; sid:100001812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.80.216",nocase; classtype:trojan-activity; sid:100001813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.100.83",nocase; classtype:trojan-activity; sid:100001814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.111.39",nocase; classtype:trojan-activity; sid:100001815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.206.246",nocase; classtype:trojan-activity; sid:100001816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.218.31",nocase; classtype:trojan-activity; sid:100001817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.220.167",nocase; classtype:trojan-activity; sid:100001818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.254.178",nocase; classtype:trojan-activity; sid:100001819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.83.55",nocase; classtype:trojan-activity; sid:100001820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.214.53.159",nocase; classtype:trojan-activity; sid:100001821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.214.85.149",nocase; classtype:trojan-activity; sid:100001822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.177.196",nocase; classtype:trojan-activity; sid:100001823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.86.208",nocase; classtype:trojan-activity; sid:100001824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.4.72",nocase; classtype:trojan-activity; sid:100001825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.51.127",nocase; classtype:trojan-activity; sid:100001826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.60.174",nocase; classtype:trojan-activity; sid:100001827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.8.81",nocase; classtype:trojan-activity; sid:100001828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.10.121",nocase; classtype:trojan-activity; sid:100001829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.8.43",nocase; classtype:trojan-activity; sid:100001830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.146.108.150",nocase; classtype:trojan-activity; sid:100001831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.163.131.67",nocase; classtype:trojan-activity; sid:100001832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.91.194",nocase; classtype:trojan-activity; sid:100001833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.247.224.66",nocase; classtype:trojan-activity; sid:100001834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.150.101",nocase; classtype:trojan-activity; sid:100001835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.101.143",nocase; classtype:trojan-activity; sid:100001836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.186.186",nocase; classtype:trojan-activity; sid:100001837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.241.252",nocase; classtype:trojan-activity; sid:100001838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.57.40",nocase; classtype:trojan-activity; sid:100001839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.9.166",nocase; classtype:trojan-activity; sid:100001840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.97.68",nocase; classtype:trojan-activity; sid:100001841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.98.43",nocase; classtype:trojan-activity; sid:100001842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.99.161",nocase; classtype:trojan-activity; sid:100001843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.117.152",nocase; classtype:trojan-activity; sid:100001844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.103.56",nocase; classtype:trojan-activity; sid:100001845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.180.67",nocase; classtype:trojan-activity; sid:100001846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.181.7",nocase; classtype:trojan-activity; sid:100001847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.57.96.116",nocase; classtype:trojan-activity; sid:100001848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.170.60",nocase; classtype:trojan-activity; sid:100001849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.73.220",nocase; classtype:trojan-activity; sid:100001850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.61.218.23",nocase; classtype:trojan-activity; sid:100001851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.65.172.121",nocase; classtype:trojan-activity; sid:100001852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.0.22",nocase; classtype:trojan-activity; sid:100001853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.104.46",nocase; classtype:trojan-activity; sid:100001854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.110.59",nocase; classtype:trojan-activity; sid:100001855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.195",nocase; classtype:trojan-activity; sid:100001856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.255.60",nocase; classtype:trojan-activity; sid:100001857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.45.130",nocase; classtype:trojan-activity; sid:100001858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.98.144.75",nocase; classtype:trojan-activity; sid:100001859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.1.98.131",nocase; classtype:trojan-activity; sid:100001860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.141.73.58",nocase; classtype:trojan-activity; sid:100001861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.131.205",nocase; classtype:trojan-activity; sid:100001862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.143.46",nocase; classtype:trojan-activity; sid:100001863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.31.126.33",nocase; classtype:trojan-activity; sid:100001864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.149.66",nocase; classtype:trojan-activity; sid:100001865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.43.207.148",nocase; classtype:trojan-activity; sid:100001866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.90.165.236",nocase; classtype:trojan-activity; sid:100001867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"63.245.122.93",nocase; classtype:trojan-activity; sid:100001868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"64.233.154.99",nocase; classtype:trojan-activity; sid:100001869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.125.128.196",nocase; classtype:trojan-activity; sid:100001870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.26.155.131",nocase; classtype:trojan-activity; sid:100001871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.35.61.255",nocase; classtype:trojan-activity; sid:100001872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.108.199.144",nocase; classtype:trojan-activity; sid:100001873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.57.55.210",nocase; classtype:trojan-activity; sid:100001874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.74.7.197",nocase; classtype:trojan-activity; sid:100001875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.97.181.196",nocase; classtype:trojan-activity; sid:100001876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.245.151.203",nocase; classtype:trojan-activity; sid:100001877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.8.138.101",nocase; classtype:trojan-activity; sid:100001878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.83.49.234",nocase; classtype:trojan-activity; sid:100001879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.84.138.165",nocase; classtype:trojan-activity; sid:100001880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.148.103.248",nocase; classtype:trojan-activity; sid:100001881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.174.182.226",nocase; classtype:trojan-activity; sid:100001882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.175.107.153",nocase; classtype:trojan-activity; sid:100001883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.188.144.143",nocase; classtype:trojan-activity; sid:100001884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.204.88.29",nocase; classtype:trojan-activity; sid:100001885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.119.241",nocase; classtype:trojan-activity; sid:100001886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.78.33.33",nocase; classtype:trojan-activity; sid:100001887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.115.37.205",nocase; classtype:trojan-activity; sid:100001888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.120.237.255",nocase; classtype:trojan-activity; sid:100001889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.123.245.151",nocase; classtype:trojan-activity; sid:100001890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.124.231.110",nocase; classtype:trojan-activity; sid:100001891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.127.214.47",nocase; classtype:trojan-activity; sid:100001892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.146.232.34",nocase; classtype:trojan-activity; sid:100001893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.165.173.49",nocase; classtype:trojan-activity; sid:100001894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.196.158.227",nocase; classtype:trojan-activity; sid:100001895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.222.157.166",nocase; classtype:trojan-activity; sid:100001896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.229.0.133",nocase; classtype:trojan-activity; sid:100001897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.63.73.234",nocase; classtype:trojan-activity; sid:100001898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.115.194",nocase; classtype:trojan-activity; sid:100001899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.227.186",nocase; classtype:trojan-activity; sid:100001900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.76.240.206",nocase; classtype:trojan-activity; sid:100001901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.115.31.30",nocase; classtype:trojan-activity; sid:100001902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.118.240.88",nocase; classtype:trojan-activity; sid:100001903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.167.10.180",nocase; classtype:trojan-activity; sid:100001904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.236.190.250",nocase; classtype:trojan-activity; sid:100001905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.25.5.105",nocase; classtype:trojan-activity; sid:100001906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.93.129.118",nocase; classtype:trojan-activity; sid:100001907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.127.148.69",nocase; classtype:trojan-activity; sid:100001908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.146.190.91",nocase; classtype:trojan-activity; sid:100001909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.204.63.239",nocase; classtype:trojan-activity; sid:100001910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.34.191.213",nocase; classtype:trojan-activity; sid:100001911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.40.234.166",nocase; classtype:trojan-activity; sid:100001912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.106.142",nocase; classtype:trojan-activity; sid:100001913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.2.122",nocase; classtype:trojan-activity; sid:100001914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.235.106",nocase; classtype:trojan-activity; sid:100001915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.47.133.58",nocase; classtype:trojan-activity; sid:100001916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.71.60.69",nocase; classtype:trojan-activity; sid:100001917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.85.106.211",nocase; classtype:trojan-activity; sid:100001918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.17.22.30",nocase; classtype:trojan-activity; sid:100001919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.180.98",nocase; classtype:trojan-activity; sid:100001920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.200.62",nocase; classtype:trojan-activity; sid:100001921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.202.249.109",nocase; classtype:trojan-activity; sid:100001922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.214.69.226",nocase; classtype:trojan-activity; sid:100001923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.229.230.118",nocase; classtype:trojan-activity; sid:100001924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.31.40.122",nocase; classtype:trojan-activity; sid:100001925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.112.123.203",nocase; classtype:trojan-activity; sid:100001926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.204.216.103",nocase; classtype:trojan-activity; sid:100001927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.31.139.77",nocase; classtype:trojan-activity; sid:100001928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.70.164.42",nocase; classtype:trojan-activity; sid:100001929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.101.1.159",nocase; classtype:trojan-activity; sid:100001930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.108.224.112",nocase; classtype:trojan-activity; sid:100001931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.195.115.176",nocase; classtype:trojan-activity; sid:100001932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.199.84.77",nocase; classtype:trojan-activity; sid:100001933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.64.139.223",nocase; classtype:trojan-activity; sid:100001934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.75.165.81",nocase; classtype:trojan-activity; sid:100001935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.127.141.52",nocase; classtype:trojan-activity; sid:100001936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.83.102.27",nocase; classtype:trojan-activity; sid:100001937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.99.213.61",nocase; classtype:trojan-activity; sid:100001938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.170.11.82",nocase; classtype:trojan-activity; sid:100001939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.178.22.145",nocase; classtype:trojan-activity; sid:100001940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.217.92.231",nocase; classtype:trojan-activity; sid:100001941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.250.199.133",nocase; classtype:trojan-activity; sid:100001942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.254.129.227",nocase; classtype:trojan-activity; sid:100001943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.84.134.33",nocase; classtype:trojan-activity; sid:100001944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.89.107.69",nocase; classtype:trojan-activity; sid:100001945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.95.12.137",nocase; classtype:trojan-activity; sid:100001946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.237.25.210",nocase; classtype:trojan-activity; sid:100001947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.50.153",nocase; classtype:trojan-activity; sid:100001948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.89.203.238",nocase; classtype:trojan-activity; sid:100001949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77st.net",nocase; classtype:trojan-activity; sid:100001950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.138.98.134",nocase; classtype:trojan-activity; sid:100001951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.145.224.45",nocase; classtype:trojan-activity; sid:100001952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.41.200",nocase; classtype:trojan-activity; sid:100001953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.106.235",nocase; classtype:trojan-activity; sid:100001954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.168.64",nocase; classtype:trojan-activity; sid:100001955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.188.141",nocase; classtype:trojan-activity; sid:100001956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.104.157",nocase; classtype:trojan-activity; sid:100001957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.176.163",nocase; classtype:trojan-activity; sid:100001958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.27.157",nocase; classtype:trojan-activity; sid:100001959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.23.172.81",nocase; classtype:trojan-activity; sid:100001960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.8.225.77",nocase; classtype:trojan-activity; sid:100001961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.11.195.121",nocase; classtype:trojan-activity; sid:100001962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.147.123.48",nocase; classtype:trojan-activity; sid:100001963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.175.42.244",nocase; classtype:trojan-activity; sid:100001964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.21.84.63",nocase; classtype:trojan-activity; sid:100001965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.7.170.58",nocase; classtype:trojan-activity; sid:100001966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.79.58.94",nocase; classtype:trojan-activity; sid:100001967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.8.70.162",nocase; classtype:trojan-activity; sid:100001968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.9.88.185",nocase; classtype:trojan-activity; sid:100001969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.107.89.207",nocase; classtype:trojan-activity; sid:100001970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.19.101.218",nocase; classtype:trojan-activity; sid:100001971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.211.181.77",nocase; classtype:trojan-activity; sid:100001972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.99.128.61",nocase; classtype:trojan-activity; sid:100001973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.136.146.213",nocase; classtype:trojan-activity; sid:100001974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.165.44.109",nocase; classtype:trojan-activity; sid:100001975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.191.40.58",nocase; classtype:trojan-activity; sid:100001976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.198.7.22",nocase; classtype:trojan-activity; sid:100001977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.141.184",nocase; classtype:trojan-activity; sid:100001978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.215.199.29",nocase; classtype:trojan-activity; sid:100001979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.187.113",nocase; classtype:trojan-activity; sid:100001980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.195.216",nocase; classtype:trojan-activity; sid:100001981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.229.230.103",nocase; classtype:trojan-activity; sid:100001982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.244.219.41",nocase; classtype:trojan-activity; sid:100001983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.246.225.203",nocase; classtype:trojan-activity; sid:100001984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.30.177.68",nocase; classtype:trojan-activity; sid:100001985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.92.36.96",nocase; classtype:trojan-activity; sid:100001986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.103.108.72",nocase; classtype:trojan-activity; sid:100001987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.135.196.130",nocase; classtype:trojan-activity; sid:100001988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.85.112",nocase; classtype:trojan-activity; sid:100001989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.207.61.194",nocase; classtype:trojan-activity; sid:100001990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.209.250.155",nocase; classtype:trojan-activity; sid:100001991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.211.156.38",nocase; classtype:trojan-activity; sid:100001992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.59.31.181",nocase; classtype:trojan-activity; sid:100001993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.110.252",nocase; classtype:trojan-activity; sid:100001994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.53.77",nocase; classtype:trojan-activity; sid:100001995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.138.72",nocase; classtype:trojan-activity; sid:100001996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.139.92",nocase; classtype:trojan-activity; sid:100001997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.154.214",nocase; classtype:trojan-activity; sid:100001998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.187.109",nocase; classtype:trojan-activity; sid:100001999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.100.54",nocase; classtype:trojan-activity; sid:100002000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.102.84",nocase; classtype:trojan-activity; sid:100002001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.106.65",nocase; classtype:trojan-activity; sid:100002002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.108.172",nocase; classtype:trojan-activity; sid:100002003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.131.158",nocase; classtype:trojan-activity; sid:100002004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.134.66",nocase; classtype:trojan-activity; sid:100002005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.19.42",nocase; classtype:trojan-activity; sid:100002006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.197.254",nocase; classtype:trojan-activity; sid:100002007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.215.149",nocase; classtype:trojan-activity; sid:100002008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.232.68",nocase; classtype:trojan-activity; sid:100002009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.234.195",nocase; classtype:trojan-activity; sid:100002010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.246.96",nocase; classtype:trojan-activity; sid:100002011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.28.57",nocase; classtype:trojan-activity; sid:100002012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.4.57",nocase; classtype:trojan-activity; sid:100002013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.55.84",nocase; classtype:trojan-activity; sid:100002014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.73.245",nocase; classtype:trojan-activity; sid:100002015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.98.51",nocase; classtype:trojan-activity; sid:100002016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.165.237.163",nocase; classtype:trojan-activity; sid:100002017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.147.99",nocase; classtype:trojan-activity; sid:100002018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.218.42",nocase; classtype:trojan-activity; sid:100002019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.242.253.154",nocase; classtype:trojan-activity; sid:100002020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.252.9.37",nocase; classtype:trojan-activity; sid:100002021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.210.219.213",nocase; classtype:trojan-activity; sid:100002022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.50.118",nocase; classtype:trojan-activity; sid:100002023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.95.204",nocase; classtype:trojan-activity; sid:100002024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.238.24.35",nocase; classtype:trojan-activity; sid:100002025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.247.83.74",nocase; classtype:trojan-activity; sid:100002026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.254.39.129",nocase; classtype:trojan-activity; sid:100002027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.33.111.227",nocase; classtype:trojan-activity; sid:100002028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.40.127.242",nocase; classtype:trojan-activity; sid:100002029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.42.20.217",nocase; classtype:trojan-activity; sid:100002030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com",nocase; classtype:trojan-activity; sid:100002031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.11.216",nocase; classtype:trojan-activity; sid:100002032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.123.251",nocase; classtype:trojan-activity; sid:100002033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.135.187",nocase; classtype:trojan-activity; sid:100002034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.180.33",nocase; classtype:trojan-activity; sid:100002035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.208.25",nocase; classtype:trojan-activity; sid:100002036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.224.141",nocase; classtype:trojan-activity; sid:100002037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.241.2",nocase; classtype:trojan-activity; sid:100002038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.214.149.236",nocase; classtype:trojan-activity; sid:100002039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.241.39.182",nocase; classtype:trojan-activity; sid:100002040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.250.147.134",nocase; classtype:trojan-activity; sid:100002041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.64.181.50",nocase; classtype:trojan-activity; sid:100002042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.74.215.180",nocase; classtype:trojan-activity; sid:100002043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.130.227",nocase; classtype:trojan-activity; sid:100002044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"86.35.43.220",nocase; classtype:trojan-activity; sid:100002045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"86.98.23.78",nocase; classtype:trojan-activity; sid:100002046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.117.11.46",nocase; classtype:trojan-activity; sid:100002047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.172.19.130",nocase; classtype:trojan-activity; sid:100002048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.251.71.78",nocase; classtype:trojan-activity; sid:100002049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87du.vip",nocase; classtype:trojan-activity; sid:100002050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.119.171.253",nocase; classtype:trojan-activity; sid:100002051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.129.208.43",nocase; classtype:trojan-activity; sid:100002052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.208.71",nocase; classtype:trojan-activity; sid:100002053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.219.179",nocase; classtype:trojan-activity; sid:100002054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.218.17.149",nocase; classtype:trojan-activity; sid:100002055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.225.222.128",nocase; classtype:trojan-activity; sid:100002056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.247.96.19",nocase; classtype:trojan-activity; sid:100002057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.51.139",nocase; classtype:trojan-activity; sid:100002058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.249.13.164",nocase; classtype:trojan-activity; sid:100002059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.249.244.180",nocase; classtype:trojan-activity; sid:100002060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.204.12",nocase; classtype:trojan-activity; sid:100002061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.226.26",nocase; classtype:trojan-activity; sid:100002062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.240.245",nocase; classtype:trojan-activity; sid:100002063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.254.90",nocase; classtype:trojan-activity; sid:100002064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.122.183.130",nocase; classtype:trojan-activity; sid:100002065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.136.197.170",nocase; classtype:trojan-activity; sid:100002066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.22.152.244",nocase; classtype:trojan-activity; sid:100002067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.237.84.19",nocase; classtype:trojan-activity; sid:100002068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.248.112.202",nocase; classtype:trojan-activity; sid:100002069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.29.213.33",nocase; classtype:trojan-activity; sid:100002070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.85.166",nocase; classtype:trojan-activity; sid:100002071; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.87.5",nocase; classtype:trojan-activity; sid:100002072; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8poieq.bn.files.1drv.com",nocase; classtype:trojan-activity; sid:100002073; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"90.152.144.139",nocase; classtype:trojan-activity; sid:100002074; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.132.197.39",nocase; classtype:trojan-activity; sid:100002075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.177.139.132",nocase; classtype:trojan-activity; sid:100002076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.187.103.32",nocase; classtype:trojan-activity; sid:100002077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.212.150.241",nocase; classtype:trojan-activity; sid:100002078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.217.104.185",nocase; classtype:trojan-activity; sid:100002079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.233.112.188",nocase; classtype:trojan-activity; sid:100002080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.234.60.94",nocase; classtype:trojan-activity; sid:100002081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.244.169.139",nocase; classtype:trojan-activity; sid:100002082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.92.16.244",nocase; classtype:trojan-activity; sid:100002083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.114.191.82",nocase; classtype:trojan-activity; sid:100002084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.241.78.114",nocase; classtype:trojan-activity; sid:100002085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.27.246.202",nocase; classtype:trojan-activity; sid:100002086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.54.237.237",nocase; classtype:trojan-activity; sid:100002087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.83.62.139",nocase; classtype:trojan-activity; sid:100002088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.85.18.138",nocase; classtype:trojan-activity; sid:100002089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.157.63.221",nocase; classtype:trojan-activity; sid:100002090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.159.169.190",nocase; classtype:trojan-activity; sid:100002091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.173.235.110",nocase; classtype:trojan-activity; sid:100002092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.21.224.154",nocase; classtype:trojan-activity; sid:100002093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.39.115.176",nocase; classtype:trojan-activity; sid:100002094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.39.79.41",nocase; classtype:trojan-activity; sid:100002095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.137.16",nocase; classtype:trojan-activity; sid:100002096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.182.249",nocase; classtype:trojan-activity; sid:100002097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.206.56",nocase; classtype:trojan-activity; sid:100002098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.57.43.233",nocase; classtype:trojan-activity; sid:100002099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.73.99.102",nocase; classtype:trojan-activity; sid:100002100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.136.69.199",nocase; classtype:trojan-activity; sid:100002101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.143.53.34",nocase; classtype:trojan-activity; sid:100002102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.17.170",nocase; classtype:trojan-activity; sid:100002103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.82.190",nocase; classtype:trojan-activity; sid:100002104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.200.16.22",nocase; classtype:trojan-activity; sid:100002105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.224.83.208",nocase; classtype:trojan-activity; sid:100002106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.53.120.109",nocase; classtype:trojan-activity; sid:100002107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.85.0.3",nocase; classtype:trojan-activity; sid:100002108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.132.129.250",nocase; classtype:trojan-activity; sid:100002109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.133.158.20",nocase; classtype:trojan-activity; sid:100002110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.158.19.130",nocase; classtype:trojan-activity; sid:100002111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.113.227",nocase; classtype:trojan-activity; sid:100002112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.201.34",nocase; classtype:trojan-activity; sid:100002113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.60.146.134",nocase; classtype:trojan-activity; sid:100002114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.66.196.63",nocase; classtype:trojan-activity; sid:100002115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.9.111.51",nocase; classtype:trojan-activity; sid:100002116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.9.120.40",nocase; classtype:trojan-activity; sid:100002117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.239.73.246",nocase; classtype:trojan-activity; sid:100002118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.47.147.169",nocase; classtype:trojan-activity; sid:100002119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.68.140.254",nocase; classtype:trojan-activity; sid:100002120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.96.199.75",nocase; classtype:trojan-activity; sid:100002121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.0.210.218",nocase; classtype:trojan-activity; sid:100002122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.113.239.207",nocase; classtype:trojan-activity; sid:100002123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.116.72.119",nocase; classtype:trojan-activity; sid:100002124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.128.147.115",nocase; classtype:trojan-activity; sid:100002125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.178.242.44",nocase; classtype:trojan-activity; sid:100002126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.30.24.54",nocase; classtype:trojan-activity; sid:100002127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.150.245.203",nocase; classtype:trojan-activity; sid:100002128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.33.195.164",nocase; classtype:trojan-activity; sid:100002129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"a.stro.lo.gy.t.em.r@zytrox.tk",nocase; classtype:trojan-activity; sid:100002130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aatreefelling.co.za",nocase; classtype:trojan-activity; sid:100002131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abcd.bg",nocase; classtype:trojan-activity; sid:100002132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abissnet.net",nocase; classtype:trojan-activity; sid:100002133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aboveandbelow.com.au",nocase; classtype:trojan-activity; sid:100002134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absoftechworld.com",nocase; classtype:trojan-activity; sid:100002135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abyssos.eu",nocase; classtype:trojan-activity; sid:100002136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"academyshademani.com",nocase; classtype:trojan-activity; sid:100002137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acbick.com",nocase; classtype:trojan-activity; sid:100002138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"accesslinksgroup.com",nocase; classtype:trojan-activity; sid:100002139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acellr.co.uk",nocase; classtype:trojan-activity; sid:100002140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acteon.com.ar",nocase; classtype:trojan-activity; sid:100002141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"addahealingmusic.com",nocase; classtype:trojan-activity; sid:100002142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.com",nocase; classtype:trojan-activity; sid:100002143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.memengers.com",nocase; classtype:trojan-activity; sid:100002144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.erapor.smk-alasror.net",nocase; classtype:trojan-activity; sid:100002145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.grandoceanvilla.com",nocase; classtype:trojan-activity; sid:100002146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admission.kmctartskuttippuram.org",nocase; classtype:trojan-activity; sid:100002147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adventureexplorer.in",nocase; classtype:trojan-activity; sid:100002148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aeropilates.cl",nocase; classtype:trojan-activity; sid:100002149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afnan-amc.com",nocase; classtype:trojan-activity; sid:100002150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afrimedspecialist.com",nocase; classtype:trojan-activity; sid:100002151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agemn.co.za",nocase; classtype:trojan-activity; sid:100002152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenciadigitalwdys.com",nocase; classtype:trojan-activity; sid:100002153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenda.gmelloinformatica.com.br",nocase; classtype:trojan-activity; sid:100002154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agentt.ac.ug",nocase; classtype:trojan-activity; sid:100002155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agile8studio.com",nocase; classtype:trojan-activity; sid:100002156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aiecons.com",nocase; classtype:trojan-activity; sid:100002157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aiqtest.com",nocase; classtype:trojan-activity; sid:100002158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajpharmaholding.com",nocase; classtype:trojan-activity; sid:100002159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"akdvidyalaya.com",nocase; classtype:trojan-activity; sid:100002160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"al-wahd.com",nocase; classtype:trojan-activity; sid:100002161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alasdemariposas.org",nocase; classtype:trojan-activity; sid:100002162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alberts.diamondrelationscrm.us",nocase; classtype:trojan-activity; sid:100002163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alemelektronik.com",nocase; classtype:trojan-activity; sid:100002164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alena1971.es",nocase; classtype:trojan-activity; sid:100002165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alexdubai.com.aldiabsteel.com",nocase; classtype:trojan-activity; sid:100002166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alka.institute",nocase; classtype:trojan-activity; sid:100002167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"allforcreative.com.au",nocase; classtype:trojan-activity; sid:100002168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alltheway.travel",nocase; classtype:trojan-activity; sid:100002169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alpaylar.com.tr",nocase; classtype:trojan-activity; sid:100002170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alumni.hildred.ibbott@46.249.33.79",nocase; classtype:trojan-activity; sid:100002171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"am-concepts.ca",nocase; classtype:trojan-activity; sid:100002172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarresdeamorymaestroshechiceros.com",nocase; classtype:trojan-activity; sid:100002173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarteargentina.com.ar",nocase; classtype:trojan-activity; sid:100002174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amos524.org",nocase; classtype:trojan-activity; sid:100002175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ams.alvinasschools.org.ng",nocase; classtype:trojan-activity; sid:100002176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anadelgbt.org",nocase; classtype:trojan-activity; sid:100002177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anantam.net.in",nocase; classtype:trojan-activity; sid:100002178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreelapeyre.com",nocase; classtype:trojan-activity; sid:100002179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andremaraisbeleggings.co.za",nocase; classtype:trojan-activity; sid:100002180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ac.ug",nocase; classtype:trojan-activity; sid:100002181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ug",nocase; classtype:trojan-activity; sid:100002182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreshconcejal.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelsdetour.com",nocase; classtype:trojan-activity; sid:100002184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anurontv.com",nocase; classtype:trojan-activity; sid:100002185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anysbergbiltong.co.za",nocase; classtype:trojan-activity; sid:100002186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apartamentoscitta.com",nocase; classtype:trojan-activity; sid:100002187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api-ms.cobainaja.id",nocase; classtype:trojan-activity; sid:100002188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.cstdevs.com",nocase; classtype:trojan-activity; sid:100002189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apoolcondo.com",nocase; classtype:trojan-activity; sid:100002190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.adsensearticle.com",nocase; classtype:trojan-activity; sid:100002191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.explicitsurveys.co.uk",nocase; classtype:trojan-activity; sid:100002192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.prerana.info",nocase; classtype:trojan-activity; sid:100002193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apps.saintsoporte.com",nocase; classtype:trojan-activity; sid:100002194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aps-scribe.com",nocase; classtype:trojan-activity; sid:100002195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aps-sv.com",nocase; classtype:trojan-activity; sid:100002196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"artedibujoyarquitectura.com",nocase; classtype:trojan-activity; sid:100002197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"arwenyapi.com",nocase; classtype:trojan-activity; sid:100002198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ask-regard.call-save.biz",nocase; classtype:trojan-activity; sid:100002199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atfile.com",nocase; classtype:trojan-activity; sid:100002200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"athenacapsg.com",nocase; classtype:trojan-activity; sid:100002201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atlasconcreteworks.com",nocase; classtype:trojan-activity; sid:100002202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"attach.66rpg.com",nocase; classtype:trojan-activity; sid:100002203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atteuqpotentialunlimited.com",nocase; classtype:trojan-activity; sid:100002204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"augustair.com",nocase; classtype:trojan-activity; sid:100002205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aulist.com",nocase; classtype:trojan-activity; sid:100002206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"australianpga.com.au",nocase; classtype:trojan-activity; sid:100002207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"automaticrefreshments.com",nocase; classtype:trojan-activity; sid:100002208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"avadhanagames.com",nocase; classtype:trojan-activity; sid:100002209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aventuramotorhome.com",nocase; classtype:trojan-activity; sid:100002210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"awumad01.top",nocase; classtype:trojan-activity; sid:100002211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"awuqze02.top",nocase; classtype:trojan-activity; sid:100002212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ayahuascasp.com.br",nocase; classtype:trojan-activity; sid:100002213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ayamallah.com",nocase; classtype:trojan-activity; sid:100002214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azmeasurement.com",nocase; classtype:trojan-activity; sid:100002215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azraktours.com",nocase; classtype:trojan-activity; sid:100002216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"b.r.uce.lee.b.es.t@zytrox.tk",nocase; classtype:trojan-activity; sid:100002217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"b2b.toptanakaryakit.com.tr",nocase; classtype:trojan-activity; sid:100002218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"backgrounds.pk",nocase; classtype:trojan-activity; sid:100002219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"badeggdesign.com",nocase; classtype:trojan-activity; sid:100002220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bakamla.go.id",nocase; classtype:trojan-activity; sid:100002221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"balealgodon.mx",nocase; classtype:trojan-activity; sid:100002222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bangkok-orchids.com",nocase; classtype:trojan-activity; sid:100002223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bangladeshunbound.com",nocase; classtype:trojan-activity; sid:100002224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bary.sz4h.com",nocase; classtype:trojan-activity; sid:100002225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bash.givemexyz.in",nocase; classtype:trojan-activity; sid:100002226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk",nocase; classtype:trojan-activity; sid:100002227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bavhome.com",nocase; classtype:trojan-activity; sid:100002228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bbia.co.uk",nocase; classtype:trojan-activity; sid:100002229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcmt.elin.co.za",nocase; classtype:trojan-activity; sid:100002230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcrg.co.za",nocase; classtype:trojan-activity; sid:100002231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bdnextrend.xyz",nocase; classtype:trojan-activity; sid:100002232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beanx88.xyz",nocase; classtype:trojan-activity; sid:100002233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bearcatpumps.com.cn",nocase; classtype:trojan-activity; sid:100002234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beautincollagen.rs",nocase; classtype:trojan-activity; sid:100002235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beautymomentsgt.de",nocase; classtype:trojan-activity; sid:100002236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bekape.co.id",nocase; classtype:trojan-activity; sid:100002237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beor360.com",nocase; classtype:trojan-activity; sid:100002238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bespokeweddings.ie",nocase; classtype:trojan-activity; sid:100002239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bestcarenepal.com",nocase; classtype:trojan-activity; sid:100002240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betone.co.kr",nocase; classtype:trojan-activity; sid:100002241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beveragesmiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bhavaniengineering.com",nocase; classtype:trojan-activity; sid:100002243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bigmikesupplies.co.za",nocase; classtype:trojan-activity; sid:100002244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilbosaquet.ug",nocase; classtype:trojan-activity; sid:100002245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilhen.co.za",nocase; classtype:trojan-activity; sid:100002246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"billing.rahitechnosoft.com",nocase; classtype:trojan-activity; sid:100002247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"binoy.stalphonsamissionva.org",nocase; classtype:trojan-activity; sid:100002248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"biometrico.gpotecnosystems.com",nocase; classtype:trojan-activity; sid:100002249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bioskey.com",nocase; classtype:trojan-activity; sid:100002250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birdi.elin.co.za",nocase; classtype:trojan-activity; sid:100002251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birminghamlink.org",nocase; classtype:trojan-activity; sid:100002252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bizztradingbot.nl",nocase; classtype:trojan-activity; sid:100002253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bl4n3.zadns.co.za",nocase; classtype:trojan-activity; sid:100002254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.callensaxen.com",nocase; classtype:trojan-activity; sid:100002255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.difusodesign.com",nocase; classtype:trojan-activity; sid:100002256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.oyinblogs.com",nocase; classtype:trojan-activity; sid:100002257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.takbelit.com",nocase; classtype:trojan-activity; sid:100002258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bmlifestyle.co.uk",nocase; classtype:trojan-activity; sid:100002259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"boatpecas.com.br",nocase; classtype:trojan-activity; sid:100002260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bodenstein.co.za",nocase; classtype:trojan-activity; sid:100002261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bodylanguage.santulan.co.in",nocase; classtype:trojan-activity; sid:100002262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"booksearch.com",nocase; classtype:trojan-activity; sid:100002263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bophelocare.co.za",nocase; classtype:trojan-activity; sid:100002264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bounces.mi-fs.com",nocase; classtype:trojan-activity; sid:100002265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"boutiqueofferte.com",nocase; classtype:trojan-activity; sid:100002266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bpo.correct.go.th",nocase; classtype:trojan-activity; sid:100002267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bradleyinstitute.co.za",nocase; classtype:trojan-activity; sid:100002268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brandtrust.com.pk",nocase; classtype:trojan-activity; sid:100002269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"braunfinancial.com.au",nocase; classtype:trojan-activity; sid:100002270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brendanquine.com",nocase; classtype:trojan-activity; sid:100002271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brideofmessiah.com",nocase; classtype:trojan-activity; sid:100002272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightaffiliatesales.org",nocase; classtype:trojan-activity; sid:100002273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightmega.com",nocase; classtype:trojan-activity; sid:100002274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightstarshop.com",nocase; classtype:trojan-activity; sid:100002275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"browardinsurancemiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bt2.elin.co.za",nocase; classtype:trojan-activity; sid:100002277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"btdapi.robotake.com",nocase; classtype:trojan-activity; sid:100002278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buigiaphat.com.vn",nocase; classtype:trojan-activity; sid:100002279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bullseyemedia.in",nocase; classtype:trojan-activity; sid:100002280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"busandvanrentalmalaysia.com",nocase; classtype:trojan-activity; sid:100002281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buscascolegios.diit.cl",nocase; classtype:trojan-activity; sid:100002282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"business.softberg.ro",nocase; classtype:trojan-activity; sid:100002283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"business2.softberg.ro",nocase; classtype:trojan-activity; sid:100002284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c.ompact.i.o.np.d.yu@zytrox.tk",nocase; classtype:trojan-activity; sid:100002285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c.oooooooooo.ga",nocase; classtype:trojan-activity; sid:100002286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c0140529.ferozo.com",nocase; classtype:trojan-activity; sid:100002287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"caballo.com.au",nocase; classtype:trojan-activity; sid:100002288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cacaoprojects.com",nocase; classtype:trojan-activity; sid:100002289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"calgaryautorepairservice.com",nocase; classtype:trojan-activity; sid:100002290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"callbury.in",nocase; classtype:trojan-activity; sid:100002291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"camminachetipassa.it",nocase; classtype:trojan-activity; sid:100002292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"canadianwork.cc",nocase; classtype:trojan-activity; sid:100002293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capitalgroup-kw.com",nocase; classtype:trojan-activity; sid:100002294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capoeiraventrelivre.com",nocase; classtype:trojan-activity; sid:100002295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cashyinvestment.org",nocase; classtype:trojan-activity; sid:100002296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"casiomaneflirt.cf",nocase; classtype:trojan-activity; sid:100002297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"catchpoolshetlands.co.uk",nocase; classtype:trojan-activity; sid:100002298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cazyacustomfurniture.com",nocase; classtype:trojan-activity; sid:100002299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cbn.hypervoizd.com",nocase; classtype:trojan-activity; sid:100002300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ccauthority.net",nocase; classtype:trojan-activity; sid:100002301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdaonline.com.ar",nocase; classtype:trojan-activity; sid:100002302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cec.asso.ac-amiens.fr",nocase; classtype:trojan-activity; sid:100002303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cellas.sk",nocase; classtype:trojan-activity; sid:100002304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cendekiabinaaksara.com",nocase; classtype:trojan-activity; sid:100002305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cfs5.tistory.com",nocase; classtype:trojan-activity; sid:100002306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ch.rmu.ac.th",nocase; classtype:trojan-activity; sid:100002307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"changematterscounselling.com",nocase; classtype:trojan-activity; sid:100002308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chardhamdodham.com",nocase; classtype:trojan-activity; sid:100002309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chezalice.co.za",nocase; classtype:trojan-activity; sid:100002310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"childselect.com",nocase; classtype:trojan-activity; sid:100002311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile.myvnc.com",nocase; classtype:trojan-activity; sid:100002312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile80.myvnc.com",nocase; classtype:trojan-activity; sid:100002313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cible-energy.com",nocase; classtype:trojan-activity; sid:100002314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cifeer.net",nocase; classtype:trojan-activity; sid:100002315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citiconstructioncorp.com",nocase; classtype:trojan-activity; sid:100002316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citihits.lk",nocase; classtype:trojan-activity; sid:100002317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citssolutions.co.za",nocase; classtype:trojan-activity; sid:100002318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cityglobalgospel.com",nocase; classtype:trojan-activity; sid:100002319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"civi.istmejia.com",nocase; classtype:trojan-activity; sid:100002320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cleanbydesignllc.com",nocase; classtype:trojan-activity; sid:100002321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloud.fc.co.mz",nocase; classtype:trojan-activity; sid:100002322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cnc.tacobelllover.tk",nocase; classtype:trojan-activity; sid:100002323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codsambal.com",nocase; classtype:trojan-activity; sid:100002324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colorpak.pl",nocase; classtype:trojan-activity; sid:100002325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"columbia.aula-web.net",nocase; classtype:trojan-activity; sid:100002326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"community.reimclub.com",nocase; classtype:trojan-activity; sid:100002327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"competancy.indigoconsult.net",nocase; classtype:trojan-activity; sid:100002328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"conceptimagine.ro",nocase; classtype:trojan-activity; sid:100002329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"config.cqhbkjzx.com",nocase; classtype:trojan-activity; sid:100002330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"connectcapital.com.br",nocase; classtype:trojan-activity; sid:100002331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"constructoralyon.com",nocase; classtype:trojan-activity; sid:100002332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"consulateins.solucioneslink.com",nocase; classtype:trojan-activity; sid:100002333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"contributeindustry.com",nocase; classtype:trojan-activity; sid:100002334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"copelandscapes.com",nocase; classtype:trojan-activity; sid:100002335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"corwin-tommie06f.ru.com",nocase; classtype:trojan-activity; sid:100002336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"coulsongraphics.com",nocase; classtype:trojan-activity; sid:100002337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"count.mail.163.com.impactmedfoundation.com",nocase; classtype:trojan-activity; sid:100002338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"covid19.cyberschool.or.id",nocase; classtype:trojan-activity; sid:100002339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"covid19vaccinations.hopto.org",nocase; classtype:trojan-activity; sid:100002340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cr-sq.com",nocase; classtype:trojan-activity; sid:100002341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"craftech.nxtnet.ga",nocase; classtype:trojan-activity; sid:100002342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crearechile.cl",nocase; classtype:trojan-activity; sid:100002343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"creationskateboards.com",nocase; classtype:trojan-activity; sid:100002344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crecerco.com",nocase; classtype:trojan-activity; sid:100002345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crittersbythebay.com",nocase; classtype:trojan-activity; sid:100002346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crm.notariavieitoyvelamazan.com",nocase; classtype:trojan-activity; sid:100002347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crmfarko.manivelasst.com",nocase; classtype:trojan-activity; sid:100002348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crmroche.manivelasst.com",nocase; classtype:trojan-activity; sid:100002349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crscorretordeimoveis.com.br",nocase; classtype:trojan-activity; sid:100002350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cse-engineer.com",nocase; classtype:trojan-activity; sid:100002351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"csnserver.com",nocase; classtype:trojan-activity; sid:100002352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cubescargoexpress.com",nocase; classtype:trojan-activity; sid:100002353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"curasoles.co.za",nocase; classtype:trojan-activity; sid:100002354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"currantmedia.com",nocase; classtype:trojan-activity; sid:100002355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cwa.mx",nocase; classtype:trojan-activity; sid:100002356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cyclomove.com",nocase; classtype:trojan-activity; sid:100002357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cynkon.kairoscs.net",nocase; classtype:trojan-activity; sid:100002358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"czsl.91756.cn",nocase; classtype:trojan-activity; sid:100002359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d.powerofwish.com",nocase; classtype:trojan-activity; sid:100002360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d9.99ddd.com",nocase; classtype:trojan-activity; sid:100002361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"da.alibuf.com",nocase; classtype:trojan-activity; sid:100002362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"danaevara.com",nocase; classtype:trojan-activity; sid:100002363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dartoonpictures.com",nocase; classtype:trojan-activity; sid:100002364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.cdevelop.org",nocase; classtype:trojan-activity; sid:100002365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.over-blog-kiwi.com",nocase; classtype:trojan-activity; sid:100002366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datapolish.com",nocase; classtype:trojan-activity; sid:100002367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dating.khokhas.co.za",nocase; classtype:trojan-activity; sid:100002368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datsom.vn",nocase; classtype:trojan-activity; sid:100002369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davethompson.me.uk",nocase; classtype:trojan-activity; sid:100002370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davidmcguinness.info",nocase; classtype:trojan-activity; sid:100002371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dayspringdaisies.com",nocase; classtype:trojan-activity; sid:100002372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dd.qiyuea.cn",nocase; classtype:trojan-activity; sid:100002373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"de.gsearch.com.de",nocase; classtype:trojan-activity; sid:100002374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"decifrar.com.br",nocase; classtype:trojan-activity; sid:100002375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deigratia2.elin.co.za",nocase; classtype:trojan-activity; sid:100002376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dekovizyon.com",nocase; classtype:trojan-activity; sid:100002377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo-cliente.mindcreative.com.br",nocase; classtype:trojan-activity; sid:100002378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo.glassforcars.com.au",nocase; classtype:trojan-activity; sid:100002379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo6.hiites.com",nocase; classtype:trojan-activity; sid:100002380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dent-estet.com",nocase; classtype:trojan-activity; sid:100002381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dental.xiaoxiao.media",nocase; classtype:trojan-activity; sid:100002382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dentalalliance.se",nocase; classtype:trojan-activity; sid:100002383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"desertlandtrd.com",nocase; classtype:trojan-activity; sid:100002384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"designerliving.co.za",nocase; classtype:trojan-activity; sid:100002385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"despertaresi.com.br",nocase; classtype:trojan-activity; sid:100002386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"destinymc.co.za",nocase; classtype:trojan-activity; sid:100002387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"detorre.es",nocase; classtype:trojan-activity; sid:100002388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.sebpo.net",nocase; classtype:trojan-activity; sid:100002389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.watch-store.eu",nocase; classtype:trojan-activity; sid:100002390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dezcom.com",nocase; classtype:trojan-activity; sid:100002391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfcf.91756.cn",nocase; classtype:trojan-activity; sid:100002392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"diamantenegro.mi-fs.com",nocase; classtype:trojan-activity; sid:100002393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dienmayminhhung.com",nocase; classtype:trojan-activity; sid:100002394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digilib.dianhusada.ac.id",nocase; classtype:trojan-activity; sid:100002395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digisails.org",nocase; classtype:trojan-activity; sid:100002396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"disinfection-cleaning.co.za",nocase; classtype:trojan-activity; sid:100002397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"djking.f3322.net",nocase; classtype:trojan-activity; sid:100002398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.1003b.56a.com",nocase; classtype:trojan-activity; sid:100002399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.198424.com",nocase; classtype:trojan-activity; sid:100002400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.installcdn-aws.com",nocase; classtype:trojan-activity; sid:100002401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.packetstormsecurity.net",nocase; classtype:trojan-activity; sid:100002402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.pandasecur.com",nocase; classtype:trojan-activity; sid:100002403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.rina-roleplay.com",nocase; classtype:trojan-activity; sid:100002404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dnn.alibuf.com",nocase; classtype:trojan-activity; sid:100002405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dns.alibuf.com",nocase; classtype:trojan-activity; sid:100002406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dockerupdate.anondns.net",nocase; classtype:trojan-activity; sid:100002407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docman.orientalservices.in",nocase; classtype:trojan-activity; sid:100002408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dodsonimaging.com",nocase; classtype:trojan-activity; sid:100002409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"doitunlimited.com",nocase; classtype:trojan-activity; sid:100002410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dokan.blueberrytec.com",nocase; classtype:trojan-activity; sid:100002411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom.daf.free.fr",nocase; classtype:trojan-activity; sid:100002412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"doncedyhall.com",nocase; classtype:trojan-activity; sid:100002413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donghobinhminh.com",nocase; classtype:trojan-activity; sid:100002414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dongphuctop.com",nocase; classtype:trojan-activity; sid:100002415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosman.pl",nocase; classtype:trojan-activity; sid:100002416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dovberger.com",nocase; classtype:trojan-activity; sid:100002417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.pcclear.com",nocase; classtype:trojan-activity; sid:100002418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.udashi.com",nocase; classtype:trojan-activity; sid:100002419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.webbora.com",nocase; classtype:trojan-activity; sid:100002420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down1.arpun.com",nocase; classtype:trojan-activity; sid:100002421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.caihong.com",nocase; classtype:trojan-activity; sid:100002422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.doumaibiji.cn",nocase; classtype:trojan-activity; sid:100002423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.exrnybuf.cn",nocase; classtype:trojan-activity; sid:100002424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.kaobeitu.com",nocase; classtype:trojan-activity; sid:100002425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.pdf00.cn",nocase; classtype:trojan-activity; sid:100002426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.rising.com.cn",nocase; classtype:trojan-activity; sid:100002427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.skycn.com",nocase; classtype:trojan-activity; sid:100002428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.zjsyawqj.cn",nocase; classtype:trojan-activity; sid:100002429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dragonsknot.com",nocase; classtype:trojan-activity; sid:100002430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drbaby.com.sa",nocase; classtype:trojan-activity; sid:100002431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dream.pics",nocase; classtype:trojan-activity; sid:100002432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drgroup.co.za",nocase; classtype:trojan-activity; sid:100002433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drools-moved.46999.n3.nabble.com",nocase; classtype:trojan-activity; sid:100002434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drsha.innovativesolutions.mobi",nocase; classtype:trojan-activity; sid:100002435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsenterprize.co.za",nocase; classtype:trojan-activity; sid:100002436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsspainting.com",nocase; classtype:trojan-activity; sid:100002437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"du-wizards.com",nocase; classtype:trojan-activity; sid:100002438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duque.guantanameratravel.com",nocase; classtype:trojan-activity; sid:100002439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dutapp.wisolve.co.za",nocase; classtype:trojan-activity; sid:100002440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duvalcharter.dekitout.com",nocase; classtype:trojan-activity; sid:100002441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dw2.co.id",nocase; classtype:trojan-activity; sid:100002442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dx.qqyewu.com",nocase; classtype:trojan-activity; sid:100002443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dzinestudio87.co.uk",nocase; classtype:trojan-activity; sid:100002444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-commerce.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100002445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e.sldov.ru",nocase; classtype:trojan-activity; sid:100002446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eandgdesign.com.ng",nocase; classtype:trojan-activity; sid:100002447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ebruyatkin.com",nocase; classtype:trojan-activity; sid:100002448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"edu.saicraftsman.com",nocase; classtype:trojan-activity; sid:100002449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"efficientegroup.com",nocase; classtype:trojan-activity; sid:100002450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"elbauldenora.com",nocase; classtype:trojan-activity; sid:100002451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"emaids.co.za",nocase; classtype:trojan-activity; sid:100002452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"emaz.pk",nocase; classtype:trojan-activity; sid:100002453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"en.baoend.com",nocase; classtype:trojan-activity; sid:100002454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enc-tech.com",nocase; classtype:trojan-activity; sid:100002455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"endurotanzania.co.tz",nocase; classtype:trojan-activity; sid:100002456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ennovate.elin.co.za",nocase; classtype:trojan-activity; sid:100002457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"equimination.ee",nocase; classtype:trojan-activity; sid:100002458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"erp.nanotechproautocare.com",nocase; classtype:trojan-activity; sid:100002459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"esaja09.top",nocase; classtype:trojan-activity; sid:100002460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"escola.probommar.org.br",nocase; classtype:trojan-activity; sid:100002461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eservices.immigration.gov.lk",nocase; classtype:trojan-activity; sid:100002462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"esnconsultants.com",nocase; classtype:trojan-activity; sid:100002463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"essentia.org.br",nocase; classtype:trojan-activity; sid:100002464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eubanks7.com",nocase; classtype:trojan-activity; sid:100002465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"europeanzonexxi.com",nocase; classtype:trojan-activity; sid:100002466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exilum.com",nocase; classtype:trojan-activity; sid:100002467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exitoalfaomega.co",nocase; classtype:trojan-activity; sid:100002468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"extrovertoffers.com",nocase; classtype:trojan-activity; sid:100002469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"f1sol.com",nocase; classtype:trojan-activity; sid:100002470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"familydentist.site",nocase; classtype:trojan-activity; sid:100002471; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"faveraprojects.com",nocase; classtype:trojan-activity; sid:100002472; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fc.co.mz",nocase; classtype:trojan-activity; sid:100002473; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"felicienne.nl",nocase; classtype:trojan-activity; sid:100002474; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.martellexpress.us",nocase; classtype:trojan-activity; sid:100002475; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files6.uludagbilisim.com",nocase; classtype:trojan-activity; sid:100002476; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"final.makkahkmcc.com",nocase; classtype:trojan-activity; sid:100002477; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fineartgallerym.com",nocase; classtype:trojan-activity; sid:100002478; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fisconline.bar",nocase; classtype:trojan-activity; sid:100002479; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fisconline.casa",nocase; classtype:trojan-activity; sid:100002480; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fix-america-now.org",nocase; classtype:trojan-activity; sid:100002481; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fkd.derpcity.ru",nocase; classtype:trojan-activity; sid:100002482; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flexypay.dsquaregroup.com",nocase; classtype:trojan-activity; sid:100002483; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flintspin.com",nocase; classtype:trojan-activity; sid:100002484; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flyingbuddhadesign.com",nocase; classtype:trojan-activity; sid:100002485; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fmjplastering.co.uk",nocase; classtype:trojan-activity; sid:100002486; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"follower.instantcashback.in",nocase; classtype:trojan-activity; sid:100002487; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foothills.com.br",nocase; classtype:trojan-activity; sid:100002488; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"footweardirect.elin.co.za",nocase; classtype:trojan-activity; sid:100002489; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"forum.mdb.nu",nocase; classtype:trojan-activity; sid:100002490; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fotoobjetivo.com",nocase; classtype:trojan-activity; sid:100002491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foundationrepairhoustontx.net",nocase; classtype:trojan-activity; sid:100002492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foxeps.com.br",nocase; classtype:trojan-activity; sid:100002493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freecnetdownload.com",nocase; classtype:trojan-activity; sid:100002494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freisites.com.br",nocase; classtype:trojan-activity; sid:100002495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ftp.n3twork30cm.ml",nocase; classtype:trojan-activity; sid:100002496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fullelectronica.com.ar",nocase; classtype:trojan-activity; sid:100002497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"funletters.net",nocase; classtype:trojan-activity; sid:100002498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fusionfiresolutions.com",nocase; classtype:trojan-activity; sid:100002499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"futbolpr.com",nocase; classtype:trojan-activity; sid:100002500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"futuregraphics.com.ar",nocase; classtype:trojan-activity; sid:100002501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"g.pinmonkey.xyz",nocase; classtype:trojan-activity; sid:100002502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gametwogame.com",nocase; classtype:trojan-activity; sid:100002503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garciadogshow.com",nocase; classtype:trojan-activity; sid:100002504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow.myvnc.com",nocase; classtype:trojan-activity; sid:100002505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow4.myvnc.com",nocase; classtype:trojan-activity; sid:100002506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gastoudergonny.nl",nocase; classtype:trojan-activity; sid:100002507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gbbulls.co.uk",nocase; classtype:trojan-activity; sid:100002508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gcpc.co.id.chronoscurtain.com",nocase; classtype:trojan-activity; sid:100002509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"generaldeviales.com",nocase; classtype:trojan-activity; sid:100002510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfmodd1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100002511; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfold1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100002512; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghettohub.co.za",nocase; classtype:trojan-activity; sid:100002513; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghislain.dartois.pagesperso-orange.fr",nocase; classtype:trojan-activity; sid:100002514; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giadungg7.com",nocase; classtype:trojan-activity; sid:100002515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giddos.ga",nocase; classtype:trojan-activity; sid:100002516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giteletropical.com",nocase; classtype:trojan-activity; sid:100002517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"glowinmedia.co.ke",nocase; classtype:trojan-activity; sid:100002518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmtransformationacademy.com",nocase; classtype:trojan-activity; sid:100002519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmvadmission.org",nocase; classtype:trojan-activity; sid:100002520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnimelf.net",nocase; classtype:trojan-activity; sid:100002521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnscrew.ro",nocase; classtype:trojan-activity; sid:100002522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gold.investforex.id",nocase; classtype:trojan-activity; sid:100002523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcake.co.id",nocase; classtype:trojan-activity; sid:100002524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com",nocase; classtype:trojan-activity; sid:100002525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com.au",nocase; classtype:trojan-activity; sid:100002526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"golden-memories-funerals.yourpageserver.com",nocase; classtype:trojan-activity; sid:100002527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldenasiacapital.com",nocase; classtype:trojan-activity; sid:100002528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldmen.in",nocase; classtype:trojan-activity; sid:100002529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gpotecnosystems.com",nocase; classtype:trojan-activity; sid:100002530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gracejukes.com",nocase; classtype:trojan-activity; sid:100002531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"grupoinmare.com",nocase; classtype:trojan-activity; sid:100002532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gruposelt.000webhostapp.com",nocase; classtype:trojan-activity; sid:100002533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gs.monerorx.com",nocase; classtype:trojan-activity; sid:100002534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"guide-to-cell-phones.com",nocase; classtype:trojan-activity; sid:100002535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gulfac-house.com",nocase; classtype:trojan-activity; sid:100002536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gvpcdpgc.edu.in",nocase; classtype:trojan-activity; sid:100002537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"h.epelcdn.com",nocase; classtype:trojan-activity; sid:100002538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"habbotips.free.fr",nocase; classtype:trojan-activity; sid:100002539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hagebakken.no",nocase; classtype:trojan-activity; sid:100002540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hamptonpartyoffive.com",nocase; classtype:trojan-activity; sid:100002541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hashmati.com",nocase; classtype:trojan-activity; sid:100002542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hassanproduct.com",nocase; classtype:trojan-activity; sid:100002543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hchfug.org",nocase; classtype:trojan-activity; sid:100002544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hd11315.com",nocase; classtype:trojan-activity; sid:100002545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hdkamera2003.hu",nocase; classtype:trojan-activity; sid:100002546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hds.sz4h.com",nocase; classtype:trojan-activity; sid:100002547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hellogorgeous.com.au",nocase; classtype:trojan-activity; sid:100002548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"help.hizuko.com",nocase; classtype:trojan-activity; sid:100002549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"helpdeskserver.epelcdn.com",nocase; classtype:trojan-activity; sid:100002550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"herchinfitout.com.sg",nocase; classtype:trojan-activity; sid:100002551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hhaward.org",nocase; classtype:trojan-activity; sid:100002552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandroadcoc.com",nocase; classtype:trojan-activity; sid:100002553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandslasvegas.atakdev.com",nocase; classtype:trojan-activity; sid:100002554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hindi.factsriver.com",nocase; classtype:trojan-activity; sid:100002555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hiptool.net",nocase; classtype:trojan-activity; sid:100002556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitpe.com",nocase; classtype:trojan-activity; sid:100002557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitstation.nl",nocase; classtype:trojan-activity; sid:100002558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hmpmall.co.kr",nocase; classtype:trojan-activity; sid:100002559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoagietesting10.com",nocase; classtype:trojan-activity; sid:100002560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoayeuthuong-my.sharepoint.com",nocase; classtype:trojan-activity; sid:100002561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"homefindersolutions.com",nocase; classtype:trojan-activity; sid:100002562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hometownchick.com",nocase; classtype:trojan-activity; sid:100002563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hookedupboatclub.com",nocase; classtype:trojan-activity; sid:100002564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostingparacolombia.com",nocase; classtype:trojan-activity; sid:100002565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostzaa.com",nocase; classtype:trojan-activity; sid:100002566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hr2019.vrcom7.com",nocase; classtype:trojan-activity; sid:100002567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hseda.com",nocase; classtype:trojan-activity; sid:100002568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"htownbars.com",nocase; classtype:trojan-activity; sid:100002569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hubtech.co.za",nocase; classtype:trojan-activity; sid:100002570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"huellacero.cl",nocase; classtype:trojan-activity; sid:100002571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hunchomusichub.com",nocase; classtype:trojan-activity; sid:100002572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hunggiang.vn",nocase; classtype:trojan-activity; sid:100002573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"husamiyahschool.com",nocase; classtype:trojan-activity; sid:100002574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"i.n.t.e.rloca.l.qs.j.y@jfas.top",nocase; classtype:trojan-activity; sid:100002575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iabmixx2020.rayadigital.online",nocase; classtype:trojan-activity; sid:100002576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iam313.com",nocase; classtype:trojan-activity; sid:100002577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"icon.shatangmu.cn",nocase; classtype:trojan-activity; sid:100002578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idea-secure-login.com",nocase; classtype:trojan-activity; sid:100002579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idilsoft.com",nocase; classtype:trojan-activity; sid:100002580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idj.no",nocase; classtype:trojan-activity; sid:100002581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idvindia.com",nocase; classtype:trojan-activity; sid:100002582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ieclb.com.br",nocase; classtype:trojan-activity; sid:100002583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ikexpert.com",nocase; classtype:trojan-activity; sid:100002584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ilrafrica.com",nocase; classtype:trojan-activity; sid:100002585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"images.jermiau.com",nocase; classtype:trojan-activity; sid:100002586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"imbueautoworx.co.za",nocase; classtype:trojan-activity; sid:100002587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"in-tune2016.com",nocase; classtype:trojan-activity; sid:100002588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incrediblepixels.com",nocase; classtype:trojan-activity; sid:100002589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incredicole.com",nocase; classtype:trojan-activity; sid:100002590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indrasbikaner.com",nocase; classtype:trojan-activity; sid:100002591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infair.vn",nocase; classtype:trojan-activity; sid:100002592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infovator.com",nocase; classtype:trojan-activity; sid:100002593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"initialnetworks.com",nocase; classtype:trojan-activity; sid:100002594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inodesthetotaldesigners.com",nocase; classtype:trojan-activity; sid:100002595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inrajahmundry.co.in",nocase; classtype:trojan-activity; sid:100002596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"instantindialoan.com",nocase; classtype:trojan-activity; sid:100002597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intersel-idf.org",nocase; classtype:trojan-activity; sid:100002598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intuitiveideas.com.my",nocase; classtype:trojan-activity; sid:100002599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inversiones.arrayanfinanciero.cl",nocase; classtype:trojan-activity; sid:100002600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"invest.xpcorporative.com.br",nocase; classtype:trojan-activity; sid:100002601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ipmes.ma",nocase; classtype:trojan-activity; sid:100002602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iremart.es",nocase; classtype:trojan-activity; sid:100002603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iris101.co.uk",nocase; classtype:trojan-activity; sid:100002604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isaac.mikhailmotoringschool.com",nocase; classtype:trojan-activity; sid:100002605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iscamenabe.com",nocase; classtype:trojan-activity; sid:100002606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isiphephelocon.co.za",nocase; classtype:trojan-activity; sid:100002607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ismf.com.ng",nocase; classtype:trojan-activity; sid:100002608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iso-dubai.net",nocase; classtype:trojan-activity; sid:100002609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"israrulhaq.me",nocase; classtype:trojan-activity; sid:100002610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isrorg.com",nocase; classtype:trojan-activity; sid:100002611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isso.ps",nocase; classtype:trojan-activity; sid:100002612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"it123.ru",nocase; classtype:trojan-activity; sid:100002613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"italiandirezione.casa",nocase; classtype:trojan-activity; sid:100002614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itc-demo.softgig.co.ke",nocase; classtype:trojan-activity; sid:100002615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itsrlytry.000webhostapp.com",nocase; classtype:trojan-activity; sid:100002616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jaishomo.info",nocase; classtype:trojan-activity; sid:100002617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamiekaylive.com",nocase; classtype:trojan-activity; sid:100002618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamshed.pk",nocase; classtype:trojan-activity; sid:100002619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jansen-heesch.nl",nocase; classtype:trojan-activity; sid:100002620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jathra.co.uk",nocase; classtype:trojan-activity; sid:100002621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jay.diamondrelationscrm.us",nocase; classtype:trojan-activity; sid:100002622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jebs.net.au",nocase; classtype:trojan-activity; sid:100002623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jeffdahlke.com",nocase; classtype:trojan-activity; sid:100002624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jfas.top",nocase; classtype:trojan-activity; sid:100002625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jhayesconsulting.com",nocase; classtype:trojan-activity; sid:100002626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jiaoyuzixun.cn",nocase; classtype:trojan-activity; sid:100002627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jing-da.com.tw",nocase; classtype:trojan-activity; sid:100002628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jmtc.91756.cn",nocase; classtype:trojan-activity; sid:100002629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jnanbharati.com",nocase; classtype:trojan-activity; sid:100002630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jobs.thebeessolution.com",nocase; classtype:trojan-activity; sid:100002631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"joelbonissilver.com",nocase; classtype:trojan-activity; sid:100002632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"join.cl8movement.co.za",nocase; classtype:trojan-activity; sid:100002633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"josegene.com",nocase; classtype:trojan-activity; sid:100002634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jpwoodfordco.com",nocase; classtype:trojan-activity; sid:100002635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jumpmanualjacobhiller.com",nocase; classtype:trojan-activity; sid:100002636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jupiter.toxsl.in",nocase; classtype:trojan-activity; sid:100002637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"justinscott.com.au",nocase; classtype:trojan-activity; sid:100002638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kadigital.co.uk",nocase; classtype:trojan-activity; sid:100002639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalawatihomes.com",nocase; classtype:trojan-activity; sid:100002640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalogirosfinance.com",nocase; classtype:trojan-activity; sid:100002641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kaptaanchapal.com",nocase; classtype:trojan-activity; sid:100002642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karer.by",nocase; classtype:trojan-activity; sid:100002643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"katanvetov.co.il",nocase; classtype:trojan-activity; sid:100002644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"katelynn9506a.ru.com",nocase; classtype:trojan-activity; sid:100002645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kensingtondriving.com",nocase; classtype:trojan-activity; sid:100002646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ketofitnessexpert.com",nocase; classtype:trojan-activity; sid:100002647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kevinjewelry.com.co",nocase; classtype:trojan-activity; sid:100002648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"keywatch.yourpageserver.com",nocase; classtype:trojan-activity; sid:100002649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kingssa.co.za",nocase; classtype:trojan-activity; sid:100002650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kjcpromo.com",nocase; classtype:trojan-activity; sid:100002651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kleinendeli.co.za",nocase; classtype:trojan-activity; sid:100002652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"korrectconceptservices.com",nocase; classtype:trojan-activity; sid:100002653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"krisbadminton.com",nocase; classtype:trojan-activity; sid:100002654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ktb.sch.id",nocase; classtype:trojan-activity; sid:100002655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kubatoglubaklava.com.tr",nocase; classtype:trojan-activity; sid:100002656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kumaralok.in",nocase; classtype:trojan-activity; sid:100002657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kwanfromhongkong.com",nocase; classtype:trojan-activity; sid:100002658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kz.sldov.ru",nocase; classtype:trojan-activity; sid:100002659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"l.oc.atevur.c@zytrox.tk",nocase; classtype:trojan-activity; sid:100002660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lacasadelosalebrijes.com",nocase; classtype:trojan-activity; sid:100002661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lameguard.ru",nocase; classtype:trojan-activity; sid:100002662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laodongnhat.vn",nocase; classtype:trojan-activity; sid:100002663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laravel.pointersoftwares.com.br",nocase; classtype:trojan-activity; sid:100002664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lasermobilesounds.co.uk",nocase; classtype:trojan-activity; sid:100002665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lauratomismith.com",nocase; classtype:trojan-activity; sid:100002666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lautarosanmiguel.com",nocase; classtype:trojan-activity; sid:100002667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lawforall.edu.lk",nocase; classtype:trojan-activity; sid:100002668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lawschoolideas.xyz",nocase; classtype:trojan-activity; sid:100002669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lceventos.net",nocase; classtype:trojan-activity; sid:100002670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ld.mediaget.com",nocase; classtype:trojan-activity; sid:100002671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ldgcorp.com",nocase; classtype:trojan-activity; sid:100002672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"learning.real-academy.net",nocase; classtype:trojan-activity; sid:100002673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leasiacherise.com",nocase; classtype:trojan-activity; sid:100002674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leczkregoslup.acelero.pl",nocase; classtype:trojan-activity; sid:100002675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"legend.nu",nocase; classtype:trojan-activity; sid:100002676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leluibuffet.com.br",nocase; classtype:trojan-activity; sid:100002677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lestesteux.ca",nocase; classtype:trojan-activity; sid:100002678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.arihantmbainstitute.ac.in",nocase; classtype:trojan-activity; sid:100002679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.uib.ac.id",nocase; classtype:trojan-activity; sid:100002680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lidoraggiodisole.it",nocase; classtype:trojan-activity; sid:100002681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lifebeam.elin.co.za",nocase; classtype:trojan-activity; sid:100002682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lindnerelektroanlagen.de",nocase; classtype:trojan-activity; sid:100002683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linkintec.cn",nocase; classtype:trojan-activity; sid:100002684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"liquidaz.casa",nocase; classtype:trojan-activity; sid:100002685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"livetrack.in",nocase; classtype:trojan-activity; sid:100002686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lloydsindian.co.uk",nocase; classtype:trojan-activity; sid:100002687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lm.stagingarea.co.za",nocase; classtype:trojan-activity; sid:100002688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lmaancha.co.il",nocase; classtype:trojan-activity; sid:100002689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.cstdevs.com",nocase; classtype:trojan-activity; sid:100002690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.login2.in",nocase; classtype:trojan-activity; sid:100002691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"location-voitures.ma",nocase; classtype:trojan-activity; sid:100002692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"login.trezor.com.stockfootagesindia.com",nocase; classtype:trojan-activity; sid:100002693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"logotypfabriken.se",nocase; classtype:trojan-activity; sid:100002694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotix.de",nocase; classtype:trojan-activity; sid:100002695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotusanddragonfly.com",nocase; classtype:trojan-activity; sid:100002696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.definerisco.com",nocase; classtype:trojan-activity; sid:100002697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.difusodesign.com",nocase; classtype:trojan-activity; sid:100002698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ltc.typoten.com",nocase; classtype:trojan-activity; sid:100002699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luckybrownie.com",nocase; classtype:trojan-activity; sid:100002700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luminouspneuma.com",nocase; classtype:trojan-activity; sid:100002701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luxomodels.com",nocase; classtype:trojan-activity; sid:100002702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m-technics.kz",nocase; classtype:trojan-activity; sid:100002703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m.estudiomoros.com.ar",nocase; classtype:trojan-activity; sid:100002704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"madicon.co.za",nocase; classtype:trojan-activity; sid:100002705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"magianegramagiablancayamarres.com",nocase; classtype:trojan-activity; sid:100002706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.bs-eiendomme.co.za",nocase; classtype:trojan-activity; sid:100002707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.golimoapp.com",nocase; classtype:trojan-activity; sid:100002708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.jeffsono.org",nocase; classtype:trojan-activity; sid:100002709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maksi.feb.unib.ac.id",nocase; classtype:trojan-activity; sid:100002710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malaya.tv",nocase; classtype:trojan-activity; sid:100002711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malwarecoding.github.io",nocase; classtype:trojan-activity; sid:100002712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managemysalon.in",nocase; classtype:trojan-activity; sid:100002713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manantialesdelnorte.uy",nocase; classtype:trojan-activity; sid:100002714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manhtien.net",nocase; classtype:trojan-activity; sid:100002715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marcapinyo.ru",nocase; classtype:trojan-activity; sid:100002716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mario-sunjic.com",nocase; classtype:trojan-activity; sid:100002717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariobrown.net",nocase; classtype:trojan-activity; sid:100002718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariotessarollo.com",nocase; classtype:trojan-activity; sid:100002719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketinfosales.com",nocase; classtype:trojan-activity; sid:100002720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketing.enexusgroup.com.au",nocase; classtype:trojan-activity; sid:100002721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marksidfgs.ug",nocase; classtype:trojan-activity; sid:100002722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"masjidhabeebiyarazviya.mysunni.com",nocase; classtype:trojan-activity; sid:100002723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mastersofclientretention.com.au",nocase; classtype:trojan-activity; sid:100002724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"materialescantu.com",nocase; classtype:trojan-activity; sid:100002725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"matruchhaya.co.in",nocase; classtype:trojan-activity; sid:100002726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxtox.com.pk",nocase; classtype:trojan-activity; sid:100002727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbgrm.com",nocase; classtype:trojan-activity; sid:100002728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbjtimes.com",nocase; classtype:trojan-activity; sid:100002729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbsolutions.ge",nocase; classtype:trojan-activity; sid:100002730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mdasa.elin.co.za",nocase; classtype:trojan-activity; sid:100002731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medevlb.org",nocase; classtype:trojan-activity; sid:100002732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"media-server.skyinternet.com.pk",nocase; classtype:trojan-activity; sid:100002733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medianews.ge",nocase; classtype:trojan-activity; sid:100002734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mediawaysnews.com",nocase; classtype:trojan-activity; sid:100002735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medistaffconsulting.com",nocase; classtype:trojan-activity; sid:100002736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meeweb.com",nocase; classtype:trojan-activity; sid:100002737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"megagynreformas.com.br",nocase; classtype:trojan-activity; sid:100002738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"megamart.afnan-amc.com",nocase; classtype:trojan-activity; sid:100002739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mehainteriors.com",nocase; classtype:trojan-activity; sid:100002740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"merkathink.com",nocase; classtype:trojan-activity; sid:100002741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mertlog.com",nocase; classtype:trojan-activity; sid:100002742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"metalin-cr.com",nocase; classtype:trojan-activity; sid:100002743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mettaanand.org",nocase; classtype:trojan-activity; sid:100002744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meuoculosnanet.com.br",nocase; classtype:trojan-activity; sid:100002745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mfevr.com",nocase; classtype:trojan-activity; sid:100002746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot.myvnc.com",nocase; classtype:trojan-activity; sid:100002747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot80.myvnc.com",nocase; classtype:trojan-activity; sid:100002748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"micalle.com.au",nocase; classtype:trojan-activity; sid:100002749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michaelphilip.com",nocase; classtype:trojan-activity; sid:100002750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michimal2.000webhostapp.com",nocase; classtype:trojan-activity; sid:100002751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microblading.mirliandias.com.br",nocase; classtype:trojan-activity; sid:100002752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microcomm-group.com",nocase; classtype:trojan-activity; sid:100002753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mikhailmotoringschool.com",nocase; classtype:trojan-activity; sid:100002754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mills-skyla30ec.com",nocase; classtype:trojan-activity; sid:100002755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mingguanwms.com",nocase; classtype:trojan-activity; sid:100002756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minuevavida.org",nocase; classtype:trojan-activity; sid:100002757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mirror.mypage.sk",nocase; classtype:trojan-activity; sid:100002758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mis.nbcc.ac.th",nocase; classtype:trojan-activity; sid:100002759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"misterson.com",nocase; classtype:trojan-activity; sid:100002760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mkontakt.az",nocase; classtype:trojan-activity; sid:100002761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mktf.mx",nocase; classtype:trojan-activity; sid:100002762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mmdx.com",nocase; classtype:trojan-activity; sid:100002763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mmogollon.com.mx",nocase; classtype:trojan-activity; sid:100002764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mncarteam.com",nocase; classtype:trojan-activity; sid:100002765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modelhouseturkey.com",nocase; classtype:trojan-activity; sid:100002766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modernmanna.org",nocase; classtype:trojan-activity; sid:100002767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"monetization.business",nocase; classtype:trojan-activity; sid:100002768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moninediy.com",nocase; classtype:trojan-activity; sid:100002769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moreirawag.ac.ug",nocase; classtype:trojan-activity; sid:100002770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"motorcomunicacion.com",nocase; classtype:trojan-activity; sid:100002771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moumitas.com",nocase; classtype:trojan-activity; sid:100002772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"msacontabil.com.br",nocase; classtype:trojan-activity; sid:100002773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mumgee.co.za",nocase; classtype:trojan-activity; sid:100002774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"muzimbiti.xigubo.co.mz",nocase; classtype:trojan-activity; sid:100002775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mvb.kz",nocase; classtype:trojan-activity; sid:100002776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mxpiqw.am.files.1drv.com",nocase; classtype:trojan-activity; sid:100002777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mydatebook.in",nocase; classtype:trojan-activity; sid:100002778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mymlql.com",nocase; classtype:trojan-activity; sid:100002779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myritz.vettickal.com",nocase; classtype:trojan-activity; sid:100002780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mysalons.in",nocase; classtype:trojan-activity; sid:100002781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myscape.in",nocase; classtype:trojan-activity; sid:100002782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mysura.it",nocase; classtype:trojan-activity; sid:100002783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"naeemacademy.com",nocase; classtype:trojan-activity; sid:100002784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"namnyak.co.ke",nocase; classtype:trojan-activity; sid:100002785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nap.mgsservers.com",nocase; classtype:trojan-activity; sid:100002786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"navayurveda.in",nocase; classtype:trojan-activity; sid:100002787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nec-i.com",nocase; classtype:trojan-activity; sid:100002788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nelitrianggraeni.000webhostapp.com",nocase; classtype:trojan-activity; sid:100002789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nerve.untergrund.net",nocase; classtype:trojan-activity; sid:100002790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nettube.com.br",nocase; classtype:trojan-activity; sid:100002791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"networkwheels.co.za",nocase; classtype:trojan-activity; sid:100002792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newfuture.fr",nocase; classtype:trojan-activity; sid:100002793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newinfinitysynergy.com",nocase; classtype:trojan-activity; sid:100002794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newtreedesign.co.uk",nocase; classtype:trojan-activity; sid:100002795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newvisionopticallab.com",nocase; classtype:trojan-activity; sid:100002796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newxing.com",nocase; classtype:trojan-activity; sid:100002797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nextdigitalday.ru",nocase; classtype:trojan-activity; sid:100002798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ngdaycare.co.za",nocase; classtype:trojan-activity; sid:100002799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nguyenkekhuyen.com",nocase; classtype:trojan-activity; sid:100002800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhorangtreem.com",nocase; classtype:trojan-activity; sid:100002801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nicolas.ug",nocase; classtype:trojan-activity; sid:100002802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nidhi.iexist.in",nocase; classtype:trojan-activity; sid:100002803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nikanpolimer.ir",nocase; classtype:trojan-activity; sid:100002804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilehouse.co.ug",nocase; classtype:trojan-activity; sid:100002805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilinkeji.com",nocase; classtype:trojan-activity; sid:100002806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nimboohomes.com",nocase; classtype:trojan-activity; sid:100002807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"njtiledesigncenter.com",nocase; classtype:trojan-activity; sid:100002808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nobius.org",nocase; classtype:trojan-activity; sid:100002809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nocalnoodle.elin.co.za",nocase; classtype:trojan-activity; sid:100002810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nomadicbees.com",nocase; classtype:trojan-activity; sid:100002811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"northnodegroup.com.au",nocase; classtype:trojan-activity; sid:100002812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"notamuzikaletleri.com",nocase; classtype:trojan-activity; sid:100002813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ns1.the-widyantos.com",nocase; classtype:trojan-activity; sid:100002814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nsb.org.uk",nocase; classtype:trojan-activity; sid:100002815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nurmarkaz.org",nocase; classtype:trojan-activity; sid:100002816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nxtnet.ga",nocase; classtype:trojan-activity; sid:100002817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nyasabigbullets.com",nocase; classtype:trojan-activity; sid:100002818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nyeh2o.com.au",nocase; classtype:trojan-activity; sid:100002819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"obseques-conseils.com",nocase; classtype:trojan-activity; sid:100002820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oecteam.com",nocase; classtype:trojan-activity; sid:100002821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohe.ie",nocase; classtype:trojan-activity; sid:100002822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohsewgorgeous.co.uk",nocase; classtype:trojan-activity; sid:100002823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oleholeh.memangbeda.website",nocase; classtype:trojan-activity; sid:100002824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaia.org",nocase; classtype:trojan-activity; sid:100002825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaromatic.com",nocase; classtype:trojan-activity; sid:100002826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omega.az",nocase; classtype:trojan-activity; sid:100002827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oms.pappai.com",nocase; classtype:trojan-activity; sid:100002828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omscoc.pappai.com",nocase; classtype:trojan-activity; sid:100002829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedigitalcard.granvizionnecorp.com",nocase; classtype:trojan-activity; sid:100002830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.listifyapp.co",nocase; classtype:trojan-activity; sid:100002831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"online.creedglobal.in",nocase; classtype:trojan-activity; sid:100002832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"open.warehousesaas.co.uk",nocase; classtype:trojan-activity; sid:100002833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opolis.io",nocase; classtype:trojan-activity; sid:100002834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"optimus.com.sg",nocase; classtype:trojan-activity; sid:100002835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"order.bizpeed.com",nocase; classtype:trojan-activity; sid:100002836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orientgatewayltd.com",nocase; classtype:trojan-activity; sid:100002837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orion445.com",nocase; classtype:trojan-activity; sid:100002838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orlina.be",nocase; classtype:trojan-activity; sid:100002839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oserve.pk",nocase; classtype:trojan-activity; sid:100002840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ot.weenets.com",nocase; classtype:trojan-activity; sid:100002841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ozemag.com",nocase; classtype:trojan-activity; sid:100002842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p1.lingpao8.com",nocase; classtype:trojan-activity; sid:100002843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p3.zbjimg.com",nocase; classtype:trojan-activity; sid:100002844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p6.zbjimg.com",nocase; classtype:trojan-activity; sid:100002845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pablobrothel.com.ar",nocase; classtype:trojan-activity; sid:100002846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacificgroup.ws",nocase; classtype:trojan-activity; sid:100002847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacwebdesigns.com",nocase; classtype:trojan-activity; sid:100002848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pagos.krayem.com.mx",nocase; classtype:trojan-activity; sid:100002849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"palochusvet.szm.com",nocase; classtype:trojan-activity; sid:100002850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"panslimiterd.com",nocase; classtype:trojan-activity; sid:100002851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parallel.rockvideos.at",nocase; classtype:trojan-activity; sid:100002852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parejasfelices.mi-fs.com",nocase; classtype:trojan-activity; sid:100002853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parkhussion.com",nocase; classtype:trojan-activity; sid:100002854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastorpaulocosta.com",nocase; classtype:trojan-activity; sid:100002855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.51lg.com",nocase; classtype:trojan-activity; sid:100002856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.99ddd.com",nocase; classtype:trojan-activity; sid:100002857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch3.99ddd.com",nocase; classtype:trojan-activity; sid:100002858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paths.elin.co.za",nocase; classtype:trojan-activity; sid:100002859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patriotsupremehemp.com",nocase; classtype:trojan-activity; sid:100002860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paulmercier.biz",nocase; classtype:trojan-activity; sid:100002861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payerrealty.com",nocase; classtype:trojan-activity; sid:100002862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payments.atifsiddiqui.me",nocase; classtype:trojan-activity; sid:100002863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pcsoori.com",nocase; classtype:trojan-activity; sid:100002864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pd.oceaniarp.net",nocase; classtype:trojan-activity; sid:100002865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pemdodo.com",nocase; classtype:trojan-activity; sid:100002866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perfumeriamontes.es",nocase; classtype:trojan-activity; sid:100002867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"periodiche.bar",nocase; classtype:trojan-activity; sid:100002868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpus.onlineman7-jombang.sch.id",nocase; classtype:trojan-activity; sid:100002869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpustekim.untirta.ac.id",nocase; classtype:trojan-activity; sid:100002870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pestoclean.co.uk",nocase; classtype:trojan-activity; sid:100002871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"petercollie.com",nocase; classtype:trojan-activity; sid:100002872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ph4s.ru",nocase; classtype:trojan-activity; sid:100002873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phasdesign.com",nocase; classtype:trojan-activity; sid:100002874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phenhuong.sanpham.online",nocase; classtype:trojan-activity; sid:100002875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phittc.com",nocase; classtype:trojan-activity; sid:100002876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"photo360.kubooking.com",nocase; classtype:trojan-activity; sid:100002877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pink99.com",nocase; classtype:trojan-activity; sid:100002878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"plasfan.ind.br",nocase; classtype:trojan-activity; sid:100002879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"playground2.grupoaliadasca.com",nocase; classtype:trojan-activity; sid:100002880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pmglance.startwriteup.com",nocase; classtype:trojan-activity; sid:100002881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pokojewewladyslawowie.pl",nocase; classtype:trojan-activity; sid:100002882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pole.com.vc",nocase; classtype:trojan-activity; sid:100002883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pool.phxdir.com",nocase; classtype:trojan-activity; sid:100002884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pooltablemoversdenver.net",nocase; classtype:trojan-activity; sid:100002885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"posmicrosystems.com",nocase; classtype:trojan-activity; sid:100002886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"poulman.panagiotopoulos-tours.gr",nocase; classtype:trojan-activity; sid:100002887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ppdb.smk-ciptaskill.sch.id",nocase; classtype:trojan-activity; sid:100002888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestasicash.com.ar",nocase; classtype:trojan-activity; sid:100002889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestigehomeautomation.net",nocase; classtype:trojan-activity; sid:100002890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"preview2.behalen.com",nocase; classtype:trojan-activity; sid:100002891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prishaartcreations.com",nocase; classtype:trojan-activity; sid:100002892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"production.sparshims.com",nocase; classtype:trojan-activity; sid:100002893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"programaoperadoronline.com.br",nocase; classtype:trojan-activity; sid:100002894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"project.exquitec.com",nocase; classtype:trojan-activity; sid:100002895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promotoradescomplica.com.br",nocase; classtype:trojan-activity; sid:100002896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promoversdubai.com",nocase; classtype:trojan-activity; sid:100002897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq.elin.co.za",nocase; classtype:trojan-activity; sid:100002898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq2.elin.co.za",nocase; classtype:trojan-activity; sid:100002899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosoc.nl",nocase; classtype:trojan-activity; sid:100002900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosyarmakassar.com",nocase; classtype:trojan-activity; sid:100002901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"provence.elin.co.za",nocase; classtype:trojan-activity; sid:100002902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prox.realunix.cc",nocase; classtype:trojan-activity; sid:100002903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pujashoppe.in",nocase; classtype:trojan-activity; sid:100002904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punchdialogues.com",nocase; classtype:trojan-activity; sid:100002905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punjabdevelopersassociation.com.pk",nocase; classtype:trojan-activity; sid:100002906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pvcprinting.co.uk",nocase; classtype:trojan-activity; sid:100002907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qadir.tickfa.ir",nocase; classtype:trojan-activity; sid:100002908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qatarglobalconsulting.com",nocase; classtype:trojan-activity; sid:100002909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qmsled.com",nocase; classtype:trojan-activity; sid:100002910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qu.o.t.ev.v.n.r@zytrox.tk",nocase; classtype:trojan-activity; sid:100002911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quartier-midi.be",nocase; classtype:trojan-activity; sid:100002912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"querocar.com",nocase; classtype:trojan-activity; sid:100002913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rachmat-assuhaimi.my.id",nocase; classtype:trojan-activity; sid:100002914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"radioafifense.deploys.live",nocase; classtype:trojan-activity; sid:100002915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rainbowisp.info",nocase; classtype:trojan-activity; sid:100002916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rajeshtailang.com",nocase; classtype:trojan-activity; sid:100002917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rakeshkhatri.in",nocase; classtype:trojan-activity; sid:100002918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raodigitalmedia.com",nocase; classtype:trojan-activity; sid:100002919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raquelhelena.com.br",nocase; classtype:trojan-activity; sid:100002920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rarlabarchiver.ac",nocase; classtype:trojan-activity; sid:100002921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rasadbar.ir",nocase; classtype:trojan-activity; sid:100002922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rashika.ascarvalho.co.za",nocase; classtype:trojan-activity; sid:100002923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ratemyfenancialadvisor.com",nocase; classtype:trojan-activity; sid:100002924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ravenproductionsltd.com",nocase; classtype:trojan-activity; sid:100002925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ravo.net.au",nocase; classtype:trojan-activity; sid:100002926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rc.ixiaoyang.cn",nocase; classtype:trojan-activity; sid:100002927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rcmesilva.charbelsales.com.br",nocase; classtype:trojan-activity; sid:100002928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reacredit.com.br",nocase; classtype:trojan-activity; sid:100002929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"readwrite26.nl",nocase; classtype:trojan-activity; sid:100002930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"readymmade.com",nocase; classtype:trojan-activity; sid:100002931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"recyclethesurplus.com",nocase; classtype:trojan-activity; sid:100002932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redbats.co.in",nocase; classtype:trojan-activity; sid:100002933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redboxmultimedia.com",nocase; classtype:trojan-activity; sid:100002934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redchillicrackers.com",nocase; classtype:trojan-activity; sid:100002935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reifenquick.de",nocase; classtype:trojan-activity; sid:100002936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"renehavis.com.ua",nocase; classtype:trojan-activity; sid:100002937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"repatriacioncolombia.com",nocase; classtype:trojan-activity; sid:100002938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.uf1.cn",nocase; classtype:trojan-activity; sid:100002939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reseller.digimitra.in",nocase; classtype:trojan-activity; sid:100002940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reseller.itechbrasil.com",nocase; classtype:trojan-activity; sid:100002941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"resuco.net",nocase; classtype:trojan-activity; sid:100002942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rezkabum.ru",nocase; classtype:trojan-activity; sid:100002943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rhema.com.sg",nocase; classtype:trojan-activity; sid:100002944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richmondminerals.co.zm",nocase; classtype:trojan-activity; sid:100002945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinaefoundation.org.za",nocase; classtype:trojan-activity; sid:100002946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinkaisystem-ht.com",nocase; classtype:trojan-activity; sid:100002947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"riverfox.co.za",nocase; classtype:trojan-activity; sid:100002948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkcable.co.in",nocase; classtype:trojan-activity; sid:100002949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkverify.securestudies.com",nocase; classtype:trojan-activity; sid:100002950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertmcardle.com",nocase; classtype:trojan-activity; sid:100002951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertsinclair.net",nocase; classtype:trojan-activity; sid:100002952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"romanianpoints.com",nocase; classtype:trojan-activity; sid:100002953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ronnietucker.co.uk",nocase; classtype:trojan-activity; sid:100002954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roomsvc.servegate.kr",nocase; classtype:trojan-activity; sid:100002955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roshnijewellery.com",nocase; classtype:trojan-activity; sid:100002956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rotronics.com.ph",nocase; classtype:trojan-activity; sid:100002957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rsgym.net",nocase; classtype:trojan-activity; sid:100002958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubazar.pro",nocase; classtype:trojan-activity; sid:100002959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubycityvietnam.com",nocase; classtype:trojan-activity; sid:100002960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruisgood.ru",nocase; classtype:trojan-activity; sid:100002961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruwadalkuwait.com",nocase; classtype:trojan-activity; sid:100002962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.51shijuan.com",nocase; classtype:trojan-activity; sid:100002963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.hu.d.es.h.d.u.e54.78.16247@46.249.33.79",nocase; classtype:trojan-activity; sid:100002964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.thechinesemuslim.com",nocase; classtype:trojan-activity; sid:100002965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sacredscentsonline.com",nocase; classtype:trojan-activity; sid:100002966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sadmahfuneralservices.co.za",nocase; classtype:trojan-activity; sid:100002967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safcol-colors.com",nocase; classtype:trojan-activity; sid:100002968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safehubsecurity.ca",nocase; classtype:trojan-activity; sid:100002969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safety.nanotechproautocare.com",nocase; classtype:trojan-activity; sid:100002970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sahathaikasetpan.com",nocase; classtype:trojan-activity; sid:100002971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sainzim.co.za",nocase; classtype:trojan-activity; sid:100002972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"saisoftwareinc.com",nocase; classtype:trojan-activity; sid:100002973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"salecorner.yourpageserver.com",nocase; classtype:trojan-activity; sid:100002974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"salonsaifa.com",nocase; classtype:trojan-activity; sid:100002975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"samriddhijyotish.com",nocase; classtype:trojan-activity; sid:100002976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sandovalgraphics.com",nocase; classtype:trojan-activity; sid:100002977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"santyago.org",nocase; classtype:trojan-activity; sid:100002978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sasystemsuk.com",nocase; classtype:trojan-activity; sid:100002979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scarfaceindustries.com",nocase; classtype:trojan-activity; sid:100002980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scglobal.co.th",nocase; classtype:trojan-activity; sid:100002981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schalke04rss.de",nocase; classtype:trojan-activity; sid:100002982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scheff.com",nocase; classtype:trojan-activity; sid:100002983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schoolbustracker.softgig.co.ke",nocase; classtype:trojan-activity; sid:100002984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sculetus.nl",nocase; classtype:trojan-activity; sid:100002985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"secure-doc-reader.com",nocase; classtype:trojan-activity; sid:100002986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"secure.activedirect.xyz",nocase; classtype:trojan-activity; sid:100002987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"segalsmetals.elin.co.za",nocase; classtype:trojan-activity; sid:100002988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sellmyphonela.com",nocase; classtype:trojan-activity; sid:100002989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"selltechtoday.com",nocase; classtype:trojan-activity; sid:100002990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"senbiaojita.com",nocase; classtype:trojan-activity; sid:100002991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sentierodelviandante.ml",nocase; classtype:trojan-activity; sid:100002992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serendibsourcing.com",nocase; classtype:trojan-activity; sid:100002993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sericaasia.com",nocase; classtype:trojan-activity; sid:100002994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd.myvnc.com",nocase; classtype:trojan-activity; sid:100002995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd80.myvnc.com",nocase; classtype:trojan-activity; sid:100002996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serviciovirtual.com.ar",nocase; classtype:trojan-activity; sid:100002997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sexologistpakistan.net",nocase; classtype:trojan-activity; sid:100002998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sgb.ac.ke",nocase; classtype:trojan-activity; sid:100002999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sgessy.com.br",nocase; classtype:trojan-activity; sid:100003000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shaheentbfoundation.com",nocase; classtype:trojan-activity; sid:100003001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shahikhana.cstdevs.com",nocase; classtype:trojan-activity; sid:100003002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shahu66.com",nocase; classtype:trojan-activity; sid:100003003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shalombaptistchapel.com",nocase; classtype:trojan-activity; sid:100003004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharkrigs.com",nocase; classtype:trojan-activity; sid:100003005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharpelevators.in",nocase; classtype:trojan-activity; sid:100003006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shembefoundation.com",nocase; classtype:trojan-activity; sid:100003007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shidditourism.com",nocase; classtype:trojan-activity; sid:100003008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shivakunwar.com.np",nocase; classtype:trojan-activity; sid:100003009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shoblasaathitrust.org",nocase; classtype:trojan-activity; sid:100003010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shomalhouse.com",nocase; classtype:trojan-activity; sid:100003011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shooka-co.com",nocase; classtype:trojan-activity; sid:100003012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shop.goldspot.agency",nocase; classtype:trojan-activity; sid:100003013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shopsofe.com",nocase; classtype:trojan-activity; sid:100003014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sibernetix.fr",nocase; classtype:trojan-activity; sid:100003015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sige.brisainformatica.com.br",nocase; classtype:trojan-activity; sid:100003016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"signatureads.co.in",nocase; classtype:trojan-activity; sid:100003017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siili.net",nocase; classtype:trojan-activity; sid:100003018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simoneporzi.it",nocase; classtype:trojan-activity; sid:100003019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simorsint.com",nocase; classtype:trojan-activity; sid:100003020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simplithy.co.uk",nocase; classtype:trojan-activity; sid:100003021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindicato1ucm.cl",nocase; classtype:trojan-activity; sid:100003022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindpol.tiejuris.com.br",nocase; classtype:trojan-activity; sid:100003023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sipahielektrik.com",nocase; classtype:trojan-activity; sid:100003024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sistelligent.com",nocase; classtype:trojan-activity; sid:100003025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyflyfares.com",nocase; classtype:trojan-activity; sid:100003026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyscan.com",nocase; classtype:trojan-activity; sid:100003027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"slot0.gamoruz.com",nocase; classtype:trojan-activity; sid:100003028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smarthouseforum.ru",nocase; classtype:trojan-activity; sid:100003029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smartzedu.com",nocase; classtype:trojan-activity; sid:100003030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smokesolutionindia.com",nocase; classtype:trojan-activity; sid:100003031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smritiphotography.in",nocase; classtype:trojan-activity; sid:100003032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sobariko.com",nocase; classtype:trojan-activity; sid:100003033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sobethuacademy.com",nocase; classtype:trojan-activity; sid:100003034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.110route.com",nocase; classtype:trojan-activity; sid:100003035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.officelabo.net",nocase; classtype:trojan-activity; sid:100003036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sohs.conceptechs.info",nocase; classtype:trojan-activity; sid:100003037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"solar.amazingtribe.lk",nocase; classtype:trojan-activity; sid:100003038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somcorbera.cat",nocase; classtype:trojan-activity; sid:100003039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somir.com.mx",nocase; classtype:trojan-activity; sid:100003040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soralapps.com",nocase; classtype:trojan-activity; sid:100003041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sota-france.fr",nocase; classtype:trojan-activity; sid:100003042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"space.proactint.org",nocase; classtype:trojan-activity; sid:100003043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spaceframe.mobi.space-frame.co.za",nocase; classtype:trojan-activity; sid:100003044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"special-key.cf",nocase; classtype:trojan-activity; sid:100003045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spent.com.pl",nocase; classtype:trojan-activity; sid:100003046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spetsesyachtcharter.gr",nocase; classtype:trojan-activity; sid:100003047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spititourism.com",nocase; classtype:trojan-activity; sid:100003048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spittinfire.com",nocase; classtype:trojan-activity; sid:100003049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"src1.minibai.com",nocase; classtype:trojan-activity; sid:100003050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sreenivasapaintingworks.com",nocase; classtype:trojan-activity; sid:100003051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sriglobalit.com",nocase; classtype:trojan-activity; sid:100003052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"srilankamovies.com",nocase; classtype:trojan-activity; sid:100003053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"srvmanos.no-ip.info",nocase; classtype:trojan-activity; sid:100003054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ss.monita.co.id",nocase; classtype:trojan-activity; sid:100003055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"st.devcodin.com",nocase; classtype:trojan-activity; sid:100003056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"staging.apparelpunch.com",nocase; classtype:trojan-activity; sid:100003057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"starcountry.net",nocase; classtype:trojan-activity; sid:100003058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"static.3001.net",nocase; classtype:trojan-activity; sid:100003059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stdynbnbnewagedevixz.dns.army",nocase; classtype:trojan-activity; sid:100003060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stdynmxwllminoragest.dns.army",nocase; classtype:trojan-activity; sid:100003061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stdyunitedkesokokgst.dns.army",nocase; classtype:trojan-activity; sid:100003062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stdyworkfinetraingst.dns.army",nocase; classtype:trojan-activity; sid:100003063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stdyzgchgcloudgostxs.dns.army",nocase; classtype:trojan-activity; sid:100003064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stiau.iuc.ac",nocase; classtype:trojan-activity; sid:100003065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sticker.jewsjuice.com",nocase; classtype:trojan-activity; sid:100003066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stiepancasetia.ac.id",nocase; classtype:trojan-activity; sid:100003067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stlukesohag.com",nocase; classtype:trojan-activity; sid:100003068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"store.ericalgarin.com",nocase; classtype:trojan-activity; sid:100003069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stott-thompson.co.uk",nocase; classtype:trojan-activity; sid:100003070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stratexec.co.za",nocase; classtype:trojan-activity; sid:100003071; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"streetdemo.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003072; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"suboldesign.com",nocase; classtype:trojan-activity; sid:100003073; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sumerians.org",nocase; classtype:trojan-activity; sid:100003074; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunaryem.com.tr",nocase; classtype:trojan-activity; sid:100003075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunbrero.com.au",nocase; classtype:trojan-activity; sid:100003076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunmarkholidays.com",nocase; classtype:trojan-activity; sid:100003077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support-4-free.com",nocase; classtype:trojan-activity; sid:100003078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support.clz.kr",nocase; classtype:trojan-activity; sid:100003079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supportit.online",nocase; classtype:trojan-activity; sid:100003080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sw.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweaty.dk",nocase; classtype:trojan-activity; sid:100003082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweet-diet.com",nocase; classtype:trojan-activity; sid:100003083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swiftlogisticseg.com",nocase; classtype:trojan-activity; sid:100003084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swwbia.com",nocase; classtype:trojan-activity; sid:100003085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"syracusecoffee.com",nocase; classtype:trojan-activity; sid:100003086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sytraders.co",nocase; classtype:trojan-activity; sid:100003087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"t.honker.info",nocase; classtype:trojan-activity; sid:100003088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tadoo.ca",nocase; classtype:trojan-activity; sid:100003089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tafsantoursandtravels.com",nocase; classtype:trojan-activity; sid:100003090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tajushariya.com",nocase; classtype:trojan-activity; sid:100003091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tallyinvoicecustomization.com",nocase; classtype:trojan-activity; sid:100003092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taltus.co.uk",nocase; classtype:trojan-activity; sid:100003093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tapalkoedacoffee.com",nocase; classtype:trojan-activity; sid:100003094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tarravalleyfoods.com.au",nocase; classtype:trojan-activity; sid:100003095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taurus.ug",nocase; classtype:trojan-activity; sid:100003096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tc.snpsresidential.com",nocase; classtype:trojan-activity; sid:100003097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tcy.198424.com",nocase; classtype:trojan-activity; sid:100003098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tdsp.yngw518.com",nocase; classtype:trojan-activity; sid:100003099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"techgms.com",nocase; classtype:trojan-activity; sid:100003100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teduae.com",nocase; classtype:trojan-activity; sid:100003101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teleargentina.com",nocase; classtype:trojan-activity; sid:100003102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"telescopelms.com",nocase; classtype:trojan-activity; sid:100003103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"temptmag.com",nocase; classtype:trojan-activity; sid:100003104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tencoconsulting.com",nocase; classtype:trojan-activity; sid:100003105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teneth.co.za",nocase; classtype:trojan-activity; sid:100003106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tentandoserfitness.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tessrobins.com",nocase; classtype:trojan-activity; sid:100003108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.adventser.com",nocase; classtype:trojan-activity; sid:100003109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.letraele.es",nocase; classtype:trojan-activity; sid:100003110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.lubrico.in",nocase; classtype:trojan-activity; sid:100003111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.protocsconnectes.eu",nocase; classtype:trojan-activity; sid:100003112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.typoten.com",nocase; classtype:trojan-activity; sid:100003113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.wanepghana.org",nocase; classtype:trojan-activity; sid:100003114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.asistencia247.com",nocase; classtype:trojan-activity; sid:100003115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.milenial.id",nocase; classtype:trojan-activity; sid:100003116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.tenplusone.my",nocase; classtype:trojan-activity; sid:100003117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.basis-web.com",nocase; classtype:trojan-activity; sid:100003118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.marrenconstruction.ie",nocase; classtype:trojan-activity; sid:100003119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.clickitsolutionsmw.com",nocase; classtype:trojan-activity; sid:100003120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.thinkingcorp.in",nocase; classtype:trojan-activity; sid:100003121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testnew.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teteaffiche.stephanebillon.com",nocase; classtype:trojan-activity; sid:100003123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tewoerd.eu",nocase; classtype:trojan-activity; sid:100003124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"textile.softberg.ro",nocase; classtype:trojan-activity; sid:100003125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tharringtonsponsorship.com",nocase; classtype:trojan-activity; sid:100003126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecleaningladiespdx.com",nocase; classtype:trojan-activity; sid:100003127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecreativecafe.co.uk",nocase; classtype:trojan-activity; sid:100003128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thedesertship.com",nocase; classtype:trojan-activity; sid:100003129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thefamouscurrybazaar.co.uk",nocase; classtype:trojan-activity; sid:100003130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thefuturelife.in",nocase; classtype:trojan-activity; sid:100003131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thehighlightinterior.com",nocase; classtype:trojan-activity; sid:100003132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thekassia.co.uk",nocase; classtype:trojan-activity; sid:100003133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"themansionkasauli.com",nocase; classtype:trojan-activity; sid:100003134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theprofinn.com",nocase; classtype:trojan-activity; sid:100003135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thesummitpc.net",nocase; classtype:trojan-activity; sid:100003136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theurbantutors.com",nocase; classtype:trojan-activity; sid:100003137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thosewebbs.com",nocase; classtype:trojan-activity; sid:100003138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thriveink.com",nocase; classtype:trojan-activity; sid:100003139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tianangdep.com",nocase; classtype:trojan-activity; sid:100003140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickfoods.tickme.lk",nocase; classtype:trojan-activity; sid:100003141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tidymasters.com.au",nocase; classtype:trojan-activity; sid:100003142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"timegonebuy.com",nocase; classtype:trojan-activity; sid:100003143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tksb.net",nocase; classtype:trojan-activity; sid:100003144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tlcc.com.gt",nocase; classtype:trojan-activity; sid:100003145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"todoapp.cstdevs.com",nocase; classtype:trojan-activity; sid:100003146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonydong.com",nocase; classtype:trojan-activity; sid:100003147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonyzone.com",nocase; classtype:trojan-activity; sid:100003148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tooba.tenplusone.my",nocase; classtype:trojan-activity; sid:100003149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tools.reimclub.com",nocase; classtype:trojan-activity; sid:100003150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topcell9.com",nocase; classtype:trojan-activity; sid:100003151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toplevel.com.br",nocase; classtype:trojan-activity; sid:100003152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topmask.co.za",nocase; classtype:trojan-activity; sid:100003153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"torresquinterocorp.com",nocase; classtype:trojan-activity; sid:100003154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toyotacollege.ac.th",nocase; classtype:trojan-activity; sid:100003155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpke.hu",nocase; classtype:trojan-activity; sid:100003156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"translaterjemah.com",nocase; classtype:trojan-activity; sid:100003157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"travelwithmanta.co.za",nocase; classtype:trojan-activity; sid:100003158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trendyshoes.co.za",nocase; classtype:trojan-activity; sid:100003159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trezors.io.mahlongwa.com",nocase; classtype:trojan-activity; sid:100003160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trimestre.bar",nocase; classtype:trojan-activity; sid:100003161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"troki.com.co",nocase; classtype:trojan-activity; sid:100003162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tropics.codeleek.net",nocase; classtype:trojan-activity; sid:100003163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trudelfavreau.com",nocase; classtype:trojan-activity; sid:100003164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsd.jxwan.com",nocase; classtype:trojan-activity; sid:100003165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tulli.info",nocase; classtype:trojan-activity; sid:100003166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tupperware.michaelroberge.ca",nocase; classtype:trojan-activity; sid:100003167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"turanggaresources.com",nocase; classtype:trojan-activity; sid:100003168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uat.indianfilmzone.com",nocase; classtype:trojan-activity; sid:100003169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ublretailerdemo.cstdevs.com",nocase; classtype:trojan-activity; sid:100003170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uc-56.ru",nocase; classtype:trojan-activity; sid:100003171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uisusa.uisusa.com",nocase; classtype:trojan-activity; sid:100003172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ultimate-24.de",nocase; classtype:trojan-activity; sid:100003173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"umwelt-kirchhof.de",nocase; classtype:trojan-activity; sid:100003174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unicorpbrunei.com",nocase; classtype:trojan-activity; sid:100003175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uniengrisb.com",nocase; classtype:trojan-activity; sid:100003176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"union.jctrip.cn",nocase; classtype:trojan-activity; sid:100003177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unyazitelecom.com",nocase; classtype:trojan-activity; sid:100003178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"up.llw0.com",nocase; classtype:trojan-activity; sid:100003179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"upcbpta.com",nocase; classtype:trojan-activity; sid:100003180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"useformoney.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uss.ac.th",nocase; classtype:trojan-activity; sid:100003182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uzzepay.com.br",nocase; classtype:trojan-activity; sid:100003183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vanzare.cabanabrazi2.ro",nocase; classtype:trojan-activity; sid:100003184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vbcargo.hu",nocase; classtype:trojan-activity; sid:100003185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vcah.co.uk",nocase; classtype:trojan-activity; sid:100003186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vectarts.com",nocase; classtype:trojan-activity; sid:100003187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vegadelcasero.cl",nocase; classtype:trojan-activity; sid:100003188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vendas.lidiacarmeli.com.br",nocase; classtype:trojan-activity; sid:100003189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"veterinariadrpopui.com",nocase; classtype:trojan-activity; sid:100003190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vfocus.net",nocase; classtype:trojan-activity; sid:100003191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vienen.gblix.srv.br",nocase; classtype:trojan-activity; sid:100003192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vilaart.rs",nocase; classtype:trojan-activity; sid:100003193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villamarand.com",nocase; classtype:trojan-activity; sid:100003194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villatera.com",nocase; classtype:trojan-activity; sid:100003195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"violinstop.com",nocase; classtype:trojan-activity; sid:100003196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"virtuleverage.com",nocase; classtype:trojan-activity; sid:100003197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visions.alnisamart.com",nocase; classtype:trojan-activity; sid:100003198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visualhome.cl",nocase; classtype:trojan-activity; sid:100003199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vivationdesign.com",nocase; classtype:trojan-activity; sid:100003200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"viveirodoiscorregos.com.br",nocase; classtype:trojan-activity; sid:100003201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vksales.com",nocase; classtype:trojan-activity; sid:100003202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vocalterra.com",nocase; classtype:trojan-activity; sid:100003203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vologroup.com.br",nocase; classtype:trojan-activity; sid:100003204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"voteyouramerica.dekitout.com",nocase; classtype:trojan-activity; sid:100003205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vpts.co.za",nocase; classtype:trojan-activity; sid:100003206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vstsample.com",nocase; classtype:trojan-activity; sid:100003207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vtube.fadlymotivator.com",nocase; classtype:trojan-activity; sid:100003208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vvsskmodinationalschool.com",nocase; classtype:trojan-activity; sid:100003209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu",nocase; classtype:trojan-activity; sid:100003210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepliberia.org",nocase; classtype:trojan-activity; sid:100003211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepniger.org",nocase; classtype:trojan-activity; sid:100003212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weareactum.com",nocase; classtype:trojan-activity; sid:100003213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.eng.ubu.ac.th",nocase; classtype:trojan-activity; sid:100003214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geomegasoft.net",nocase; classtype:trojan-activity; sid:100003215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.newinnovationtechnology.com",nocase; classtype:trojan-activity; sid:100003216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.smarts-works.com",nocase; classtype:trojan-activity; sid:100003217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.thebeessolution.com",nocase; classtype:trojan-activity; sid:100003218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webgis.perumdasolo.com",nocase; classtype:trojan-activity; sid:100003219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webpresario.com",nocase; classtype:trojan-activity; sid:100003220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weinsteincounseling.com",nocase; classtype:trojan-activity; sid:100003221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wfinance.com.br",nocase; classtype:trojan-activity; sid:100003222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whcms.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteglovetailgate.com",nocase; classtype:trojan-activity; sid:100003224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteresponse.com",nocase; classtype:trojan-activity; sid:100003225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wi522012.ferozo.com",nocase; classtype:trojan-activity; sid:100003226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikalen.co.za",nocase; classtype:trojan-activity; sid:100003227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildnights.co.uk",nocase; classtype:trojan-activity; sid:100003228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildtrust.mediadevstaging.com",nocase; classtype:trojan-activity; sid:100003229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"willow-nettica.com",nocase; classtype:trojan-activity; sid:100003230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wimbamusica.com",nocase; classtype:trojan-activity; sid:100003231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"windcomtechnologies.com",nocase; classtype:trojan-activity; sid:100003232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wishesconcierge.com",nocase; classtype:trojan-activity; sid:100003233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woezon.agency",nocase; classtype:trojan-activity; sid:100003234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wolfgang-brodte.de",nocase; classtype:trojan-activity; sid:100003235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woodsytech.com",nocase; classtype:trojan-activity; sid:100003236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wordpress.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100003237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wozata.000webhostapp.com",nocase; classtype:trojan-activity; sid:100003238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wp.readhere.in",nocase; classtype:trojan-activity; sid:100003239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wpdemo.101clients.com.au",nocase; classtype:trojan-activity; sid:100003240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"writtendeer.com",nocase; classtype:trojan-activity; sid:100003241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ws5588.f3322.net",nocase; classtype:trojan-activity; sid:100003242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wyklej.pl",nocase; classtype:trojan-activity; sid:100003243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"x2vn.com",nocase; classtype:trojan-activity; sid:100003244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xia.beihaixue.com",nocase; classtype:trojan-activity; sid:100003245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xixaoclothing.com",nocase; classtype:trojan-activity; sid:100003246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xk.996is.com",nocase; classtype:trojan-activity; sid:100003247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--polimerbizmimarlk-rvc.com",nocase; classtype:trojan-activity; sid:100003248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ybom.urbanolab.com",nocase; classtype:trojan-activity; sid:100003249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yeichner.com",nocase; classtype:trojan-activity; sid:100003250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yeq.i.u.j.ia.n.3@zytrox.tk",nocase; classtype:trojan-activity; sid:100003251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ylfpremium.com",nocase; classtype:trojan-activity; sid:100003252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yoast.yourpageserver.com",nocase; classtype:trojan-activity; sid:100003253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yp.hnggzyjy.cn",nocase; classtype:trojan-activity; sid:100003254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yummyyogaudaipur.com",nocase; classtype:trojan-activity; sid:100003255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yzkzixun.com",nocase; classtype:trojan-activity; sid:100003256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ziyker4gaming@zytrox.tk",nocase; classtype:trojan-activity; sid:100003257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zmedcoach.com",nocase; classtype:trojan-activity; sid:100003258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zytrox.tk",nocase; classtype:trojan-activity; sid:100003259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zz.690tx.com",nocase; classtype:trojan-activity; sid:100003260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100003261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/86.exe",nocase; classtype:trojan-activity; sid:100003262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/c64.exe",nocase; classtype:trojan-activity; sid:100003263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amumufree.weebly.com",nocase; http_uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe",nocase; classtype:trojan-activity; sid:100003264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"analogx.com",nocase; http_uri; content:"/files/proxyi.exe",nocase; classtype:trojan-activity; sid:100003265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe",nocase; classtype:trojan-activity; sid:100003266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/clubhousedev/clubhouse/downloads/clubhousepc.exe",nocase; classtype:trojan-activity; sid:100003267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/dvdfv/anjj/downloads/jami.exe",nocase; classtype:trojan-activity; sid:100003268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/heyhoeee/heyhoename1/downloads/1234.exe",nocase; classtype:trojan-activity; sid:100003269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/4.exe",nocase; classtype:trojan-activity; sid:100003270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/6.exe",nocase; classtype:trojan-activity; sid:100003271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/labesoftware/update/downloads/boost-fps.exe",nocase; classtype:trojan-activity; sid:100003272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/labesoftware/update/downloads/install_plugin_x64_x86.exe",nocase; classtype:trojan-activity; sid:100003273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/labesoftware/update/downloads/vpn_free.exe",nocase; classtype:trojan-activity; sid:100003274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/clr.exe",nocase; classtype:trojan-activity; sid:100003275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/dianthus.exe",nocase; classtype:trojan-activity; sid:100003276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/n.exe",nocase; classtype:trojan-activity; sid:100003277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/newred.exe",nocase; classtype:trojan-activity; sid:100003278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/omar.exe",nocase; classtype:trojan-activity; sid:100003279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/serv.exe",nocase; classtype:trojan-activity; sid:100003280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/test.exe",nocase; classtype:trojan-activity; sid:100003281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updachrome.exe",nocase; classtype:trojan-activity; sid:100003282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatedata.exe",nocase; classtype:trojan-activity; sid:100003283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatev.exe",nocase; classtype:trojan-activity; sid:100003284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/work.exe",nocase; classtype:trojan-activity; sid:100003285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/component.exe",nocase; classtype:trojan-activity; sid:100003286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe",nocase; classtype:trojan-activity; sid:100003287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/regsvc.exe",nocase; classtype:trojan-activity; sid:100003288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/skygaming/updates/downloads/update.exe",nocase; classtype:trojan-activity; sid:100003289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/001.txt",nocase; classtype:trojan-activity; sid:100003290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1488.txt",nocase; classtype:trojan-activity; sid:100003291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1_cr.txt",nocase; classtype:trojan-activity; sid:100003292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1cr.txt",nocase; classtype:trojan-activity; sid:100003293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1fc2d.txt",nocase; classtype:trojan-activity; sid:100003294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/26a5.txt",nocase; classtype:trojan-activity; sid:100003295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt",nocase; classtype:trojan-activity; sid:100003296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/abjects.txt",nocase; classtype:trojan-activity; sid:100003297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/attached.txt",nocase; classtype:trojan-activity; sid:100003298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/b7f2c.exe",nocase; classtype:trojan-activity; sid:100003299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/battletext.txt",nocase; classtype:trojan-activity; sid:100003300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe",nocase; classtype:trojan-activity; sid:100003301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe",nocase; classtype:trojan-activity; sid:100003302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build.txt",nocase; classtype:trojan-activity; sid:100003303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_makros.exe",nocase; classtype:trojan-activity; sid:100003304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_silent.txt",nocase; classtype:trojan-activity; sid:100003305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_sup.txt",nocase; classtype:trojan-activity; sid:100003306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe",nocase; classtype:trojan-activity; sid:100003307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt",nocase; classtype:trojan-activity; sid:100003308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcr.txt",nocase; classtype:trojan-activity; sid:100003309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildss.txt",nocase; classtype:trojan-activity; sid:100003310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientnik.txt",nocase; classtype:trojan-activity; sid:100003311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientrevers.txt",nocase; classtype:trojan-activity; sid:100003312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dcrat.exe",nocase; classtype:trojan-activity; sid:100003313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices.exe",nocase; classtype:trojan-activity; sid:100003314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe",nocase; classtype:trojan-activity; sid:100003315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hans.txt",nocase; classtype:trojan-activity; sid:100003316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hulu.txt",nocase; classtype:trojan-activity; sid:100003317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfive.txt",nocase; classtype:trojan-activity; sid:100003318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfour.txt",nocase; classtype:trojan-activity; sid:100003319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelone.txt",nocase; classtype:trojan-activity; sid:100003320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelthree.txt",nocase; classtype:trojan-activity; sid:100003321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/inteltwo.txt",nocase; classtype:trojan-activity; sid:100003322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe",nocase; classtype:trojan-activity; sid:100003323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/kleiman.exe",nocase; classtype:trojan-activity; sid:100003324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe",nocase; classtype:trojan-activity; sid:100003325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/notepadplus.txt",nocase; classtype:trojan-activity; sid:100003326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe",nocase; classtype:trojan-activity; sid:100003327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.exe",nocase; classtype:trojan-activity; sid:100003328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.txt",nocase; classtype:trojan-activity; sid:100003329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt",nocase; classtype:trojan-activity; sid:100003330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/putty.txt",nocase; classtype:trojan-activity; sid:100003331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/rockethcd.txt",nocase; classtype:trojan-activity; sid:100003332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/scvhost900.exe",nocase; classtype:trojan-activity; sid:100003333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/sessionwin.exe",nocase; classtype:trojan-activity; sid:100003334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/siliculose.txt",nocase; classtype:trojan-activity; sid:100003335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/statemobi.txt",nocase; classtype:trojan-activity; sid:100003336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers.exe",nocase; classtype:trojan-activity; sid:100003337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers2.exe",nocase; classtype:trojan-activity; sid:100003338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stgedo.exe",nocase; classtype:trojan-activity; sid:100003339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/svcperf.txt",nocase; classtype:trojan-activity; sid:100003340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe",nocase; classtype:trojan-activity; sid:100003341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurjok.txt",nocase; classtype:trojan-activity; sid:100003342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurusbabac.exe",nocase; classtype:trojan-activity; sid:100003343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/telekiller.exe",nocase; classtype:trojan-activity; sid:100003344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateanddr.txt",nocase; classtype:trojan-activity; sid:100003345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateandr.txt",nocase; classtype:trojan-activity; sid:100003346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/vhajeja.txt",nocase; classtype:trojan-activity; sid:100003347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/word.txt",nocase; classtype:trojan-activity; sid:100003348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/www.txt",nocase; classtype:trojan-activity; sid:100003349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/xlsd.txt",nocase; classtype:trojan-activity; sid:100003350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin",nocase; classtype:trojan-activity; sid:100003351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin",nocase; classtype:trojan-activity; sid:100003352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cd.textfiles.com",nocase; http_uri; content:"/hmatrix/data/hack1226.exe",nocase; classtype:trojan-activity; sid:100003353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq",nocase; classtype:trojan-activity; sid:100003354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/775238059083038744/829993648186851338/pslmlyfnpzgsgitrwwvalcfunumfmac",nocase; classtype:trojan-activity; sid:100003355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/816070119281131570/816070273254162442/all.txt",nocase; classtype:trojan-activity; sid:100003356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/826848185246023750/loaddd.exe",nocase; classtype:trojan-activity; sid:100003357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/826848348342059008/zeppelin.exe",nocase; classtype:trojan-activity; sid:100003358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/826848405258633277/build.exe",nocase; classtype:trojan-activity; sid:100003359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/825372018244583454/830455061724528690/v1.exe",nocase; classtype:trojan-activity; sid:100003360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/826198252025675816/826537386485612574/china.png",nocase; classtype:trojan-activity; sid:100003361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin",nocase; classtype:trojan-activity; sid:100003362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe",nocase; classtype:trojan-activity; sid:100003363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chiptune.com",nocase; http_uri; content:"/razor/rzr-winner_intro.zip",nocase; classtype:trojan-activity; sid:100003364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz",nocase; classtype:trojan-activity; sid:100003365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar",nocase; classtype:trojan-activity; sid:100003366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codeload.github.com",nocase; http_uri; content:"/meteoradminz/hidden-tear/zip/master",nocase; classtype:trojan-activity; sid:100003367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colfincas.com",nocase; http_uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/",nocase; classtype:trojan-activity; sid:100003368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?export=download&id=1ktcghnmcwws43wzscphukbfnwtuaxidx&revid=0b8z0b7_i5sirk2xrtehmstg0vxvit3b4n3lmbdrdrjrodndrpq",nocase; classtype:trojan-activity; sid:100003369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docs.google.com",nocase; http_uri; content:"/uc?export=download&id=1qze6qzzh1uf7iaj4rqixttznx6u1--gc&revid=0b45wwmcofx7fuvnmdhpkt1d0k3rhzldyoffnuc83auzkslvrpq",nocase; classtype:trojan-activity; sid:100003370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com.it-barcelona.com",nocase; http_uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe",nocase; classtype:trojan-activity; sid:100003371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm",nocase; classtype:trojan-activity; sid:100003372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=11idvvx22jx_1lw-hxnpmlwuvjgdyp63g",nocase; classtype:trojan-activity; sid:100003373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=12khl-unz2np4q54b2jgpwlsh6cuz0pss",nocase; classtype:trojan-activity; sid:100003374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch",nocase; classtype:trojan-activity; sid:100003375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox",nocase; classtype:trojan-activity; sid:100003376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=16yyvhney9_-nygeipjqgnlcmwfoyiaxo",nocase; classtype:trojan-activity; sid:100003377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=17pl-4i0otjbyxwrtrdagxxebirdh2wl8",nocase; classtype:trojan-activity; sid:100003378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig",nocase; classtype:trojan-activity; sid:100003379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn",nocase; classtype:trojan-activity; sid:100003380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1br5iufkkmmfeipqo3ecviqykbcdgcnio",nocase; classtype:trojan-activity; sid:100003381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1bwtwpqmeqdvctbcqcc2gil5xzjf28c0z",nocase; classtype:trojan-activity; sid:100003382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv",nocase; classtype:trojan-activity; sid:100003383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben",nocase; classtype:trojan-activity; sid:100003384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1d0ij6qkgrf6irywv6ftk1m7p5l3weh3a",nocase; classtype:trojan-activity; sid:100003385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1dzx_cflers_zntlrip3fhbxb5who03u0",nocase; classtype:trojan-activity; sid:100003386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1gprlk2mcrl6law-zk5r0pjogaqrxwepd",nocase; classtype:trojan-activity; sid:100003387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei",nocase; classtype:trojan-activity; sid:100003388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr",nocase; classtype:trojan-activity; sid:100003389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1jdqcxydqvz3bjodp66ieiocbjcz8foi6",nocase; classtype:trojan-activity; sid:100003390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1l5urks5wzib2zcb16bfsk76bjrdsejms",nocase; classtype:trojan-activity; sid:100003391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ldxaekbcbzb-zfdix-ucj4rilobnbswx",nocase; classtype:trojan-activity; sid:100003392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ljz-kmuibyiehba6blw37guu_yr799y0",nocase; classtype:trojan-activity; sid:100003393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1lsv4sko083sywwjndgqnsh_6sgqodqtu",nocase; classtype:trojan-activity; sid:100003394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y",nocase; classtype:trojan-activity; sid:100003395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd",nocase; classtype:trojan-activity; sid:100003396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw",nocase; classtype:trojan-activity; sid:100003397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1oek6vmzbv15nyho_uqcbk4_vaq1ezowv",nocase; classtype:trojan-activity; sid:100003398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ph-lri07dohowhmuczrrvjwrtsvmnu9s",nocase; classtype:trojan-activity; sid:100003399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej",nocase; classtype:trojan-activity; sid:100003400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1r1flwyfwtyziyr47y5sk3q821r6_tgsl",nocase; classtype:trojan-activity; sid:100003401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1r9f9irwhutxozsbp2h9erd_a7fa2pwko",nocase; classtype:trojan-activity; sid:100003402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1s221a6wpx6i7nfrztnhh9priojtybuxq",nocase; classtype:trojan-activity; sid:100003403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1sutnyikgc4qw-tbvnnvzm8uz9thch0vz",nocase; classtype:trojan-activity; sid:100003404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn",nocase; classtype:trojan-activity; sid:100003405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1taubixyqiqdgfbhmc2rv_aitvkbqhzwz",nocase; classtype:trojan-activity; sid:100003406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1tpd_qbnl_mtmhfsv4a-qtfsnuiimyoy6",nocase; classtype:trojan-activity; sid:100003407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t",nocase; classtype:trojan-activity; sid:100003408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vjq92eqivh01yxmal20whl2es3ld6nxb",nocase; classtype:trojan-activity; sid:100003409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1voqnsh0cmxl5hty4zpc18pgnkud5rtvy",nocase; classtype:trojan-activity; sid:100003410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vy1nx5zefluh5ewihr-6pcndlyex7xcm",nocase; classtype:trojan-activity; sid:100003411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1wpqa2nnnktbhzs4j0r-erosvgyaagi_a",nocase; classtype:trojan-activity; sid:100003412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xbp7hvw2ybwjrftbvdkjvwzrfuk4ope9",nocase; classtype:trojan-activity; sid:100003413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e",nocase; classtype:trojan-activity; sid:100003414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi",nocase; classtype:trojan-activity; sid:100003415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58",nocase; classtype:trojan-activity; sid:100003416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi",nocase; classtype:trojan-activity; sid:100003417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ywkgalidldb32pio6ywmbyvdk7oar3yy",nocase; classtype:trojan-activity; sid:100003418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr",nocase; classtype:trojan-activity; sid:100003419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0",nocase; classtype:trojan-activity; sid:100003420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/1zilg/",nocase; classtype:trojan-activity; sid:100003421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/qcgfmfvh/",nocase; classtype:trojan-activity; sid:100003422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-mudhra.com",nocase; http_uri; content:"/downloads/emclick.zip",nocase; classtype:trojan-activity; sid:100003423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evertkok.nl",nocase; http_uri; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe",nocase; classtype:trojan-activity; sid:100003424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evertkok.nl",nocase; http_uri; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe",nocase; classtype:trojan-activity; sid:100003425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/",nocase; classtype:trojan-activity; sid:100003426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/",nocase; classtype:trojan-activity; sid:100003427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/x/",nocase; classtype:trojan-activity; sid:100003428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/",nocase; classtype:trojan-activity; sid:100003429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//",nocase; classtype:trojan-activity; sid:100003430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///",nocase; classtype:trojan-activity; sid:100003431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////",nocase; classtype:trojan-activity; sid:100003432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"file.elecfans.com",nocase; http_uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe",nocase; classtype:trojan-activity; sid:100003433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls",nocase; classtype:trojan-activity; sid:100003434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx",nocase; classtype:trojan-activity; sid:100003435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gist.githubusercontent.com",nocase; http_uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe",nocase; classtype:trojan-activity; sid:100003436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hqdecig.com",nocase; http_uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/",nocase; classtype:trojan-activity; sid:100003437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsecaravans.co.uk",nocase; http_uri; content:"/wp-admin/suy/",nocase; classtype:trojan-activity; sid:100003438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ia801802.us.archive.org",nocase; http_uri; content:"/19/items/startup_20210219/startup.txt",nocase; classtype:trojan-activity; sid:100003439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ie-best.net",nocase; http_uri; content:"/online-timer-kvhxz/ilxl/",nocase; classtype:trojan-activity; sid:100003440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100003441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/c64.exe",nocase; classtype:trojan-activity; sid:100003442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jcedu.org",nocase; http_uri; content:"/ebook/cs17.exe",nocase; classtype:trojan-activity; sid:100003443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1",nocase; classtype:trojan-activity; sid:100003444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2",nocase; classtype:trojan-activity; sid:100003445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3",nocase; classtype:trojan-activity; sid:100003446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karmakoincodes.weebly.com",nocase; http_uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe",nocase; classtype:trojan-activity; sid:100003447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kotakwarna.co.id",nocase; http_uri; content:"/dg/etrac/nf4emwz/",nocase; classtype:trojan-activity; sid:100003448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ksh.hu",nocase; http_uri; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe",nocase; classtype:trojan-activity; sid:100003449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kuaizip.com",nocase; http_uri; content:"/down/affiliate/kuaizip_setup_10029.exe",nocase; classtype:trojan-activity; sid:100003450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linuxforensicsbook.com.s3.amazonaws.com",nocase; http_uri; content:"/linuxforensicscode.zip",nocase; classtype:trojan-activity; sid:100003451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lojavirtual.top",nocase; http_uri; content:"/dl8.exe",nocase; classtype:trojan-activity; sid:100003452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lojavirtual.top",nocase; http_uri; content:"/dl8v2.exe",nocase; classtype:trojan-activity; sid:100003453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minpic.de",nocase; http_uri; content:"/k/big5/1giof6/",nocase; classtype:trojan-activity; sid:100003454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"morrobaydrugandgift.com",nocase; http_uri; content:"/wp-contentbak/t9m/",nocase; classtype:trojan-activity; sid:100003455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"my.cloudme.com",nocase; http_uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe",nocase; classtype:trojan-activity; sid:100003456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/aacenc.exe",nocase; classtype:trojan-activity; sid:100003457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/doxillionsetup.exe",nocase; classtype:trojan-activity; sid:100003458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newyarlfm.weebly.com",nocase; http_uri; content:"/uploads/4/1/6/6/4166984/keygen.exe",nocase; classtype:trojan-activity; sid:100003459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhipcauytevietnhat.com",nocase; http_uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/",nocase; classtype:trojan-activity; sid:100003460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"note.youdao.com",nocase; http_uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a",nocase; classtype:trojan-activity; sid:100003461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oldschoolvalue.s3.amazonaws.com",nocase; http_uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe",nocase; classtype:trojan-activity; sid:100003462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20cid=ba02d68febf523dc&resid=ba02d68febf523dc!1431&authkey=afbifi7o9ywbjpm",nocase; classtype:trojan-activity; sid:100003463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?%20cid=ba02d68febf523dc&resid=ba02d68febf523dc%211431&authkey=afbifi7o9ywbjpm",nocase; classtype:trojan-activity; sid:100003464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa",nocase; classtype:trojan-activity; sid:100003465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq",nocase; classtype:trojan-activity; sid:100003466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe",nocase; classtype:trojan-activity; sid:100003467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg",nocase; classtype:trojan-activity; sid:100003468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0",nocase; classtype:trojan-activity; sid:100003469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g",nocase; classtype:trojan-activity; sid:100003470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140",nocase; classtype:trojan-activity; sid:100003471; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130",nocase; classtype:trojan-activity; sid:100003472; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135",nocase; classtype:trojan-activity; sid:100003473; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732",nocase; classtype:trojan-activity; sid:100003474; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4",nocase; classtype:trojan-activity; sid:100003475; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100003476; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100003477; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0",nocase; classtype:trojan-activity; sid:100003478; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100003479; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100003480; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100003481; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100003482; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc",nocase; classtype:trojan-activity; sid:100003483; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq",nocase; classtype:trojan-activity; sid:100003484; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko",nocase; classtype:trojan-activity; sid:100003485; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw",nocase; classtype:trojan-activity; sid:100003486; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma",nocase; classtype:trojan-activity; sid:100003487; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48",nocase; classtype:trojan-activity; sid:100003488; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq",nocase; classtype:trojan-activity; sid:100003489; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg",nocase; classtype:trojan-activity; sid:100003490; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw",nocase; classtype:trojan-activity; sid:100003491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq",nocase; classtype:trojan-activity; sid:100003492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d!184&authkey=ackbiiarirejcam",nocase; classtype:trojan-activity; sid:100003493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d%21184&authkey=ackbiiarirejcam",nocase; classtype:trojan-activity; sid:100003494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100003495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100003496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100003497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100003498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0!1667&authkey=an8otd7jzc7xgho",nocase; classtype:trojan-activity; sid:100003499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0%211667&authkey=an8otd7jzc7xgho",nocase; classtype:trojan-activity; sid:100003500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4",nocase; classtype:trojan-activity; sid:100003501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100003502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100003503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw",nocase; classtype:trojan-activity; sid:100003504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0",nocase; classtype:trojan-activity; sid:100003505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a",nocase; classtype:trojan-activity; sid:100003506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4",nocase; classtype:trojan-activity; sid:100003507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo",nocase; classtype:trojan-activity; sid:100003508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=15d9646f4dbf9553&resid=15d9646f4dbf9553%21110&authkey=ag0eg1lha_lwgi0",nocase; classtype:trojan-activity; sid:100003509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100003510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100003511; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100003512; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100003513; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100003514; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100003515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100003516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100003517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve",nocase; classtype:trojan-activity; sid:100003518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w",nocase; classtype:trojan-activity; sid:100003519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100003520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100003521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg",nocase; classtype:trojan-activity; sid:100003522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60",nocase; classtype:trojan-activity; sid:100003523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg",nocase; classtype:trojan-activity; sid:100003524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4",nocase; classtype:trojan-activity; sid:100003525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c",nocase; classtype:trojan-activity; sid:100003526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba!112&authkey=afjxmbcllibdbvo",nocase; classtype:trojan-activity; sid:100003527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba!114&authkey=adecqvkvvvadznc",nocase; classtype:trojan-activity; sid:100003528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba%21112&authkey=afjxmbcllibdbvo",nocase; classtype:trojan-activity; sid:100003529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba%21114&authkey=adecqvkvvvadznc",nocase; classtype:trojan-activity; sid:100003530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=216ef243e34992b8&resid=216ef243e34992b8!330&authkey=apiugomnim7heom",nocase; classtype:trojan-activity; sid:100003531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=216ef243e34992b8&resid=216ef243e34992b8%21330&authkey=apiugomnim7heom",nocase; classtype:trojan-activity; sid:100003532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=23423a594eafc2de&resid=23423a594eafc2de%21130&authkey=aeh1dm0c-5hp44a",nocase; classtype:trojan-activity; sid:100003533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po",nocase; classtype:trojan-activity; sid:100003534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe",nocase; classtype:trojan-activity; sid:100003535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk",nocase; classtype:trojan-activity; sid:100003536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100003537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100003538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu",nocase; classtype:trojan-activity; sid:100003539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k",nocase; classtype:trojan-activity; sid:100003540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo",nocase; classtype:trojan-activity; sid:100003541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga",nocase; classtype:trojan-activity; sid:100003542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b!287&authkey=advpfy_0ry8upmi",nocase; classtype:trojan-activity; sid:100003543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b!288&authkey=aembucxemjjo3bk",nocase; classtype:trojan-activity; sid:100003544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b%21287&authkey=advpfy_0ry8upmi",nocase; classtype:trojan-activity; sid:100003545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b%21288&authkey=aembucxemjjo3bk",nocase; classtype:trojan-activity; sid:100003546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0",nocase; classtype:trojan-activity; sid:100003547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620",nocase; classtype:trojan-activity; sid:100003548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo",nocase; classtype:trojan-activity; sid:100003549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e",nocase; classtype:trojan-activity; sid:100003550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100003551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100003552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4",nocase; classtype:trojan-activity; sid:100003553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w",nocase; classtype:trojan-activity; sid:100003554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100003555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8",nocase; classtype:trojan-activity; sid:100003556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100003557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw",nocase; classtype:trojan-activity; sid:100003558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3004cdd743a543f5&resid=3004cdd743a543f5%21170&authkey=ao8vz-4rkwuiyn8",nocase; classtype:trojan-activity; sid:100003559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100003560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100003561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100003562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100003563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq",nocase; classtype:trojan-activity; sid:100003564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o",nocase; classtype:trojan-activity; sid:100003565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1!223&authkey=aajr842bzum0yg8",nocase; classtype:trojan-activity; sid:100003566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8",nocase; classtype:trojan-activity; sid:100003567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc",nocase; classtype:trojan-activity; sid:100003568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0",nocase; classtype:trojan-activity; sid:100003569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8",nocase; classtype:trojan-activity; sid:100003570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus",nocase; classtype:trojan-activity; sid:100003571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100003572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100003573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100003574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100003575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100003576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100003577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100003578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100003579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk",nocase; classtype:trojan-activity; sid:100003580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4",nocase; classtype:trojan-activity; sid:100003581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4",nocase; classtype:trojan-activity; sid:100003582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge",nocase; classtype:trojan-activity; sid:100003583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs",nocase; classtype:trojan-activity; sid:100003584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3ee68228c34c236d&resid=3ee68228c34c236d%21129&authkey=apll6hu3-xetzxu",nocase; classtype:trojan-activity; sid:100003585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100003586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100003587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100003588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100003589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0",nocase; classtype:trojan-activity; sid:100003590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100003591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100003592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik",nocase; classtype:trojan-activity; sid:100003593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq",nocase; classtype:trojan-activity; sid:100003594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy",nocase; classtype:trojan-activity; sid:100003595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21141&authkey=aazwaw2xjms24o0",nocase; classtype:trojan-activity; sid:100003596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21145&authkey=aaenjqj018fjmc0",nocase; classtype:trojan-activity; sid:100003597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100003598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100003599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y",nocase; classtype:trojan-activity; sid:100003600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100003601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100003602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100003603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100003604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo",nocase; classtype:trojan-activity; sid:100003605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4",nocase; classtype:trojan-activity; sid:100003606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm",nocase; classtype:trojan-activity; sid:100003607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu",nocase; classtype:trojan-activity; sid:100003608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100003609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100003610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc",nocase; classtype:trojan-activity; sid:100003611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y",nocase; classtype:trojan-activity; sid:100003612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8",nocase; classtype:trojan-activity; sid:100003613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0",nocase; classtype:trojan-activity; sid:100003614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc",nocase; classtype:trojan-activity; sid:100003615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs",nocase; classtype:trojan-activity; sid:100003616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts",nocase; classtype:trojan-activity; sid:100003617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc",nocase; classtype:trojan-activity; sid:100003618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg",nocase; classtype:trojan-activity; sid:100003619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y",nocase; classtype:trojan-activity; sid:100003620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday",nocase; classtype:trojan-activity; sid:100003621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0",nocase; classtype:trojan-activity; sid:100003622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas",nocase; classtype:trojan-activity; sid:100003623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve",nocase; classtype:trojan-activity; sid:100003624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy",nocase; classtype:trojan-activity; sid:100003625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14",nocase; classtype:trojan-activity; sid:100003626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i",nocase; classtype:trojan-activity; sid:100003627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa",nocase; classtype:trojan-activity; sid:100003628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu",nocase; classtype:trojan-activity; sid:100003629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c",nocase; classtype:trojan-activity; sid:100003630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy",nocase; classtype:trojan-activity; sid:100003631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q",nocase; classtype:trojan-activity; sid:100003632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm",nocase; classtype:trojan-activity; sid:100003633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4",nocase; classtype:trojan-activity; sid:100003634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho",nocase; classtype:trojan-activity; sid:100003635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18",nocase; classtype:trojan-activity; sid:100003636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q",nocase; classtype:trojan-activity; sid:100003637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm",nocase; classtype:trojan-activity; sid:100003638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na",nocase; classtype:trojan-activity; sid:100003639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk",nocase; classtype:trojan-activity; sid:100003640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe",nocase; classtype:trojan-activity; sid:100003641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi",nocase; classtype:trojan-activity; sid:100003642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc",nocase; classtype:trojan-activity; sid:100003643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc",nocase; classtype:trojan-activity; sid:100003644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100003645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100003646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100003647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100003648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100003649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100003650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100003651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100003652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100003653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100003654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100003655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100003656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4",nocase; classtype:trojan-activity; sid:100003657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu",nocase; classtype:trojan-activity; sid:100003658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi",nocase; classtype:trojan-activity; sid:100003659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8",nocase; classtype:trojan-activity; sid:100003660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8",nocase; classtype:trojan-activity; sid:100003661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100003662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100003663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8",nocase; classtype:trojan-activity; sid:100003664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100003665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100003666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100003667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100003668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g",nocase; classtype:trojan-activity; sid:100003669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum",nocase; classtype:trojan-activity; sid:100003670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi",nocase; classtype:trojan-activity; sid:100003671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy",nocase; classtype:trojan-activity; sid:100003672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o",nocase; classtype:trojan-activity; sid:100003673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa",nocase; classtype:trojan-activity; sid:100003674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100003675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100003676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc",nocase; classtype:trojan-activity; sid:100003677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk",nocase; classtype:trojan-activity; sid:100003678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea",nocase; classtype:trojan-activity; sid:100003679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100003680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100003681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100003682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100003683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100003684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100003685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo",nocase; classtype:trojan-activity; sid:100003686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva",nocase; classtype:trojan-activity; sid:100003687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc",nocase; classtype:trojan-activity; sid:100003688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles",nocase; classtype:trojan-activity; sid:100003689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg",nocase; classtype:trojan-activity; sid:100003690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100003691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100003692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100003693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100003694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw",nocase; classtype:trojan-activity; sid:100003695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8",nocase; classtype:trojan-activity; sid:100003696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq",nocase; classtype:trojan-activity; sid:100003697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug",nocase; classtype:trojan-activity; sid:100003698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua",nocase; classtype:trojan-activity; sid:100003699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe",nocase; classtype:trojan-activity; sid:100003700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i",nocase; classtype:trojan-activity; sid:100003701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa",nocase; classtype:trojan-activity; sid:100003702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe",nocase; classtype:trojan-activity; sid:100003703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m",nocase; classtype:trojan-activity; sid:100003704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi",nocase; classtype:trojan-activity; sid:100003705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21198&authkey=akq4jrbjm6spd9m",nocase; classtype:trojan-activity; sid:100003706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi",nocase; classtype:trojan-activity; sid:100003707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e",nocase; classtype:trojan-activity; sid:100003708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100003709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c",nocase; classtype:trojan-activity; sid:100003710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100003711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c",nocase; classtype:trojan-activity; sid:100003712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk",nocase; classtype:trojan-activity; sid:100003713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4",nocase; classtype:trojan-activity; sid:100003714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo",nocase; classtype:trojan-activity; sid:100003715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100003716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100003717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg",nocase; classtype:trojan-activity; sid:100003718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70",nocase; classtype:trojan-activity; sid:100003719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc",nocase; classtype:trojan-activity; sid:100003720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100003721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100003722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100003723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100003724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw",nocase; classtype:trojan-activity; sid:100003725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq",nocase; classtype:trojan-activity; sid:100003726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm",nocase; classtype:trojan-activity; sid:100003727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100003728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100003729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100003730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100003731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu",nocase; classtype:trojan-activity; sid:100003732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i",nocase; classtype:trojan-activity; sid:100003733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam",nocase; classtype:trojan-activity; sid:100003734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble",nocase; classtype:trojan-activity; sid:100003735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60",nocase; classtype:trojan-activity; sid:100003736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k",nocase; classtype:trojan-activity; sid:100003737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8",nocase; classtype:trojan-activity; sid:100003738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg",nocase; classtype:trojan-activity; sid:100003739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte",nocase; classtype:trojan-activity; sid:100003740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34",nocase; classtype:trojan-activity; sid:100003741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w",nocase; classtype:trojan-activity; sid:100003742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta",nocase; classtype:trojan-activity; sid:100003743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em",nocase; classtype:trojan-activity; sid:100003744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100003745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100003746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100003747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100003748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm",nocase; classtype:trojan-activity; sid:100003749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100003750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100003751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100003752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100003753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100003754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100003755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs",nocase; classtype:trojan-activity; sid:100003756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c",nocase; classtype:trojan-activity; sid:100003757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0",nocase; classtype:trojan-activity; sid:100003758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq",nocase; classtype:trojan-activity; sid:100003759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda",nocase; classtype:trojan-activity; sid:100003760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm",nocase; classtype:trojan-activity; sid:100003761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=855b20b0e8399717&resid=855b20b0e8399717%21110&authkey=afhxx21ztsd7hbm",nocase; classtype:trojan-activity; sid:100003762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk",nocase; classtype:trojan-activity; sid:100003763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4",nocase; classtype:trojan-activity; sid:100003764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c",nocase; classtype:trojan-activity; sid:100003765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100003766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100003767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4",nocase; classtype:trojan-activity; sid:100003768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk",nocase; classtype:trojan-activity; sid:100003769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk",nocase; classtype:trojan-activity; sid:100003770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0",nocase; classtype:trojan-activity; sid:100003771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s",nocase; classtype:trojan-activity; sid:100003772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my",nocase; classtype:trojan-activity; sid:100003773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc",nocase; classtype:trojan-activity; sid:100003774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby",nocase; classtype:trojan-activity; sid:100003775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo",nocase; classtype:trojan-activity; sid:100003776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti",nocase; classtype:trojan-activity; sid:100003777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!112&authkey=af43qpcgl0t2f5o",nocase; classtype:trojan-activity; sid:100003778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8",nocase; classtype:trojan-activity; sid:100003779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o",nocase; classtype:trojan-activity; sid:100003780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8",nocase; classtype:trojan-activity; sid:100003781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m",nocase; classtype:trojan-activity; sid:100003782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w",nocase; classtype:trojan-activity; sid:100003783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100003784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100003785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k",nocase; classtype:trojan-activity; sid:100003786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue",nocase; classtype:trojan-activity; sid:100003787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc",nocase; classtype:trojan-activity; sid:100003788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w",nocase; classtype:trojan-activity; sid:100003789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm",nocase; classtype:trojan-activity; sid:100003790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0",nocase; classtype:trojan-activity; sid:100003791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy",nocase; classtype:trojan-activity; sid:100003792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm",nocase; classtype:trojan-activity; sid:100003793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi",nocase; classtype:trojan-activity; sid:100003794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi",nocase; classtype:trojan-activity; sid:100003795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8",nocase; classtype:trojan-activity; sid:100003796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100003797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100003798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o",nocase; classtype:trojan-activity; sid:100003799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4",nocase; classtype:trojan-activity; sid:100003800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi",nocase; classtype:trojan-activity; sid:100003801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100003802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100003803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo",nocase; classtype:trojan-activity; sid:100003804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq",nocase; classtype:trojan-activity; sid:100003805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi",nocase; classtype:trojan-activity; sid:100003806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs",nocase; classtype:trojan-activity; sid:100003807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw",nocase; classtype:trojan-activity; sid:100003808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o",nocase; classtype:trojan-activity; sid:100003809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs",nocase; classtype:trojan-activity; sid:100003810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw",nocase; classtype:trojan-activity; sid:100003811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu",nocase; classtype:trojan-activity; sid:100003812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21256&authkey=aapnly5qifymcvw",nocase; classtype:trojan-activity; sid:100003813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100003814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100003815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi",nocase; classtype:trojan-activity; sid:100003816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc",nocase; classtype:trojan-activity; sid:100003817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy",nocase; classtype:trojan-activity; sid:100003818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc",nocase; classtype:trojan-activity; sid:100003819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey",nocase; classtype:trojan-activity; sid:100003820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg",nocase; classtype:trojan-activity; sid:100003821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui",nocase; classtype:trojan-activity; sid:100003822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818!129&authkey=aesewk3cf5vbrxw",nocase; classtype:trojan-activity; sid:100003823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818%21129&authkey=aesewk3cf5vbrxw",nocase; classtype:trojan-activity; sid:100003824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk",nocase; classtype:trojan-activity; sid:100003825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5!2423&authkey=aoiqjwenlzfiqe0",nocase; classtype:trojan-activity; sid:100003826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212417&authkey=aa2zjoxjz1c83ns",nocase; classtype:trojan-activity; sid:100003827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212418&authkey=akjeumqon_fyj9c",nocase; classtype:trojan-activity; sid:100003828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212423&authkey=aoiqjwenlzfiqe0",nocase; classtype:trojan-activity; sid:100003829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw",nocase; classtype:trojan-activity; sid:100003830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100003831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100003832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e",nocase; classtype:trojan-activity; sid:100003833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100003834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100003835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u",nocase; classtype:trojan-activity; sid:100003836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm",nocase; classtype:trojan-activity; sid:100003837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy",nocase; classtype:trojan-activity; sid:100003838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc",nocase; classtype:trojan-activity; sid:100003839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy",nocase; classtype:trojan-activity; sid:100003840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84",nocase; classtype:trojan-activity; sid:100003841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo",nocase; classtype:trojan-activity; sid:100003842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw",nocase; classtype:trojan-activity; sid:100003843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww",nocase; classtype:trojan-activity; sid:100003844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy",nocase; classtype:trojan-activity; sid:100003845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w",nocase; classtype:trojan-activity; sid:100003846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq",nocase; classtype:trojan-activity; sid:100003847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100003848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100003849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg",nocase; classtype:trojan-activity; sid:100003850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg",nocase; classtype:trojan-activity; sid:100003851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100003852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100003853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m",nocase; classtype:trojan-activity; sid:100003854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8",nocase; classtype:trojan-activity; sid:100003855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ba02d68febf523dc&resid=ba02d68febf523dc%211431&authkey=afbifi7o9ywbjpm",nocase; classtype:trojan-activity; sid:100003856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1047&authkey=aod6jbxyicq2v4g",nocase; classtype:trojan-activity; sid:100003857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211047&authkey=aod6jbxyicq2v4g",nocase; classtype:trojan-activity; sid:100003858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100003859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100003860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq",nocase; classtype:trojan-activity; sid:100003861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm",nocase; classtype:trojan-activity; sid:100003862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai",nocase; classtype:trojan-activity; sid:100003863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk",nocase; classtype:trojan-activity; sid:100003864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c29fdbf45b3d2671&resid=c29fdbf45b3d2671%21608&authkey=aafwhzmybg1czta",nocase; classtype:trojan-activity; sid:100003865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100003866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100003867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100003868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100003869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100003870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100003871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100003872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100003873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100003874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100003875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100003876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100003877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100003878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100003879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100003880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100003881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100003882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100003883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100003884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100003885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8",nocase; classtype:trojan-activity; sid:100003886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc",nocase; classtype:trojan-activity; sid:100003887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc",nocase; classtype:trojan-activity; sid:100003888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs",nocase; classtype:trojan-activity; sid:100003889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m",nocase; classtype:trojan-activity; sid:100003890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga",nocase; classtype:trojan-activity; sid:100003891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk",nocase; classtype:trojan-activity; sid:100003892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!357&authkey=alw3vqqxz6myrle",nocase; classtype:trojan-activity; sid:100003893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!362&authkey=alycl9izrvfl7oc",nocase; classtype:trojan-activity; sid:100003894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21354&authkey=aa_ukeour7rex1s",nocase; classtype:trojan-activity; sid:100003895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21355&authkey=aajjwf_sm4xdqdk",nocase; classtype:trojan-activity; sid:100003896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21357&authkey=alw3vqqxz6myrle",nocase; classtype:trojan-activity; sid:100003897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21362&authkey=alycl9izrvfl7oc",nocase; classtype:trojan-activity; sid:100003898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg",nocase; classtype:trojan-activity; sid:100003899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100003900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100003901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw",nocase; classtype:trojan-activity; sid:100003902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100003903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100003904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100003905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100003906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100003907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100003908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100003909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100003910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100003911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100003912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0",nocase; classtype:trojan-activity; sid:100003913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d4d413b6e7cf7088&resid=d4d413b6e7cf7088%211271&authkey=akz65bxpgvdxjb8",nocase; classtype:trojan-activity; sid:100003914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100003915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100003916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100003917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100003918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy",nocase; classtype:trojan-activity; sid:100003919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe",nocase; classtype:trojan-activity; sid:100003920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq",nocase; classtype:trojan-activity; sid:100003921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4",nocase; classtype:trojan-activity; sid:100003922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq",nocase; classtype:trojan-activity; sid:100003923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100003924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100003925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100003926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100003927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100003928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100003929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw",nocase; classtype:trojan-activity; sid:100003930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0",nocase; classtype:trojan-activity; sid:100003931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4",nocase; classtype:trojan-activity; sid:100003932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs",nocase; classtype:trojan-activity; sid:100003933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0",nocase; classtype:trojan-activity; sid:100003934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q",nocase; classtype:trojan-activity; sid:100003935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2!107&authkey=af-bicrg1c6vgck",nocase; classtype:trojan-activity; sid:100003936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2%21107&authkey=af-bicrg1c6vgck",nocase; classtype:trojan-activity; sid:100003937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co",nocase; classtype:trojan-activity; sid:100003938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co",nocase; classtype:trojan-activity; sid:100003939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc",nocase; classtype:trojan-activity; sid:100003940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc",nocase; classtype:trojan-activity; sid:100003941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0",nocase; classtype:trojan-activity; sid:100003942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c",nocase; classtype:trojan-activity; sid:100003943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg",nocase; classtype:trojan-activity; sid:100003944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100003945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100003946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq",nocase; classtype:trojan-activity; sid:100003947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke",nocase; classtype:trojan-activity; sid:100003948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom",nocase; classtype:trojan-activity; sid:100003949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da",nocase; classtype:trojan-activity; sid:100003950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100003951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100003952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0",nocase; classtype:trojan-activity; sid:100003953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100003954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100003955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai",nocase; classtype:trojan-activity; sid:100003956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc",nocase; classtype:trojan-activity; sid:100003957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8",nocase; classtype:trojan-activity; sid:100003958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns",nocase; classtype:trojan-activity; sid:100003959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8",nocase; classtype:trojan-activity; sid:100003960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100003961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100003962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100003963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100003964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100003965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100003966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0",nocase; classtype:trojan-activity; sid:100003967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw",nocase; classtype:trojan-activity; sid:100003968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e",nocase; classtype:trojan-activity; sid:100003969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu",nocase; classtype:trojan-activity; sid:100003970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq",nocase; classtype:trojan-activity; sid:100003971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k",nocase; classtype:trojan-activity; sid:100003972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie",nocase; classtype:trojan-activity; sid:100003973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c",nocase; classtype:trojan-activity; sid:100003974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g",nocase; classtype:trojan-activity; sid:100003975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta",nocase; classtype:trojan-activity; sid:100003976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22",nocase; classtype:trojan-activity; sid:100003977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100003978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100003979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100003980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100003981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc",nocase; classtype:trojan-activity; sid:100003982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu",nocase; classtype:trojan-activity; sid:100003983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm",nocase; classtype:trojan-activity; sid:100003984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w",nocase; classtype:trojan-activity; sid:100003985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm",nocase; classtype:trojan-activity; sid:100003986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21848&authkey=ag1_e421v-t5r9w",nocase; classtype:trojan-activity; sid:100003987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw",nocase; classtype:trojan-activity; sid:100003988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100003989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100003990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100003991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100003992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100003993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100003994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg",nocase; classtype:trojan-activity; sid:100003995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100003996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm",nocase; classtype:trojan-activity; sid:100003997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100003998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/77jhk0iw",nocase; classtype:trojan-activity; sid:100003999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/89hkc7wb",nocase; classtype:trojan-activity; sid:100004000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/yqvsvlvq",nocase; classtype:trojan-activity; sid:100004001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pierreconsulting.info",nocase; http_uri; content:"/wp-admin/llc/mwcacs65xienqdp/",nocase; classtype:trojan-activity; sid:100004002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skoda22.jpg",nocase; classtype:trojan-activity; sid:100004003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg",nocase; classtype:trojan-activity; sid:100004004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qjbutterflyevents.co.za",nocase; http_uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/",nocase; classtype:trojan-activity; sid:100004005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll",nocase; classtype:trojan-activity; sid:100004006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe",nocase; classtype:trojan-activity; sid:100004007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe",nocase; classtype:trojan-activity; sid:100004008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe",nocase; classtype:trojan-activity; sid:100004009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe",nocase; classtype:trojan-activity; sid:100004010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar",nocase; classtype:trojan-activity; sid:100004011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/myqseeaccount/one/main/one.htm",nocase; classtype:trojan-activity; sid:100004012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp",nocase; classtype:trojan-activity; sid:100004013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe",nocase; classtype:trojan-activity; sid:100004014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe",nocase; classtype:trojan-activity; sid:100004015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/tennc/webshell/master/other/small_shell.txt",nocase; classtype:trojan-activity; sid:100004016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.yeshen.com",nocase; http_uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe",nocase; classtype:trojan-activity; sid:100004017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sendspace.com",nocase; http_uri; content:"/pro/dl/q05z91",nocase; classtype:trojan-activity; sid:100004018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shribharatvatika.com",nocase; http_uri; content:"/ey4lpx8rx.zip",nocase; classtype:trojan-activity; sid:100004019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sites.google.com",nocase; http_uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0",nocase; classtype:trojan-activity; sid:100004020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt",nocase; classtype:trojan-activity; sid:100004021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt",nocase; classtype:trojan-activity; sid:100004022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt",nocase; classtype:trojan-activity; sid:100004023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt",nocase; classtype:trojan-activity; sid:100004024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt",nocase; classtype:trojan-activity; sid:100004025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt",nocase; classtype:trojan-activity; sid:100004026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt",nocase; classtype:trojan-activity; sid:100004027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg",nocase; classtype:trojan-activity; sid:100004028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt",nocase; classtype:trojan-activity; sid:100004029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt",nocase; classtype:trojan-activity; sid:100004030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technologydistilled.com",nocase; http_uri; content:"/a-nurse-ss8d9/z/",nocase; classtype:trojan-activity; sid:100004031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"users.skynet.be",nocase; http_uri; content:"/crisanar/defis/jek_crackme1.7.zip",nocase; classtype:trojan-activity; sid:100004032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/amowvegfrt9ja/",nocase; classtype:trojan-activity; sid:100004033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/",nocase; classtype:trojan-activity; sid:100004034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vokasi.ub.ac.id",nocase; http_uri; content:"/wuk/kuqyslbgavnwlmcuk0qalhxifzp4mgze8anlcewu1pa8fw4lfex0y/",nocase; classtype:trojan-activity; sid:100004035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100004036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100004037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe",nocase; classtype:trojan-activity; sid:100004038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb%5efr_ouverture.exe",nocase; classtype:trojan-activity; sid:100004039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb^fr_ouverture.exe",nocase; classtype:trojan-activity; sid:100004040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe",nocase; classtype:trojan-activity; sid:100004041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/151_155/tidex_-_short_stuff.exe",nocase; classtype:trojan-activity; sid:100004042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikileaks.org",nocase; http_uri; content:"/syria-files/attach/222/222051_instruction.zip",nocase; classtype:trojan-activity; sid:100004043; rev:1;) diff --git a/urlhaus-filter-suricata-online.rules b/urlhaus-filter-suricata-online.rules index 22c58638..e0e86ae1 100644 --- a/urlhaus-filter-suricata-online.rules +++ b/urlhaus-filter-suricata-online.rules @@ -1,5 +1,5 @@ # Title: Online Malicious URL Suricata Ruleset -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -39,38 +39,38 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.98"; classtype:trojan-activity; sid:100000033; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.10"; classtype:trojan-activity; sid:100000034; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.105"; classtype:trojan-activity; sid:100000035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.109"; classtype:trojan-activity; sid:100000036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.126"; classtype:trojan-activity; sid:100000037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.127"; classtype:trojan-activity; sid:100000038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.130"; classtype:trojan-activity; sid:100000039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.146"; classtype:trojan-activity; sid:100000040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.148"; classtype:trojan-activity; sid:100000041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.15"; classtype:trojan-activity; sid:100000042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.151"; classtype:trojan-activity; sid:100000043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.22"; classtype:trojan-activity; sid:100000044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.32"; classtype:trojan-activity; sid:100000045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.4"; classtype:trojan-activity; sid:100000046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.48"; classtype:trojan-activity; sid:100000047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.54"; classtype:trojan-activity; sid:100000048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.58"; classtype:trojan-activity; sid:100000049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.59"; classtype:trojan-activity; sid:100000050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.6"; classtype:trojan-activity; sid:100000051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.61"; classtype:trojan-activity; sid:100000052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.71"; classtype:trojan-activity; sid:100000053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.83"; classtype:trojan-activity; sid:100000054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.94"; classtype:trojan-activity; sid:100000055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.247.221.141"; classtype:trojan-activity; sid:100000056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.247.221.142"; classtype:trojan-activity; sid:100000057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.250.159.41"; classtype:trojan-activity; sid:100000058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.65.166.225"; classtype:trojan-activity; sid:100000059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.82.104.89"; classtype:trojan-activity; sid:100000060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.12.184.63"; classtype:trojan-activity; sid:100000061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.12.51.122"; classtype:trojan-activity; sid:100000062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.8.77.4"; classtype:trojan-activity; sid:100000063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1008691.com"; classtype:trojan-activity; sid:100000064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.129.251"; classtype:trojan-activity; sid:100000065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.130.121"; classtype:trojan-activity; sid:100000066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.131.47"; classtype:trojan-activity; sid:100000067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.126"; classtype:trojan-activity; sid:100000036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.127"; classtype:trojan-activity; sid:100000037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.130"; classtype:trojan-activity; sid:100000038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.146"; classtype:trojan-activity; sid:100000039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.148"; classtype:trojan-activity; sid:100000040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.15"; classtype:trojan-activity; sid:100000041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.151"; classtype:trojan-activity; sid:100000042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.22"; classtype:trojan-activity; sid:100000043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.32"; classtype:trojan-activity; sid:100000044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.4"; classtype:trojan-activity; sid:100000045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.48"; classtype:trojan-activity; sid:100000046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.54"; classtype:trojan-activity; sid:100000047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.58"; classtype:trojan-activity; sid:100000048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.59"; classtype:trojan-activity; sid:100000049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.6"; classtype:trojan-activity; sid:100000050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.61"; classtype:trojan-activity; sid:100000051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.71"; classtype:trojan-activity; sid:100000052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.83"; classtype:trojan-activity; sid:100000053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.94"; classtype:trojan-activity; sid:100000054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.247.221.141"; classtype:trojan-activity; sid:100000055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.247.221.142"; classtype:trojan-activity; sid:100000056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.250.159.41"; classtype:trojan-activity; sid:100000057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.65.166.225"; classtype:trojan-activity; sid:100000058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.82.104.89"; classtype:trojan-activity; sid:100000059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.12.184.63"; classtype:trojan-activity; sid:100000060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.12.51.122"; classtype:trojan-activity; sid:100000061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.8.77.4"; classtype:trojan-activity; sid:100000062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1008691.com"; classtype:trojan-activity; sid:100000063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.129.251"; classtype:trojan-activity; sid:100000064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.130.121"; classtype:trojan-activity; sid:100000065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.131.99"; classtype:trojan-activity; sid:100000066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.138.150"; classtype:trojan-activity; sid:100000067; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.16.183.179"; classtype:trojan-activity; sid:100000068; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.229.85.127"; classtype:trojan-activity; sid:100000069; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.255.36.154"; classtype:trojan-activity; sid:100000070; rev:1;) @@ -78,402 +78,402 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.218.245"; classtype:trojan-activity; sid:100000072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.76.34"; classtype:trojan-activity; sid:100000073; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.75.157.99"; classtype:trojan-activity; sid:100000074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.130.115.14"; classtype:trojan-activity; sid:100000075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.141.240.139"; classtype:trojan-activity; sid:100000076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.113.99.79"; classtype:trojan-activity; sid:100000077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.136.82.50"; classtype:trojan-activity; sid:100000078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.16.145.25"; classtype:trojan-activity; sid:100000079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.204.168.34"; classtype:trojan-activity; sid:100000080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.217.215.21"; classtype:trojan-activity; sid:100000081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.219.152.228"; classtype:trojan-activity; sid:100000082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.224.200.146"; classtype:trojan-activity; sid:100000083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.224.200.40"; classtype:trojan-activity; sid:100000084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.227.118.129"; classtype:trojan-activity; sid:100000085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.237.21.36"; classtype:trojan-activity; sid:100000086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.238.228.3"; classtype:trojan-activity; sid:100000087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.240.249.121"; classtype:trojan-activity; sid:100000088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.4.117.26"; classtype:trojan-activity; sid:100000089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.47.104.246"; classtype:trojan-activity; sid:100000090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.99.91.200"; classtype:trojan-activity; sid:100000075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.99.94.15"; classtype:trojan-activity; sid:100000076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.130.115.14"; classtype:trojan-activity; sid:100000077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.141.240.139"; classtype:trojan-activity; sid:100000078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.113.99.79"; classtype:trojan-activity; sid:100000079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.136.82.50"; classtype:trojan-activity; sid:100000080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.16.145.25"; classtype:trojan-activity; sid:100000081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.204.168.34"; classtype:trojan-activity; sid:100000082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.217.215.21"; classtype:trojan-activity; sid:100000083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.219.152.228"; classtype:trojan-activity; sid:100000084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.224.200.146"; classtype:trojan-activity; sid:100000085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.224.200.40"; classtype:trojan-activity; sid:100000086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.227.118.129"; classtype:trojan-activity; sid:100000087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.237.21.36"; classtype:trojan-activity; sid:100000088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.238.228.3"; classtype:trojan-activity; sid:100000089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.240.249.121"; classtype:trojan-activity; sid:100000090; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.79.112.254"; classtype:trojan-activity; sid:100000091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.98.170"; classtype:trojan-activity; sid:100000092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.81.37"; classtype:trojan-activity; sid:100000092; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.240.130"; classtype:trojan-activity; sid:100000093; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.241.94"; classtype:trojan-activity; sid:100000094; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.12"; classtype:trojan-activity; sid:100000095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.13"; classtype:trojan-activity; sid:100000096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.14"; classtype:trojan-activity; sid:100000097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.16"; classtype:trojan-activity; sid:100000098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.17"; classtype:trojan-activity; sid:100000099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.27"; classtype:trojan-activity; sid:100000100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.3"; classtype:trojan-activity; sid:100000101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.36"; classtype:trojan-activity; sid:100000102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.46"; classtype:trojan-activity; sid:100000103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.47"; classtype:trojan-activity; sid:100000104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.90"; classtype:trojan-activity; sid:100000105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.95"; classtype:trojan-activity; sid:100000106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.168.44.57"; classtype:trojan-activity; sid:100000107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.184.75.123"; classtype:trojan-activity; sid:100000108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.206.93.94"; classtype:trojan-activity; sid:100000109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.33.52.85"; classtype:trojan-activity; sid:100000110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.61.86.37"; classtype:trojan-activity; sid:100000111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.1.111.91"; classtype:trojan-activity; sid:100000112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.172.178"; classtype:trojan-activity; sid:100000113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.193.155"; classtype:trojan-activity; sid:100000114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.105.33.43"; classtype:trojan-activity; sid:100000115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.104.105"; classtype:trojan-activity; sid:100000116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.141.115"; classtype:trojan-activity; sid:100000117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.249.148"; classtype:trojan-activity; sid:100000118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.219.80"; classtype:trojan-activity; sid:100000119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.23.240"; classtype:trojan-activity; sid:100000120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.24.143"; classtype:trojan-activity; sid:100000121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.61.139"; classtype:trojan-activity; sid:100000122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.197.135"; classtype:trojan-activity; sid:100000123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.33.48"; classtype:trojan-activity; sid:100000124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.181.136.96"; classtype:trojan-activity; sid:100000125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.194.242.170"; classtype:trojan-activity; sid:100000126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.219.185.75"; classtype:trojan-activity; sid:100000127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.220.119.25"; classtype:trojan-activity; sid:100000128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.221.96.202"; classtype:trojan-activity; sid:100000129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.201.37"; classtype:trojan-activity; sid:100000130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.250.48"; classtype:trojan-activity; sid:100000131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.239.155.26"; classtype:trojan-activity; sid:100000132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.249.194.121"; classtype:trojan-activity; sid:100000133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.104.151.108"; classtype:trojan-activity; sid:100000134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.124.90.229"; classtype:trojan-activity; sid:100000135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.233.196.232"; classtype:trojan-activity; sid:100000136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.235.7.228"; classtype:trojan-activity; sid:100000137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.86.85.253"; classtype:trojan-activity; sid:100000138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.102"; classtype:trojan-activity; sid:100000139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.230"; classtype:trojan-activity; sid:100000140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.127.90"; classtype:trojan-activity; sid:100000141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.57.246"; classtype:trojan-activity; sid:100000142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.99.37.97"; classtype:trojan-activity; sid:100000143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.14.58.190"; classtype:trojan-activity; sid:100000144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.182.102.201"; classtype:trojan-activity; sid:100000145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.182.126.118"; classtype:trojan-activity; sid:100000146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.187.229.182"; classtype:trojan-activity; sid:100000147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.124.254"; classtype:trojan-activity; sid:100000148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.175.141"; classtype:trojan-activity; sid:100000149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.251.194"; classtype:trojan-activity; sid:100000150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.251.10.18"; classtype:trojan-activity; sid:100000151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.213.198"; classtype:trojan-activity; sid:100000152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.208.21"; classtype:trojan-activity; sid:100000153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.209.175"; classtype:trojan-activity; sid:100000154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.223.92"; classtype:trojan-activity; sid:100000155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.225.24"; classtype:trojan-activity; sid:100000156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.235.57"; classtype:trojan-activity; sid:100000157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.4.2"; classtype:trojan-activity; sid:100000158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.88.128"; classtype:trojan-activity; sid:100000159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.88.61"; classtype:trojan-activity; sid:100000160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.119.245.114"; classtype:trojan-activity; sid:100000161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.125.67.125"; classtype:trojan-activity; sid:100000162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.86.31"; classtype:trojan-activity; sid:100000163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.172.57.20"; classtype:trojan-activity; sid:100000164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.182.237.107"; classtype:trojan-activity; sid:100000165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.171.111"; classtype:trojan-activity; sid:100000166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.177.85"; classtype:trojan-activity; sid:100000167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.23.84"; classtype:trojan-activity; sid:100000168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.230.136"; classtype:trojan-activity; sid:100000169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.27.9"; classtype:trojan-activity; sid:100000170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.49.223"; classtype:trojan-activity; sid:100000171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.114"; classtype:trojan-activity; sid:100000172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.122"; classtype:trojan-activity; sid:100000173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.141"; classtype:trojan-activity; sid:100000174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.222"; classtype:trojan-activity; sid:100000175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.223"; classtype:trojan-activity; sid:100000176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.226"; classtype:trojan-activity; sid:100000177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.136"; classtype:trojan-activity; sid:100000178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.15"; classtype:trojan-activity; sid:100000179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.200"; classtype:trojan-activity; sid:100000180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.26.243"; classtype:trojan-activity; sid:100000181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.8.81"; classtype:trojan-activity; sid:100000182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.108.184"; classtype:trojan-activity; sid:100000183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.133.222.151"; classtype:trojan-activity; sid:100000184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.124.75"; classtype:trojan-activity; sid:100000185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.233.9"; classtype:trojan-activity; sid:100000186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.210.211"; classtype:trojan-activity; sid:100000187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.96.252"; classtype:trojan-activity; sid:100000188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.187.91.117"; classtype:trojan-activity; sid:100000189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.214.127.42"; classtype:trojan-activity; sid:100000190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.187.19"; classtype:trojan-activity; sid:100000191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.236.77"; classtype:trojan-activity; sid:100000192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.239.126"; classtype:trojan-activity; sid:100000193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.43.27"; classtype:trojan-activity; sid:100000194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.162.148"; classtype:trojan-activity; sid:100000195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.180.95"; classtype:trojan-activity; sid:100000196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.230.168.103"; classtype:trojan-activity; sid:100000197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.232.0.112"; classtype:trojan-activity; sid:100000198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.141.241"; classtype:trojan-activity; sid:100000199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.144.226"; classtype:trojan-activity; sid:100000200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.75.157"; classtype:trojan-activity; sid:100000201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.99.207"; classtype:trojan-activity; sid:100000202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.143.135"; classtype:trojan-activity; sid:100000203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.190.207"; classtype:trojan-activity; sid:100000204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.227.228"; classtype:trojan-activity; sid:100000205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.39.2"; classtype:trojan-activity; sid:100000206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.239.101.146"; classtype:trojan-activity; sid:100000207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.240.216.17"; classtype:trojan-activity; sid:100000208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.12.89"; classtype:trojan-activity; sid:100000209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.8.24"; classtype:trojan-activity; sid:100000210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.126.58"; classtype:trojan-activity; sid:100000211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.162.50"; classtype:trojan-activity; sid:100000212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.100.14"; classtype:trojan-activity; sid:100000213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.16.222"; classtype:trojan-activity; sid:100000214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.191.118"; classtype:trojan-activity; sid:100000215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.214.146"; classtype:trojan-activity; sid:100000216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.240.226"; classtype:trojan-activity; sid:100000217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.82.122"; classtype:trojan-activity; sid:100000218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.148.90"; classtype:trojan-activity; sid:100000219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.63.212"; classtype:trojan-activity; sid:100000220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.109.217"; classtype:trojan-activity; sid:100000221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.118.157"; classtype:trojan-activity; sid:100000222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.102.173"; classtype:trojan-activity; sid:100000223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.218.210"; classtype:trojan-activity; sid:100000224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.128.143"; classtype:trojan-activity; sid:100000225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.221.244"; classtype:trojan-activity; sid:100000226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.6.129"; classtype:trojan-activity; sid:100000227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.8.235"; classtype:trojan-activity; sid:100000228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.120"; classtype:trojan-activity; sid:100000229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.124"; classtype:trojan-activity; sid:100000230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.131"; classtype:trojan-activity; sid:100000231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.132"; classtype:trojan-activity; sid:100000232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.133"; classtype:trojan-activity; sid:100000233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.139"; classtype:trojan-activity; sid:100000234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.143"; classtype:trojan-activity; sid:100000235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.147"; classtype:trojan-activity; sid:100000236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.149"; classtype:trojan-activity; sid:100000237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.158"; classtype:trojan-activity; sid:100000238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.165"; classtype:trojan-activity; sid:100000239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.175"; classtype:trojan-activity; sid:100000240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.177"; classtype:trojan-activity; sid:100000241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.179"; classtype:trojan-activity; sid:100000242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.125.109"; classtype:trojan-activity; sid:100000243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.127.155"; classtype:trojan-activity; sid:100000244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.80.120"; classtype:trojan-activity; sid:100000245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.81.238"; classtype:trojan-activity; sid:100000246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.82.29"; classtype:trojan-activity; sid:100000247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.182"; classtype:trojan-activity; sid:100000248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.85.113"; classtype:trojan-activity; sid:100000249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.87.130"; classtype:trojan-activity; sid:100000250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.88.116"; classtype:trojan-activity; sid:100000251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.91.212"; classtype:trojan-activity; sid:100000252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.119"; classtype:trojan-activity; sid:100000253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.149"; classtype:trojan-activity; sid:100000254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.158"; classtype:trojan-activity; sid:100000255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.159"; classtype:trojan-activity; sid:100000256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.168"; classtype:trojan-activity; sid:100000257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.177"; classtype:trojan-activity; sid:100000258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.200"; classtype:trojan-activity; sid:100000259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.211"; classtype:trojan-activity; sid:100000260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.219"; classtype:trojan-activity; sid:100000261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.230"; classtype:trojan-activity; sid:100000262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.238"; classtype:trojan-activity; sid:100000263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.245"; classtype:trojan-activity; sid:100000264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.247"; classtype:trojan-activity; sid:100000265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.55"; classtype:trojan-activity; sid:100000266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.60"; classtype:trojan-activity; sid:100000267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.90"; classtype:trojan-activity; sid:100000268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.91"; classtype:trojan-activity; sid:100000269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.38"; classtype:trojan-activity; sid:100000270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.45"; classtype:trojan-activity; sid:100000271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.60"; classtype:trojan-activity; sid:100000272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.35.237"; classtype:trojan-activity; sid:100000273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.103"; classtype:trojan-activity; sid:100000274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.118"; classtype:trojan-activity; sid:100000275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.124"; classtype:trojan-activity; sid:100000276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.53"; classtype:trojan-activity; sid:100000277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.61"; classtype:trojan-activity; sid:100000278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.68"; classtype:trojan-activity; sid:100000279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.70"; classtype:trojan-activity; sid:100000280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.73"; classtype:trojan-activity; sid:100000281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.90"; classtype:trojan-activity; sid:100000282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.0.113"; classtype:trojan-activity; sid:100000283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.177.39"; classtype:trojan-activity; sid:100000284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.211.135"; classtype:trojan-activity; sid:100000285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.216.207"; classtype:trojan-activity; sid:100000286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.240.239"; classtype:trojan-activity; sid:100000287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.224.79"; classtype:trojan-activity; sid:100000288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.227.66"; classtype:trojan-activity; sid:100000289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.65.53.175"; classtype:trojan-activity; sid:100000290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.49"; classtype:trojan-activity; sid:100000291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.175.147"; classtype:trojan-activity; sid:100000292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.112"; classtype:trojan-activity; sid:100000293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.226.202"; classtype:trojan-activity; sid:100000294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.215.101"; classtype:trojan-activity; sid:100000295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.146.253"; classtype:trojan-activity; sid:100000296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.224.139"; classtype:trojan-activity; sid:100000297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.93.29.211"; classtype:trojan-activity; sid:100000298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.11.95.254"; classtype:trojan-activity; sid:100000299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.118.249.97"; classtype:trojan-activity; sid:100000300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.122.238.68"; classtype:trojan-activity; sid:100000301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.13.241.32"; classtype:trojan-activity; sid:100000302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.161.58.249"; classtype:trojan-activity; sid:100000303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.161.78.185"; classtype:trojan-activity; sid:100000304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.230.86.107"; classtype:trojan-activity; sid:100000305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.184.245"; classtype:trojan-activity; sid:100000306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.211.131"; classtype:trojan-activity; sid:100000307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.254.169.251"; classtype:trojan-activity; sid:100000308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.128.133"; classtype:trojan-activity; sid:100000309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.149.125"; classtype:trojan-activity; sid:100000310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.154.21"; classtype:trojan-activity; sid:100000311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.180.40"; classtype:trojan-activity; sid:100000312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.191.47"; classtype:trojan-activity; sid:100000313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.61.204.205"; classtype:trojan-activity; sid:100000314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.65.10.139"; classtype:trojan-activity; sid:100000315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.153.5"; classtype:trojan-activity; sid:100000316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.192.87"; classtype:trojan-activity; sid:100000317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.89.43.165"; classtype:trojan-activity; sid:100000318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.199.204.37"; classtype:trojan-activity; sid:100000319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.199.253.235"; classtype:trojan-activity; sid:100000320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.201.201.68"; classtype:trojan-activity; sid:100000321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.224.203.128"; classtype:trojan-activity; sid:100000322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.30.54.64"; classtype:trojan-activity; sid:100000323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.35.254.7"; classtype:trojan-activity; sid:100000324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.79.172.42"; classtype:trojan-activity; sid:100000325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.165.216.112"; classtype:trojan-activity; sid:100000326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.171.204.161"; classtype:trojan-activity; sid:100000327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.42.47.36"; classtype:trojan-activity; sid:100000328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.140.22"; classtype:trojan-activity; sid:100000329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.77.222"; classtype:trojan-activity; sid:100000330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.106.238"; classtype:trojan-activity; sid:100000331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.53.203.161"; classtype:trojan-activity; sid:100000332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.241.214"; classtype:trojan-activity; sid:100000333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.156.203"; classtype:trojan-activity; sid:100000334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.131.242"; classtype:trojan-activity; sid:100000335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.133.96"; classtype:trojan-activity; sid:100000336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.155.202"; classtype:trojan-activity; sid:100000337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.178.168"; classtype:trojan-activity; sid:100000338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.182.146"; classtype:trojan-activity; sid:100000339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.182.151"; classtype:trojan-activity; sid:100000340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.111.76"; classtype:trojan-activity; sid:100000341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.132.140"; classtype:trojan-activity; sid:100000342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.203.197"; classtype:trojan-activity; sid:100000343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.214.205"; classtype:trojan-activity; sid:100000344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.233.160"; classtype:trojan-activity; sid:100000345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.252.120"; classtype:trojan-activity; sid:100000346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.110.120"; classtype:trojan-activity; sid:100000347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.73.3.11"; classtype:trojan-activity; sid:100000348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.75.217.79"; classtype:trojan-activity; sid:100000349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.88.133.148"; classtype:trojan-activity; sid:100000350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.92.174.231"; classtype:trojan-activity; sid:100000351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.97.139.110"; classtype:trojan-activity; sid:100000352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.124.219.2"; classtype:trojan-activity; sid:100000353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.206.164.46"; classtype:trojan-activity; sid:100000354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.211.100.26"; classtype:trojan-activity; sid:100000355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.138"; classtype:trojan-activity; sid:100000356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.5"; classtype:trojan-activity; sid:100000357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.210.52"; classtype:trojan-activity; sid:100000358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.243.40"; classtype:trojan-activity; sid:100000359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.201.205.232"; classtype:trojan-activity; sid:100000360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.251.59.124"; classtype:trojan-activity; sid:100000361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.26.124.173"; classtype:trojan-activity; sid:100000362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.113.146"; classtype:trojan-activity; sid:100000363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.53.15"; classtype:trojan-activity; sid:100000364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.86.105.110"; classtype:trojan-activity; sid:100000365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.101.7.28"; classtype:trojan-activity; sid:100000366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.104.35"; classtype:trojan-activity; sid:100000367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.157.64"; classtype:trojan-activity; sid:100000368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.7.132"; classtype:trojan-activity; sid:100000369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.32.74"; classtype:trojan-activity; sid:100000370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.5.149"; classtype:trojan-activity; sid:100000371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.72.141"; classtype:trojan-activity; sid:100000372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.12.130"; classtype:trojan-activity; sid:100000373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.128.147"; classtype:trojan-activity; sid:100000374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.208.215"; classtype:trojan-activity; sid:100000375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.209.108"; classtype:trojan-activity; sid:100000376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.214.72"; classtype:trojan-activity; sid:100000377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.88.146"; classtype:trojan-activity; sid:100000378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.150"; classtype:trojan-activity; sid:100000379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.6"; classtype:trojan-activity; sid:100000380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.165.213"; classtype:trojan-activity; sid:100000381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.221.162"; classtype:trojan-activity; sid:100000382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.63.194"; classtype:trojan-activity; sid:100000383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.65.93"; classtype:trojan-activity; sid:100000384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.42.125.246"; classtype:trojan-activity; sid:100000385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.43.180.33"; classtype:trojan-activity; sid:100000386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.218.213"; classtype:trojan-activity; sid:100000387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.50.203"; classtype:trojan-activity; sid:100000388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.74.77"; classtype:trojan-activity; sid:100000389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.91.41.135"; classtype:trojan-activity; sid:100000390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.179.164"; classtype:trojan-activity; sid:100000391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.183.235"; classtype:trojan-activity; sid:100000392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.239.217"; classtype:trojan-activity; sid:100000393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.14.143.145"; classtype:trojan-activity; sid:100000394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.147.213.57"; classtype:trojan-activity; sid:100000395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.18.235"; classtype:trojan-activity; sid:100000396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.218.229"; classtype:trojan-activity; sid:100000397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.107.93"; classtype:trojan-activity; sid:100000398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.241.222"; classtype:trojan-activity; sid:100000399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.27.77"; classtype:trojan-activity; sid:100000400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.68.145"; classtype:trojan-activity; sid:100000401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.97.6"; classtype:trojan-activity; sid:100000402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.26.33"; classtype:trojan-activity; sid:100000403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.177.147.38"; classtype:trojan-activity; sid:100000404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.248.123"; classtype:trojan-activity; sid:100000405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.43.1"; classtype:trojan-activity; sid:100000406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.58.163"; classtype:trojan-activity; sid:100000407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.18.38.144"; classtype:trojan-activity; sid:100000408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.106.217"; classtype:trojan-activity; sid:100000409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.119.21"; classtype:trojan-activity; sid:100000410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.182.97.232"; classtype:trojan-activity; sid:100000411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.172.199"; classtype:trojan-activity; sid:100000412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.15.159"; classtype:trojan-activity; sid:100000413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.195.161"; classtype:trojan-activity; sid:100000414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.245.61"; classtype:trojan-activity; sid:100000415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.137.195"; classtype:trojan-activity; sid:100000416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.227.244"; classtype:trojan-activity; sid:100000417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.187.206"; classtype:trojan-activity; sid:100000418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.215.221"; classtype:trojan-activity; sid:100000419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.240.20"; classtype:trojan-activity; sid:100000420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.255.236"; classtype:trojan-activity; sid:100000421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.204.30.144"; classtype:trojan-activity; sid:100000422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.250.129.231"; classtype:trojan-activity; sid:100000423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.105.221"; classtype:trojan-activity; sid:100000424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.131.155"; classtype:trojan-activity; sid:100000425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.46"; classtype:trojan-activity; sid:100000426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.71"; classtype:trojan-activity; sid:100000427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.148.115"; classtype:trojan-activity; sid:100000428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.155.57"; classtype:trojan-activity; sid:100000429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.166.36"; classtype:trojan-activity; sid:100000430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.96.38.150"; classtype:trojan-activity; sid:100000431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.132.113.2"; classtype:trojan-activity; sid:100000432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.15.69.83"; classtype:trojan-activity; sid:100000433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.6"; classtype:trojan-activity; sid:100000434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.7"; classtype:trojan-activity; sid:100000435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.8"; classtype:trojan-activity; sid:100000436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.9"; classtype:trojan-activity; sid:100000437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.207.39.227"; classtype:trojan-activity; sid:100000438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.25.204.189"; classtype:trojan-activity; sid:100000439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.70.108.141"; classtype:trojan-activity; sid:100000440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.0.255.173"; classtype:trojan-activity; sid:100000441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.1.54.62"; classtype:trojan-activity; sid:100000442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.142.222.22"; classtype:trojan-activity; sid:100000443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.150.213.110"; classtype:trojan-activity; sid:100000444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.151.248.134"; classtype:trojan-activity; sid:100000445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.180"; classtype:trojan-activity; sid:100000446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.183"; classtype:trojan-activity; sid:100000447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.185"; classtype:trojan-activity; sid:100000448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.191"; classtype:trojan-activity; sid:100000449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.193"; classtype:trojan-activity; sid:100000450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.201"; classtype:trojan-activity; sid:100000451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.202"; classtype:trojan-activity; sid:100000452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.204"; classtype:trojan-activity; sid:100000453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.208"; classtype:trojan-activity; sid:100000454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.215"; classtype:trojan-activity; sid:100000455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.233"; classtype:trojan-activity; sid:100000456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.235"; classtype:trojan-activity; sid:100000457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.239"; classtype:trojan-activity; sid:100000458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.25"; classtype:trojan-activity; sid:100000459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.250"; classtype:trojan-activity; sid:100000460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.60"; classtype:trojan-activity; sid:100000461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.74"; classtype:trojan-activity; sid:100000462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.99.127"; classtype:trojan-activity; sid:100000463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.66.60"; classtype:trojan-activity; sid:100000464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.93.115"; classtype:trojan-activity; sid:100000465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.57.123.202"; classtype:trojan-activity; sid:100000466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.8.11"; classtype:trojan-activity; sid:100000467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.7.75.99"; classtype:trojan-activity; sid:100000468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.83.79.42"; classtype:trojan-activity; sid:100000469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.172.111"; classtype:trojan-activity; sid:100000470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.14"; classtype:trojan-activity; sid:100000096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.19"; classtype:trojan-activity; sid:100000097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.36"; classtype:trojan-activity; sid:100000098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.48"; classtype:trojan-activity; sid:100000099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.90"; classtype:trojan-activity; sid:100000100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.95"; classtype:trojan-activity; sid:100000101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.97.184.180"; classtype:trojan-activity; sid:100000102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.184.75.123"; classtype:trojan-activity; sid:100000103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.206.93.94"; classtype:trojan-activity; sid:100000104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.33.52.85"; classtype:trojan-activity; sid:100000105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.61.86.37"; classtype:trojan-activity; sid:100000106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.1.111.91"; classtype:trojan-activity; sid:100000107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.172.178"; classtype:trojan-activity; sid:100000108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.193.155"; classtype:trojan-activity; sid:100000109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.105.33.43"; classtype:trojan-activity; sid:100000110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.104.105"; classtype:trojan-activity; sid:100000111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.141.115"; classtype:trojan-activity; sid:100000112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.156.3"; classtype:trojan-activity; sid:100000113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.249.148"; classtype:trojan-activity; sid:100000114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.219.80"; classtype:trojan-activity; sid:100000115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.23.240"; classtype:trojan-activity; sid:100000116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.24.143"; classtype:trojan-activity; sid:100000117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.61.139"; classtype:trojan-activity; sid:100000118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.197.135"; classtype:trojan-activity; sid:100000119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.33.48"; classtype:trojan-activity; sid:100000120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.181.136.96"; classtype:trojan-activity; sid:100000121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.194.242.170"; classtype:trojan-activity; sid:100000122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.219.185.75"; classtype:trojan-activity; sid:100000123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.220.119.25"; classtype:trojan-activity; sid:100000124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.221.96.202"; classtype:trojan-activity; sid:100000125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.201.37"; classtype:trojan-activity; sid:100000126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.250.48"; classtype:trojan-activity; sid:100000127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.239.155.26"; classtype:trojan-activity; sid:100000128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.249.194.121"; classtype:trojan-activity; sid:100000129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.124.90.229"; classtype:trojan-activity; sid:100000130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.233.196.232"; classtype:trojan-activity; sid:100000131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.235.7.228"; classtype:trojan-activity; sid:100000132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.248.58.238"; classtype:trojan-activity; sid:100000133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.86.85.253"; classtype:trojan-activity; sid:100000134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.102"; classtype:trojan-activity; sid:100000135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.230"; classtype:trojan-activity; sid:100000136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.127.90"; classtype:trojan-activity; sid:100000137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.57.246"; classtype:trojan-activity; sid:100000138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.99.37.97"; classtype:trojan-activity; sid:100000139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.14.58.190"; classtype:trojan-activity; sid:100000140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.182.102.201"; classtype:trojan-activity; sid:100000141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.182.126.118"; classtype:trojan-activity; sid:100000142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.187.229.182"; classtype:trojan-activity; sid:100000143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.124.254"; classtype:trojan-activity; sid:100000144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.175.141"; classtype:trojan-activity; sid:100000145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.251.194"; classtype:trojan-activity; sid:100000146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.251.10.18"; classtype:trojan-activity; sid:100000147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.213.198"; classtype:trojan-activity; sid:100000148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.145.127"; classtype:trojan-activity; sid:100000149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.208.21"; classtype:trojan-activity; sid:100000150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.221.77"; classtype:trojan-activity; sid:100000151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.235.57"; classtype:trojan-activity; sid:100000152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.249.21"; classtype:trojan-activity; sid:100000153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.4.2"; classtype:trojan-activity; sid:100000154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.89.10.147"; classtype:trojan-activity; sid:100000155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.88.61"; classtype:trojan-activity; sid:100000156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.119.245.114"; classtype:trojan-activity; sid:100000157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.125.67.125"; classtype:trojan-activity; sid:100000158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.86.31"; classtype:trojan-activity; sid:100000159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.172.57.20"; classtype:trojan-activity; sid:100000160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.182.237.107"; classtype:trojan-activity; sid:100000161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.171.111"; classtype:trojan-activity; sid:100000162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.177.85"; classtype:trojan-activity; sid:100000163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.23.84"; classtype:trojan-activity; sid:100000164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.230.136"; classtype:trojan-activity; sid:100000165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.27.9"; classtype:trojan-activity; sid:100000166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.49.223"; classtype:trojan-activity; sid:100000167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.114"; classtype:trojan-activity; sid:100000168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.122"; classtype:trojan-activity; sid:100000169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.222"; classtype:trojan-activity; sid:100000170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.226"; classtype:trojan-activity; sid:100000171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.136"; classtype:trojan-activity; sid:100000172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.200"; classtype:trojan-activity; sid:100000173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.26.243"; classtype:trojan-activity; sid:100000174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.8.81"; classtype:trojan-activity; sid:100000175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.108.184"; classtype:trojan-activity; sid:100000176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.133.222.151"; classtype:trojan-activity; sid:100000177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.124.75"; classtype:trojan-activity; sid:100000178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.233.9"; classtype:trojan-activity; sid:100000179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.210.211"; classtype:trojan-activity; sid:100000180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.96.252"; classtype:trojan-activity; sid:100000181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.187.91.117"; classtype:trojan-activity; sid:100000182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.214.127.42"; classtype:trojan-activity; sid:100000183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.187.19"; classtype:trojan-activity; sid:100000184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.236.77"; classtype:trojan-activity; sid:100000185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.239.126"; classtype:trojan-activity; sid:100000186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.43.27"; classtype:trojan-activity; sid:100000187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.162.148"; classtype:trojan-activity; sid:100000188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.180.95"; classtype:trojan-activity; sid:100000189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.230.168.103"; classtype:trojan-activity; sid:100000190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.232.0.112"; classtype:trojan-activity; sid:100000191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.141.241"; classtype:trojan-activity; sid:100000192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.143.135"; classtype:trojan-activity; sid:100000193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.190.207"; classtype:trojan-activity; sid:100000194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.39.2"; classtype:trojan-activity; sid:100000195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.239.101.146"; classtype:trojan-activity; sid:100000196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.240.216.17"; classtype:trojan-activity; sid:100000197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.12.89"; classtype:trojan-activity; sid:100000198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.8.24"; classtype:trojan-activity; sid:100000199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.126.58"; classtype:trojan-activity; sid:100000200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.162.50"; classtype:trojan-activity; sid:100000201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.100.14"; classtype:trojan-activity; sid:100000202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.16.222"; classtype:trojan-activity; sid:100000203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.191.118"; classtype:trojan-activity; sid:100000204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.214.146"; classtype:trojan-activity; sid:100000205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.240.226"; classtype:trojan-activity; sid:100000206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.82.122"; classtype:trojan-activity; sid:100000207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.109.156"; classtype:trojan-activity; sid:100000208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.148.90"; classtype:trojan-activity; sid:100000209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.63.212"; classtype:trojan-activity; sid:100000210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.109.217"; classtype:trojan-activity; sid:100000211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.118.157"; classtype:trojan-activity; sid:100000212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.102.173"; classtype:trojan-activity; sid:100000213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.218.210"; classtype:trojan-activity; sid:100000214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.128.143"; classtype:trojan-activity; sid:100000215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.221.244"; classtype:trojan-activity; sid:100000216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.6.129"; classtype:trojan-activity; sid:100000217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.8.235"; classtype:trojan-activity; sid:100000218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.120"; classtype:trojan-activity; sid:100000219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.124"; classtype:trojan-activity; sid:100000220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.131"; classtype:trojan-activity; sid:100000221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.132"; classtype:trojan-activity; sid:100000222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.133"; classtype:trojan-activity; sid:100000223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.139"; classtype:trojan-activity; sid:100000224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.143"; classtype:trojan-activity; sid:100000225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.147"; classtype:trojan-activity; sid:100000226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.149"; classtype:trojan-activity; sid:100000227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.150"; classtype:trojan-activity; sid:100000228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.158"; classtype:trojan-activity; sid:100000229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.165"; classtype:trojan-activity; sid:100000230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.175"; classtype:trojan-activity; sid:100000231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.177"; classtype:trojan-activity; sid:100000232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.179"; classtype:trojan-activity; sid:100000233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.125.109"; classtype:trojan-activity; sid:100000234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.127.155"; classtype:trojan-activity; sid:100000235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.80.120"; classtype:trojan-activity; sid:100000236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.81.238"; classtype:trojan-activity; sid:100000237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.82.29"; classtype:trojan-activity; sid:100000238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.182"; classtype:trojan-activity; sid:100000239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.85.113"; classtype:trojan-activity; sid:100000240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.87.130"; classtype:trojan-activity; sid:100000241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.88.116"; classtype:trojan-activity; sid:100000242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.91.212"; classtype:trojan-activity; sid:100000243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.119"; classtype:trojan-activity; sid:100000244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.149"; classtype:trojan-activity; sid:100000245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.158"; classtype:trojan-activity; sid:100000246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.159"; classtype:trojan-activity; sid:100000247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.168"; classtype:trojan-activity; sid:100000248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.177"; classtype:trojan-activity; sid:100000249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.200"; classtype:trojan-activity; sid:100000250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.211"; classtype:trojan-activity; sid:100000251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.219"; classtype:trojan-activity; sid:100000252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.230"; classtype:trojan-activity; sid:100000253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.238"; classtype:trojan-activity; sid:100000254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.245"; classtype:trojan-activity; sid:100000255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.247"; classtype:trojan-activity; sid:100000256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.55"; classtype:trojan-activity; sid:100000257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.60"; classtype:trojan-activity; sid:100000258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.90"; classtype:trojan-activity; sid:100000259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.91"; classtype:trojan-activity; sid:100000260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.30"; classtype:trojan-activity; sid:100000261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.38"; classtype:trojan-activity; sid:100000262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.45"; classtype:trojan-activity; sid:100000263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.60"; classtype:trojan-activity; sid:100000264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.35.237"; classtype:trojan-activity; sid:100000265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.118"; classtype:trojan-activity; sid:100000266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.124"; classtype:trojan-activity; sid:100000267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.53"; classtype:trojan-activity; sid:100000268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.61"; classtype:trojan-activity; sid:100000269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.68"; classtype:trojan-activity; sid:100000270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.73"; classtype:trojan-activity; sid:100000271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.90"; classtype:trojan-activity; sid:100000272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.0.113"; classtype:trojan-activity; sid:100000273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.177.39"; classtype:trojan-activity; sid:100000274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.216.207"; classtype:trojan-activity; sid:100000275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.224.79"; classtype:trojan-activity; sid:100000276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.227.66"; classtype:trojan-activity; sid:100000277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.65.53.175"; classtype:trojan-activity; sid:100000278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.159"; classtype:trojan-activity; sid:100000279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.49"; classtype:trojan-activity; sid:100000280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.175.147"; classtype:trojan-activity; sid:100000281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.112"; classtype:trojan-activity; sid:100000282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.84"; classtype:trojan-activity; sid:100000283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.226.202"; classtype:trojan-activity; sid:100000284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.215.101"; classtype:trojan-activity; sid:100000285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.146.253"; classtype:trojan-activity; sid:100000286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.224.139"; classtype:trojan-activity; sid:100000287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.9.155.122"; classtype:trojan-activity; sid:100000288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.93.29.211"; classtype:trojan-activity; sid:100000289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.11.95.254"; classtype:trojan-activity; sid:100000290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.118.249.97"; classtype:trojan-activity; sid:100000291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.122.238.68"; classtype:trojan-activity; sid:100000292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.13.241.32"; classtype:trojan-activity; sid:100000293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.161.58.249"; classtype:trojan-activity; sid:100000294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.161.78.185"; classtype:trojan-activity; sid:100000295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.194.131.72"; classtype:trojan-activity; sid:100000296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.194.135.223"; classtype:trojan-activity; sid:100000297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.226.42.250"; classtype:trojan-activity; sid:100000298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.230.86.107"; classtype:trojan-activity; sid:100000299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.184.245"; classtype:trojan-activity; sid:100000300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.211.131"; classtype:trojan-activity; sid:100000301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.254.169.251"; classtype:trojan-activity; sid:100000302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.128.133"; classtype:trojan-activity; sid:100000303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.136.39"; classtype:trojan-activity; sid:100000304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.144.42"; classtype:trojan-activity; sid:100000305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.149.125"; classtype:trojan-activity; sid:100000306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.191.47"; classtype:trojan-activity; sid:100000307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.61.204.205"; classtype:trojan-activity; sid:100000308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.65.10.139"; classtype:trojan-activity; sid:100000309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.123.22"; classtype:trojan-activity; sid:100000310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.228.152"; classtype:trojan-activity; sid:100000311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.89.43.165"; classtype:trojan-activity; sid:100000312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.199.253.235"; classtype:trojan-activity; sid:100000313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.201.201.68"; classtype:trojan-activity; sid:100000314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.224.203.128"; classtype:trojan-activity; sid:100000315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.30.54.64"; classtype:trojan-activity; sid:100000316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.79.172.42"; classtype:trojan-activity; sid:100000317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.165.216.112"; classtype:trojan-activity; sid:100000318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.171.204.161"; classtype:trojan-activity; sid:100000319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.42.47.36"; classtype:trojan-activity; sid:100000320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.232.197"; classtype:trojan-activity; sid:100000321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.172.22"; classtype:trojan-activity; sid:100000322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.2.148"; classtype:trojan-activity; sid:100000323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.106.238"; classtype:trojan-activity; sid:100000324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.91.81"; classtype:trojan-activity; sid:100000325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.53.203.161"; classtype:trojan-activity; sid:100000326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.212.175"; classtype:trojan-activity; sid:100000327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.156.203"; classtype:trojan-activity; sid:100000328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.7.9"; classtype:trojan-activity; sid:100000329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.131.242"; classtype:trojan-activity; sid:100000330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.133.96"; classtype:trojan-activity; sid:100000331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.155.202"; classtype:trojan-activity; sid:100000332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.214.205"; classtype:trojan-activity; sid:100000333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.233.160"; classtype:trojan-activity; sid:100000334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.252.120"; classtype:trojan-activity; sid:100000335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.110.120"; classtype:trojan-activity; sid:100000336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.167.21"; classtype:trojan-activity; sid:100000337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.172.140"; classtype:trojan-activity; sid:100000338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.26.113"; classtype:trojan-activity; sid:100000339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.73.3.11"; classtype:trojan-activity; sid:100000340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.75.217.79"; classtype:trojan-activity; sid:100000341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.88.133.148"; classtype:trojan-activity; sid:100000342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.92.174.231"; classtype:trojan-activity; sid:100000343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.108.92.154"; classtype:trojan-activity; sid:100000344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.124.219.2"; classtype:trojan-activity; sid:100000345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.206.164.46"; classtype:trojan-activity; sid:100000346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.211.100.26"; classtype:trojan-activity; sid:100000347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.162.12"; classtype:trojan-activity; sid:100000348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.138"; classtype:trojan-activity; sid:100000349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.5"; classtype:trojan-activity; sid:100000350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.210.52"; classtype:trojan-activity; sid:100000351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.220.126"; classtype:trojan-activity; sid:100000352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.243.40"; classtype:trojan-activity; sid:100000353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.201.205.232"; classtype:trojan-activity; sid:100000354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.64.149"; classtype:trojan-activity; sid:100000355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.12.177"; classtype:trojan-activity; sid:100000356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.47.94"; classtype:trojan-activity; sid:100000357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.9.42"; classtype:trojan-activity; sid:100000358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.215.249.250"; classtype:trojan-activity; sid:100000359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.173.91"; classtype:trojan-activity; sid:100000360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.175.134"; classtype:trojan-activity; sid:100000361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.242.208.197"; classtype:trojan-activity; sid:100000362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.247.201.45"; classtype:trojan-activity; sid:100000363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.26.124.173"; classtype:trojan-activity; sid:100000364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.113.146"; classtype:trojan-activity; sid:100000365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.133.251"; classtype:trojan-activity; sid:100000366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.53.15"; classtype:trojan-activity; sid:100000367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.86.105.110"; classtype:trojan-activity; sid:100000368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.101.7.28"; classtype:trojan-activity; sid:100000369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.104.35"; classtype:trojan-activity; sid:100000370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.157.64"; classtype:trojan-activity; sid:100000371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.7.132"; classtype:trojan-activity; sid:100000372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.32.74"; classtype:trojan-activity; sid:100000373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.5.149"; classtype:trojan-activity; sid:100000374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.72.141"; classtype:trojan-activity; sid:100000375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.12.130"; classtype:trojan-activity; sid:100000376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.128.147"; classtype:trojan-activity; sid:100000377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.208.215"; classtype:trojan-activity; sid:100000378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.209.108"; classtype:trojan-activity; sid:100000379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.214.72"; classtype:trojan-activity; sid:100000380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.88.146"; classtype:trojan-activity; sid:100000381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.150"; classtype:trojan-activity; sid:100000382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.6"; classtype:trojan-activity; sid:100000383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.165.213"; classtype:trojan-activity; sid:100000384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.221.162"; classtype:trojan-activity; sid:100000385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.63.194"; classtype:trojan-activity; sid:100000386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.65.93"; classtype:trojan-activity; sid:100000387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.42.125.246"; classtype:trojan-activity; sid:100000388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.43.180.33"; classtype:trojan-activity; sid:100000389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.113.239"; classtype:trojan-activity; sid:100000390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.218.213"; classtype:trojan-activity; sid:100000391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.50.203"; classtype:trojan-activity; sid:100000392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.179.164"; classtype:trojan-activity; sid:100000393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.183.235"; classtype:trojan-activity; sid:100000394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.239.217"; classtype:trojan-activity; sid:100000395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.14.143.145"; classtype:trojan-activity; sid:100000396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.147.213.57"; classtype:trojan-activity; sid:100000397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.18.235"; classtype:trojan-activity; sid:100000398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.218.229"; classtype:trojan-activity; sid:100000399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.107.93"; classtype:trojan-activity; sid:100000400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.241.222"; classtype:trojan-activity; sid:100000401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.27.77"; classtype:trojan-activity; sid:100000402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.68.145"; classtype:trojan-activity; sid:100000403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.97.6"; classtype:trojan-activity; sid:100000404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.26.33"; classtype:trojan-activity; sid:100000405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.177.147.38"; classtype:trojan-activity; sid:100000406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.248.123"; classtype:trojan-activity; sid:100000407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.43.1"; classtype:trojan-activity; sid:100000408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.58.163"; classtype:trojan-activity; sid:100000409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.18.38.144"; classtype:trojan-activity; sid:100000410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.18.88.78"; classtype:trojan-activity; sid:100000411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.106.217"; classtype:trojan-activity; sid:100000412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.119.21"; classtype:trojan-activity; sid:100000413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.182.97.232"; classtype:trojan-activity; sid:100000414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.172.199"; classtype:trojan-activity; sid:100000415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.15.159"; classtype:trojan-activity; sid:100000416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.195.161"; classtype:trojan-activity; sid:100000417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.245.61"; classtype:trojan-activity; sid:100000418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.137.195"; classtype:trojan-activity; sid:100000419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.227.244"; classtype:trojan-activity; sid:100000420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.187.206"; classtype:trojan-activity; sid:100000421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.215.221"; classtype:trojan-activity; sid:100000422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.240.20"; classtype:trojan-activity; sid:100000423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.255.236"; classtype:trojan-activity; sid:100000424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.204.30.144"; classtype:trojan-activity; sid:100000425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.250.129.231"; classtype:trojan-activity; sid:100000426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.131.155"; classtype:trojan-activity; sid:100000427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.46"; classtype:trojan-activity; sid:100000428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.71"; classtype:trojan-activity; sid:100000429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.148.115"; classtype:trojan-activity; sid:100000430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.155.57"; classtype:trojan-activity; sid:100000431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.206.43"; classtype:trojan-activity; sid:100000432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.96.38.150"; classtype:trojan-activity; sid:100000433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.52.69"; classtype:trojan-activity; sid:100000434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.132.113.2"; classtype:trojan-activity; sid:100000435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.15.69.83"; classtype:trojan-activity; sid:100000436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.6"; classtype:trojan-activity; sid:100000437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.7"; classtype:trojan-activity; sid:100000438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.8"; classtype:trojan-activity; sid:100000439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.9"; classtype:trojan-activity; sid:100000440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.207.39.227"; classtype:trojan-activity; sid:100000441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.25.204.189"; classtype:trojan-activity; sid:100000442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.70.108.141"; classtype:trojan-activity; sid:100000443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.0.255.173"; classtype:trojan-activity; sid:100000444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.1.54.62"; classtype:trojan-activity; sid:100000445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.142.222.22"; classtype:trojan-activity; sid:100000446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.150.213.110"; classtype:trojan-activity; sid:100000447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.151.248.134"; classtype:trojan-activity; sid:100000448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.180"; classtype:trojan-activity; sid:100000449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.183"; classtype:trojan-activity; sid:100000450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.185"; classtype:trojan-activity; sid:100000451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.191"; classtype:trojan-activity; sid:100000452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.193"; classtype:trojan-activity; sid:100000453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.201"; classtype:trojan-activity; sid:100000454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.202"; classtype:trojan-activity; sid:100000455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.204"; classtype:trojan-activity; sid:100000456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.215"; classtype:trojan-activity; sid:100000457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.233"; classtype:trojan-activity; sid:100000458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.206"; classtype:trojan-activity; sid:100000459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.235"; classtype:trojan-activity; sid:100000460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.239"; classtype:trojan-activity; sid:100000461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.250"; classtype:trojan-activity; sid:100000462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.60"; classtype:trojan-activity; sid:100000463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.74"; classtype:trojan-activity; sid:100000464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.99.127"; classtype:trojan-activity; sid:100000465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.66.60"; classtype:trojan-activity; sid:100000466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.93.115"; classtype:trojan-activity; sid:100000467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.8.11"; classtype:trojan-activity; sid:100000468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.7.75.99"; classtype:trojan-activity; sid:100000469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.83.79.42"; classtype:trojan-activity; sid:100000470; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.114.164"; classtype:trojan-activity; sid:100000471; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.96.8"; classtype:trojan-activity; sid:100000472; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.121.44.222"; classtype:trojan-activity; sid:100000473; rev:1;) @@ -494,26 +494,26 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.254.76.17"; classtype:trojan-activity; sid:100000488; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.96.158"; classtype:trojan-activity; sid:100000489; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.97.64"; classtype:trojan-activity; sid:100000490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.88.99.236"; classtype:trojan-activity; sid:100000491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.100.150.204"; classtype:trojan-activity; sid:100000492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.137.53.134"; classtype:trojan-activity; sid:100000493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.160.147.53"; classtype:trojan-activity; sid:100000494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.66.28"; classtype:trojan-activity; sid:100000495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.72.23"; classtype:trojan-activity; sid:100000496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.79.27"; classtype:trojan-activity; sid:100000497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.37.85"; classtype:trojan-activity; sid:100000498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.232.227.128"; classtype:trojan-activity; sid:100000499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.33.214"; classtype:trojan-activity; sid:100000500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.0.240.58"; classtype:trojan-activity; sid:100000501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.137.193"; classtype:trojan-activity; sid:100000502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.202.178"; classtype:trojan-activity; sid:100000503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.244"; classtype:trojan-activity; sid:100000504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.170.237"; classtype:trojan-activity; sid:100000505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.182.187"; classtype:trojan-activity; sid:100000506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.19.248"; classtype:trojan-activity; sid:100000507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.200.98"; classtype:trojan-activity; sid:100000508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.238.188"; classtype:trojan-activity; sid:100000509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.12.164.165"; classtype:trojan-activity; sid:100000510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.8.107.214"; classtype:trojan-activity; sid:100000491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.88.99.236"; classtype:trojan-activity; sid:100000492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.100.150.204"; classtype:trojan-activity; sid:100000493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.137.53.134"; classtype:trojan-activity; sid:100000494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.160.147.53"; classtype:trojan-activity; sid:100000495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.66.28"; classtype:trojan-activity; sid:100000496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.72.23"; classtype:trojan-activity; sid:100000497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.79.27"; classtype:trojan-activity; sid:100000498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.37.85"; classtype:trojan-activity; sid:100000499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.232.227.128"; classtype:trojan-activity; sid:100000500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.33.214"; classtype:trojan-activity; sid:100000501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.0.240.58"; classtype:trojan-activity; sid:100000502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.32.252"; classtype:trojan-activity; sid:100000503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.202.178"; classtype:trojan-activity; sid:100000504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.244"; classtype:trojan-activity; sid:100000505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.170.237"; classtype:trojan-activity; sid:100000506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.182.187"; classtype:trojan-activity; sid:100000507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.19.248"; classtype:trojan-activity; sid:100000508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.200.98"; classtype:trojan-activity; sid:100000509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.238.188"; classtype:trojan-activity; sid:100000510; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.129.2.28"; classtype:trojan-activity; sid:100000511; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.129.84.36"; classtype:trojan-activity; sid:100000512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.208.52"; classtype:trojan-activity; sid:100000513; rev:1;) @@ -527,192 +527,192 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.14.130"; classtype:trojan-activity; sid:100000521; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.20.164"; classtype:trojan-activity; sid:100000522; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.246.180"; classtype:trojan-activity; sid:100000523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.236.114"; classtype:trojan-activity; sid:100000524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.8.100"; classtype:trojan-activity; sid:100000525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.183.16.71"; classtype:trojan-activity; sid:100000526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.191.164.92"; classtype:trojan-activity; sid:100000527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.101.163"; classtype:trojan-activity; sid:100000528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.53.237"; classtype:trojan-activity; sid:100000529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.235.37"; classtype:trojan-activity; sid:100000530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.35.146"; classtype:trojan-activity; sid:100000531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.52.79"; classtype:trojan-activity; sid:100000532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.60.238"; classtype:trojan-activity; sid:100000533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.112.240"; classtype:trojan-activity; sid:100000534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.184.191"; classtype:trojan-activity; sid:100000535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.212.29.154"; classtype:trojan-activity; sid:100000536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.213.225.130"; classtype:trojan-activity; sid:100000537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.130.162"; classtype:trojan-activity; sid:100000538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.152.249"; classtype:trojan-activity; sid:100000539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.116.110"; classtype:trojan-activity; sid:100000540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.184.57"; classtype:trojan-activity; sid:100000541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.103.89"; classtype:trojan-activity; sid:100000542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.181.57"; classtype:trojan-activity; sid:100000543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.79.61"; classtype:trojan-activity; sid:100000544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.11.41"; classtype:trojan-activity; sid:100000545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.148.58"; classtype:trojan-activity; sid:100000546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.184.124"; classtype:trojan-activity; sid:100000547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.28.217.23"; classtype:trojan-activity; sid:100000548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.204.223"; classtype:trojan-activity; sid:100000549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.251.81"; classtype:trojan-activity; sid:100000550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.250.132"; classtype:trojan-activity; sid:100000551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.9.193.253"; classtype:trojan-activity; sid:100000552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.9.85.25"; classtype:trojan-activity; sid:100000553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.221.150"; classtype:trojan-activity; sid:100000554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.76.230"; classtype:trojan-activity; sid:100000555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.130.40.31"; classtype:trojan-activity; sid:100000556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.104.82"; classtype:trojan-activity; sid:100000557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.131.105"; classtype:trojan-activity; sid:100000558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.151.135"; classtype:trojan-activity; sid:100000559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.24.185"; classtype:trojan-activity; sid:100000560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.26.243"; classtype:trojan-activity; sid:100000561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.42.98"; classtype:trojan-activity; sid:100000562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.54.33"; classtype:trojan-activity; sid:100000563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.132.110.150"; classtype:trojan-activity; sid:100000564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.135.34.49"; classtype:trojan-activity; sid:100000565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.136.175"; classtype:trojan-activity; sid:100000566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.236.6"; classtype:trojan-activity; sid:100000567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.160.126.238"; classtype:trojan-activity; sid:100000568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.65.64"; classtype:trojan-activity; sid:100000569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.165.123.7"; classtype:trojan-activity; sid:100000570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.187.111.160"; classtype:trojan-activity; sid:100000571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.199.56.198"; classtype:trojan-activity; sid:100000572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.230.174.233"; classtype:trojan-activity; sid:100000573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.254.210.69"; classtype:trojan-activity; sid:100000574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.5.112.43"; classtype:trojan-activity; sid:100000575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.5.92.20"; classtype:trojan-activity; sid:100000576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.6.0.4"; classtype:trojan-activity; sid:100000577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.67.89.28"; classtype:trojan-activity; sid:100000578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.80.46.73"; classtype:trojan-activity; sid:100000579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.93.94.207"; classtype:trojan-activity; sid:100000580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.95.10.235"; classtype:trojan-activity; sid:100000581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.128.28.161"; classtype:trojan-activity; sid:100000582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.142.93.34"; classtype:trojan-activity; sid:100000583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.191.113.212"; classtype:trojan-activity; sid:100000584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.36.222.249"; classtype:trojan-activity; sid:100000585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.1.235"; classtype:trojan-activity; sid:100000586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.146.46"; classtype:trojan-activity; sid:100000587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.3.71"; classtype:trojan-activity; sid:100000588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.82.59"; classtype:trojan-activity; sid:100000589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.8.154"; classtype:trojan-activity; sid:100000590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.186.88"; classtype:trojan-activity; sid:100000591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.66.253"; classtype:trojan-activity; sid:100000592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.244.8"; classtype:trojan-activity; sid:100000593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.74.230"; classtype:trojan-activity; sid:100000594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.93.160"; classtype:trojan-activity; sid:100000595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.95.26"; classtype:trojan-activity; sid:100000524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.236.114"; classtype:trojan-activity; sid:100000525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.8.100"; classtype:trojan-activity; sid:100000526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.183.16.71"; classtype:trojan-activity; sid:100000527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.191.164.92"; classtype:trojan-activity; sid:100000528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.101.163"; classtype:trojan-activity; sid:100000529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.53.237"; classtype:trojan-activity; sid:100000530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.235.37"; classtype:trojan-activity; sid:100000531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.35.146"; classtype:trojan-activity; sid:100000532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.52.79"; classtype:trojan-activity; sid:100000533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.60.238"; classtype:trojan-activity; sid:100000534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.112.240"; classtype:trojan-activity; sid:100000535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.184.191"; classtype:trojan-activity; sid:100000536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.212.29.154"; classtype:trojan-activity; sid:100000537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.213.225.130"; classtype:trojan-activity; sid:100000538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.130.162"; classtype:trojan-activity; sid:100000539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.152.249"; classtype:trojan-activity; sid:100000540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.116.110"; classtype:trojan-activity; sid:100000541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.184.57"; classtype:trojan-activity; sid:100000542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.103.89"; classtype:trojan-activity; sid:100000543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.181.57"; classtype:trojan-activity; sid:100000544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.79.61"; classtype:trojan-activity; sid:100000545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.11.41"; classtype:trojan-activity; sid:100000546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.148.58"; classtype:trojan-activity; sid:100000547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.184.124"; classtype:trojan-activity; sid:100000548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.28.217.23"; classtype:trojan-activity; sid:100000549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.242.19"; classtype:trojan-activity; sid:100000550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.47.57"; classtype:trojan-activity; sid:100000551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.148.182"; classtype:trojan-activity; sid:100000552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.189.15"; classtype:trojan-activity; sid:100000553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.9.36.120"; classtype:trojan-activity; sid:100000554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.221.150"; classtype:trojan-activity; sid:100000555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.76.230"; classtype:trojan-activity; sid:100000556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.130.40.31"; classtype:trojan-activity; sid:100000557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.104.82"; classtype:trojan-activity; sid:100000558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.131.105"; classtype:trojan-activity; sid:100000559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.151.135"; classtype:trojan-activity; sid:100000560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.24.185"; classtype:trojan-activity; sid:100000561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.26.243"; classtype:trojan-activity; sid:100000562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.42.98"; classtype:trojan-activity; sid:100000563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.54.33"; classtype:trojan-activity; sid:100000564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.132.110.150"; classtype:trojan-activity; sid:100000565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.135.34.49"; classtype:trojan-activity; sid:100000566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.136.175"; classtype:trojan-activity; sid:100000567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.236.6"; classtype:trojan-activity; sid:100000568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.160.126.238"; classtype:trojan-activity; sid:100000569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.65.64"; classtype:trojan-activity; sid:100000570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.165.123.7"; classtype:trojan-activity; sid:100000571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.187.111.160"; classtype:trojan-activity; sid:100000572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.199.56.198"; classtype:trojan-activity; sid:100000573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.230.174.233"; classtype:trojan-activity; sid:100000574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.254.210.69"; classtype:trojan-activity; sid:100000575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.5.112.43"; classtype:trojan-activity; sid:100000576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.5.92.20"; classtype:trojan-activity; sid:100000577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.6.0.4"; classtype:trojan-activity; sid:100000578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.67.89.28"; classtype:trojan-activity; sid:100000579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.80.46.73"; classtype:trojan-activity; sid:100000580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.93.94.207"; classtype:trojan-activity; sid:100000581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.95.10.235"; classtype:trojan-activity; sid:100000582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.128.28.161"; classtype:trojan-activity; sid:100000583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.142.93.34"; classtype:trojan-activity; sid:100000584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.191.113.212"; classtype:trojan-activity; sid:100000585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.36.222.249"; classtype:trojan-activity; sid:100000586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.1.235"; classtype:trojan-activity; sid:100000587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.146.46"; classtype:trojan-activity; sid:100000588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.3.71"; classtype:trojan-activity; sid:100000589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.14.228"; classtype:trojan-activity; sid:100000590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.82.59"; classtype:trojan-activity; sid:100000591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.186.88"; classtype:trojan-activity; sid:100000592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.66.253"; classtype:trojan-activity; sid:100000593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.244.126"; classtype:trojan-activity; sid:100000594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.74.230"; classtype:trojan-activity; sid:100000595; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"126.39.155.210"; classtype:trojan-activity; sid:100000596; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"128.116.133.92"; classtype:trojan-activity; sid:100000597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"13.114.247.134"; classtype:trojan-activity; sid:100000598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"130.255.159.133"; classtype:trojan-activity; sid:100000599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"134.119.186.214"; classtype:trojan-activity; sid:100000600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"135.148.36.127"; classtype:trojan-activity; sid:100000601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"138.99.204.224"; classtype:trojan-activity; sid:100000602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.159.226.180"; classtype:trojan-activity; sid:100000603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.173.198"; classtype:trojan-activity; sid:100000604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.216.102.151"; classtype:trojan-activity; sid:100000605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.102.17.222"; classtype:trojan-activity; sid:100000606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.136.80.242"; classtype:trojan-activity; sid:100000607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.215"; classtype:trojan-activity; sid:100000608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.51"; classtype:trojan-activity; sid:100000609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.155.86.253"; classtype:trojan-activity; sid:100000610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.160.34.50"; classtype:trojan-activity; sid:100000611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.232.33.212"; classtype:trojan-activity; sid:100000612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.37.222.190"; classtype:trojan-activity; sid:100000613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.42.237.237"; classtype:trojan-activity; sid:100000614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.45.127.110"; classtype:trojan-activity; sid:100000615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.25.17"; classtype:trojan-activity; sid:100000616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.50.129.248"; classtype:trojan-activity; sid:100000617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.55.29.2"; classtype:trojan-activity; sid:100000618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"140.237.12.32"; classtype:trojan-activity; sid:100000619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.11.216.5"; classtype:trojan-activity; sid:100000620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.177.56.127"; classtype:trojan-activity; sid:100000621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"148.69.108.177"; classtype:trojan-activity; sid:100000622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.134"; classtype:trojan-activity; sid:100000623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.99"; classtype:trojan-activity; sid:100000624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.124.194"; classtype:trojan-activity; sid:100000625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14karatvisions.com"; classtype:trojan-activity; sid:100000626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"150.116.207.99"; classtype:trojan-activity; sid:100000627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.177.163.87"; classtype:trojan-activity; sid:100000628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.33.230.191"; classtype:trojan-activity; sid:100000629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.234.167"; classtype:trojan-activity; sid:100000630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.152.106"; classtype:trojan-activity; sid:100000631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.135.92"; classtype:trojan-activity; sid:100000632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.159.207"; classtype:trojan-activity; sid:100000633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"156.234.211.198"; classtype:trojan-activity; sid:100000634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.101.165.14"; classtype:trojan-activity; sid:100000635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.174.213.128"; classtype:trojan-activity; sid:100000636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.51.125.115"; classtype:trojan-activity; sid:100000637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"159.224.74.112"; classtype:trojan-activity; sid:100000638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"159.65.199.92"; classtype:trojan-activity; sid:100000639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.191.165.238"; classtype:trojan-activity; sid:100000640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.194.28.60"; classtype:trojan-activity; sid:100000641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.209.98.174"; classtype:trojan-activity; sid:100000642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.200.234"; classtype:trojan-activity; sid:100000643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.206.193"; classtype:trojan-activity; sid:100000644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.53.206.228"; classtype:trojan-activity; sid:100000645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"167.114.172.177"; classtype:trojan-activity; sid:100000646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"170.81.238.178"; classtype:trojan-activity; sid:100000647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.121.255.12"; classtype:trojan-activity; sid:100000648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.247.155.56"; classtype:trojan-activity; sid:100000649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.250.131.25"; classtype:trojan-activity; sid:100000650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.162.156"; classtype:trojan-activity; sid:100000651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.150.133"; classtype:trojan-activity; sid:100000652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.105.36.168"; classtype:trojan-activity; sid:100000653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.114.244.127"; classtype:trojan-activity; sid:100000654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.186.107"; classtype:trojan-activity; sid:100000655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.185"; classtype:trojan-activity; sid:100000656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.190"; classtype:trojan-activity; sid:100000657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.81.19"; classtype:trojan-activity; sid:100000658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.93.194.114"; classtype:trojan-activity; sid:100000659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.167.85.89"; classtype:trojan-activity; sid:100000660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.169.46.85"; classtype:trojan-activity; sid:100000661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.19.58.108"; classtype:trojan-activity; sid:100000662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.233.85.171"; classtype:trojan-activity; sid:100000663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.235.209.70"; classtype:trojan-activity; sid:100000664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.25.113.8"; classtype:trojan-activity; sid:100000665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.95.134"; classtype:trojan-activity; sid:100000666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.97.25"; classtype:trojan-activity; sid:100000667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.119.108"; classtype:trojan-activity; sid:100000668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.92.166"; classtype:trojan-activity; sid:100000669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.63.64.213"; classtype:trojan-activity; sid:100000670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.68.100.93"; classtype:trojan-activity; sid:100000671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.61.3.149"; classtype:trojan-activity; sid:100000672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.73.246.193"; classtype:trojan-activity; sid:100000673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.81.78.7"; classtype:trojan-activity; sid:100000674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.83.73.163"; classtype:trojan-activity; sid:100000675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.11.65.112"; classtype:trojan-activity; sid:100000676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.117.66.74"; classtype:trojan-activity; sid:100000677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.169.13.182"; classtype:trojan-activity; sid:100000678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.194.116.27"; classtype:trojan-activity; sid:100000679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.201.104.192"; classtype:trojan-activity; sid:100000680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.208.230.8"; classtype:trojan-activity; sid:100000681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.213.25.192"; classtype:trojan-activity; sid:100000682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.42.46.118"; classtype:trojan-activity; sid:100000683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"130.255.159.133"; classtype:trojan-activity; sid:100000598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"135.148.36.127"; classtype:trojan-activity; sid:100000599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"138.99.204.224"; classtype:trojan-activity; sid:100000600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.159.226.180"; classtype:trojan-activity; sid:100000601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.173.198"; classtype:trojan-activity; sid:100000602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.216.102.151"; classtype:trojan-activity; sid:100000603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.136.80.242"; classtype:trojan-activity; sid:100000604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.215"; classtype:trojan-activity; sid:100000605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.51"; classtype:trojan-activity; sid:100000606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.155.86.253"; classtype:trojan-activity; sid:100000607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.160.34.50"; classtype:trojan-activity; sid:100000608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.232.33.212"; classtype:trojan-activity; sid:100000609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.37.222.190"; classtype:trojan-activity; sid:100000610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.42.237.237"; classtype:trojan-activity; sid:100000611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.45.127.110"; classtype:trojan-activity; sid:100000612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.25.17"; classtype:trojan-activity; sid:100000613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.50.129.248"; classtype:trojan-activity; sid:100000614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.55.29.2"; classtype:trojan-activity; sid:100000615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"140.237.12.32"; classtype:trojan-activity; sid:100000616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"141.105.65.94"; classtype:trojan-activity; sid:100000617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.11.216.5"; classtype:trojan-activity; sid:100000618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.177.56.127"; classtype:trojan-activity; sid:100000619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"143.198.120.58"; classtype:trojan-activity; sid:100000620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"148.69.108.177"; classtype:trojan-activity; sid:100000621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.134"; classtype:trojan-activity; sid:100000622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.170"; classtype:trojan-activity; sid:100000623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.29"; classtype:trojan-activity; sid:100000624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.44"; classtype:trojan-activity; sid:100000625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.99"; classtype:trojan-activity; sid:100000626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.124.194"; classtype:trojan-activity; sid:100000627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14karatvisions.com"; classtype:trojan-activity; sid:100000628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"150.116.207.99"; classtype:trojan-activity; sid:100000629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.177.163.87"; classtype:trojan-activity; sid:100000630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.33.230.191"; classtype:trojan-activity; sid:100000631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.234.167"; classtype:trojan-activity; sid:100000632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.152.106"; classtype:trojan-activity; sid:100000633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.135.92"; classtype:trojan-activity; sid:100000634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.159.207"; classtype:trojan-activity; sid:100000635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"156.234.211.198"; classtype:trojan-activity; sid:100000636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.101.165.14"; classtype:trojan-activity; sid:100000637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.174.213.128"; classtype:trojan-activity; sid:100000638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.51.125.115"; classtype:trojan-activity; sid:100000639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"159.224.74.112"; classtype:trojan-activity; sid:100000640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"159.65.199.92"; classtype:trojan-activity; sid:100000641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.191.165.238"; classtype:trojan-activity; sid:100000642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.194.28.60"; classtype:trojan-activity; sid:100000643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.209.98.174"; classtype:trojan-activity; sid:100000644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.245.221.121"; classtype:trojan-activity; sid:100000645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.206.193"; classtype:trojan-activity; sid:100000646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"167.114.172.177"; classtype:trojan-activity; sid:100000647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"170.81.238.178"; classtype:trojan-activity; sid:100000648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.121.255.12"; classtype:trojan-activity; sid:100000649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.247.155.56"; classtype:trojan-activity; sid:100000650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.250.131.25"; classtype:trojan-activity; sid:100000651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.162.156"; classtype:trojan-activity; sid:100000652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.150.133"; classtype:trojan-activity; sid:100000653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.105.36.168"; classtype:trojan-activity; sid:100000654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.114.244.127"; classtype:trojan-activity; sid:100000655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.186.107"; classtype:trojan-activity; sid:100000656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.185"; classtype:trojan-activity; sid:100000657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.190"; classtype:trojan-activity; sid:100000658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.81.19"; classtype:trojan-activity; sid:100000659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.93.194.114"; classtype:trojan-activity; sid:100000660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.167.85.89"; classtype:trojan-activity; sid:100000661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.169.46.85"; classtype:trojan-activity; sid:100000662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.19.58.108"; classtype:trojan-activity; sid:100000663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.233.85.171"; classtype:trojan-activity; sid:100000664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.235.209.70"; classtype:trojan-activity; sid:100000665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.25.113.8"; classtype:trojan-activity; sid:100000666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.95.134"; classtype:trojan-activity; sid:100000667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.97.25"; classtype:trojan-activity; sid:100000668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.119.108"; classtype:trojan-activity; sid:100000669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.92.166"; classtype:trojan-activity; sid:100000670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.63.64.213"; classtype:trojan-activity; sid:100000671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.68.100.93"; classtype:trojan-activity; sid:100000672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.61.3.149"; classtype:trojan-activity; sid:100000673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.73.246.193"; classtype:trojan-activity; sid:100000674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.81.78.7"; classtype:trojan-activity; sid:100000675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.83.73.163"; classtype:trojan-activity; sid:100000676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.11.65.112"; classtype:trojan-activity; sid:100000677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.117.66.74"; classtype:trojan-activity; sid:100000678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.169.13.182"; classtype:trojan-activity; sid:100000679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.194.116.27"; classtype:trojan-activity; sid:100000680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.201.104.192"; classtype:trojan-activity; sid:100000681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.208.230.8"; classtype:trojan-activity; sid:100000682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.213.25.192"; classtype:trojan-activity; sid:100000683; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.35"; classtype:trojan-activity; sid:100000684; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.66"; classtype:trojan-activity; sid:100000685; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.67"; classtype:trojan-activity; sid:100000686; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.104"; classtype:trojan-activity; sid:100000687; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.121"; classtype:trojan-activity; sid:100000688; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.59"; classtype:trojan-activity; sid:100000689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.66"; classtype:trojan-activity; sid:100000690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.71"; classtype:trojan-activity; sid:100000691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.76"; classtype:trojan-activity; sid:100000692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.84"; classtype:trojan-activity; sid:100000693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.95"; classtype:trojan-activity; sid:100000694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.12.117.70"; classtype:trojan-activity; sid:100000695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.115"; classtype:trojan-activity; sid:100000696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.127"; classtype:trojan-activity; sid:100000697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.124.7.225"; classtype:trojan-activity; sid:100000698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.221.188.251"; classtype:trojan-activity; sid:100000699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.240.84.106"; classtype:trojan-activity; sid:100000700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.11.92.78"; classtype:trojan-activity; sid:100000701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.131.226.235"; classtype:trojan-activity; sid:100000702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.54.82.154"; classtype:trojan-activity; sid:100000703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.124.182.187"; classtype:trojan-activity; sid:100000704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.134.185.112"; classtype:trojan-activity; sid:100000705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.150.174.65"; classtype:trojan-activity; sid:100000706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.151.143.2"; classtype:trojan-activity; sid:100000707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.165.122.141"; classtype:trojan-activity; sid:100000708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.17.171.144"; classtype:trojan-activity; sid:100000709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.65"; classtype:trojan-activity; sid:100000690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.66"; classtype:trojan-activity; sid:100000691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.71"; classtype:trojan-activity; sid:100000692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.76"; classtype:trojan-activity; sid:100000693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.84"; classtype:trojan-activity; sid:100000694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.91"; classtype:trojan-activity; sid:100000695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.95"; classtype:trojan-activity; sid:100000696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.12.117.70"; classtype:trojan-activity; sid:100000697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.115"; classtype:trojan-activity; sid:100000698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.127"; classtype:trojan-activity; sid:100000699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.124.7.225"; classtype:trojan-activity; sid:100000700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.221.188.251"; classtype:trojan-activity; sid:100000701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.240.84.106"; classtype:trojan-activity; sid:100000702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.131.226.235"; classtype:trojan-activity; sid:100000703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.54.82.154"; classtype:trojan-activity; sid:100000704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.124.182.187"; classtype:trojan-activity; sid:100000705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.134.185.112"; classtype:trojan-activity; sid:100000706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.150.174.65"; classtype:trojan-activity; sid:100000707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.151.143.2"; classtype:trojan-activity; sid:100000708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.165.122.141"; classtype:trojan-activity; sid:100000709; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.0.145"; classtype:trojan-activity; sid:100000710; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.0.24"; classtype:trojan-activity; sid:100000711; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.179"; classtype:trojan-activity; sid:100000712; rev:1;) @@ -721,359 +721,359 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.124"; classtype:trojan-activity; sid:100000715; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.182"; classtype:trojan-activity; sid:100000716; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.221"; classtype:trojan-activity; sid:100000717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.96"; classtype:trojan-activity; sid:100000718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.151"; classtype:trojan-activity; sid:100000719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.252"; classtype:trojan-activity; sid:100000720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.207"; classtype:trojan-activity; sid:100000721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.217"; classtype:trojan-activity; sid:100000722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.25"; classtype:trojan-activity; sid:100000723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.52"; classtype:trojan-activity; sid:100000724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.58"; classtype:trojan-activity; sid:100000725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.112"; classtype:trojan-activity; sid:100000726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.67"; classtype:trojan-activity; sid:100000727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.89"; classtype:trojan-activity; sid:100000728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.160"; classtype:trojan-activity; sid:100000729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.179"; classtype:trojan-activity; sid:100000730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.199"; classtype:trojan-activity; sid:100000731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.142"; classtype:trojan-activity; sid:100000732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.156"; classtype:trojan-activity; sid:100000733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.224"; classtype:trojan-activity; sid:100000734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.127"; classtype:trojan-activity; sid:100000735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.173"; classtype:trojan-activity; sid:100000736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.87"; classtype:trojan-activity; sid:100000737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.165"; classtype:trojan-activity; sid:100000738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.181"; classtype:trojan-activity; sid:100000739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.101"; classtype:trojan-activity; sid:100000740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.139"; classtype:trojan-activity; sid:100000741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.6"; classtype:trojan-activity; sid:100000742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.191"; classtype:trojan-activity; sid:100000743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.195"; classtype:trojan-activity; sid:100000744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.190"; classtype:trojan-activity; sid:100000745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.111"; classtype:trojan-activity; sid:100000746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.183"; classtype:trojan-activity; sid:100000747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.254"; classtype:trojan-activity; sid:100000748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.247"; classtype:trojan-activity; sid:100000718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.96"; classtype:trojan-activity; sid:100000719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.104"; classtype:trojan-activity; sid:100000720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.151"; classtype:trojan-activity; sid:100000721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.212"; classtype:trojan-activity; sid:100000722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.252"; classtype:trojan-activity; sid:100000723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.207"; classtype:trojan-activity; sid:100000724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.217"; classtype:trojan-activity; sid:100000725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.25"; classtype:trojan-activity; sid:100000726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.14"; classtype:trojan-activity; sid:100000727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.58"; classtype:trojan-activity; sid:100000728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.112"; classtype:trojan-activity; sid:100000729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.115"; classtype:trojan-activity; sid:100000730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.67"; classtype:trojan-activity; sid:100000731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.160"; classtype:trojan-activity; sid:100000732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.179"; classtype:trojan-activity; sid:100000733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.135"; classtype:trojan-activity; sid:100000734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.142"; classtype:trojan-activity; sid:100000735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.224"; classtype:trojan-activity; sid:100000736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.127"; classtype:trojan-activity; sid:100000737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.173"; classtype:trojan-activity; sid:100000738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.165"; classtype:trojan-activity; sid:100000739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.181"; classtype:trojan-activity; sid:100000740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.100"; classtype:trojan-activity; sid:100000741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.101"; classtype:trojan-activity; sid:100000742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.139"; classtype:trojan-activity; sid:100000743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.6"; classtype:trojan-activity; sid:100000744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.191"; classtype:trojan-activity; sid:100000745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.195"; classtype:trojan-activity; sid:100000746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.111"; classtype:trojan-activity; sid:100000747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.183"; classtype:trojan-activity; sid:100000748; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.85"; classtype:trojan-activity; sid:100000749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.174"; classtype:trojan-activity; sid:100000750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.151"; classtype:trojan-activity; sid:100000751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.51"; classtype:trojan-activity; sid:100000752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.106"; classtype:trojan-activity; sid:100000753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.208"; classtype:trojan-activity; sid:100000754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.254"; classtype:trojan-activity; sid:100000755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.56"; classtype:trojan-activity; sid:100000756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.110"; classtype:trojan-activity; sid:100000757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.112"; classtype:trojan-activity; sid:100000758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.129"; classtype:trojan-activity; sid:100000759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.174"; classtype:trojan-activity; sid:100000760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.41"; classtype:trojan-activity; sid:100000761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.161"; classtype:trojan-activity; sid:100000762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.43"; classtype:trojan-activity; sid:100000763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.222"; classtype:trojan-activity; sid:100000764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.68"; classtype:trojan-activity; sid:100000765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.12"; classtype:trojan-activity; sid:100000766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.87"; classtype:trojan-activity; sid:100000750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.174"; classtype:trojan-activity; sid:100000751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.117"; classtype:trojan-activity; sid:100000752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.151"; classtype:trojan-activity; sid:100000753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.51"; classtype:trojan-activity; sid:100000754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.106"; classtype:trojan-activity; sid:100000755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.208"; classtype:trojan-activity; sid:100000756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.254"; classtype:trojan-activity; sid:100000757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.174"; classtype:trojan-activity; sid:100000758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.41"; classtype:trojan-activity; sid:100000759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.161"; classtype:trojan-activity; sid:100000760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.43"; classtype:trojan-activity; sid:100000761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.68"; classtype:trojan-activity; sid:100000762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.91"; classtype:trojan-activity; sid:100000763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.12"; classtype:trojan-activity; sid:100000764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.125"; classtype:trojan-activity; sid:100000765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.130"; classtype:trojan-activity; sid:100000766; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.151"; classtype:trojan-activity; sid:100000767; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.169"; classtype:trojan-activity; sid:100000768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.172"; classtype:trojan-activity; sid:100000769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.28"; classtype:trojan-activity; sid:100000770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.47"; classtype:trojan-activity; sid:100000771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.202"; classtype:trojan-activity; sid:100000772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.53"; classtype:trojan-activity; sid:100000773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.38"; classtype:trojan-activity; sid:100000774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.149"; classtype:trojan-activity; sid:100000775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.218"; classtype:trojan-activity; sid:100000776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.52"; classtype:trojan-activity; sid:100000777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.243"; classtype:trojan-activity; sid:100000769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.77"; classtype:trojan-activity; sid:100000770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.172"; classtype:trojan-activity; sid:100000771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.197"; classtype:trojan-activity; sid:100000772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.47"; classtype:trojan-activity; sid:100000773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.53"; classtype:trojan-activity; sid:100000774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.113"; classtype:trojan-activity; sid:100000775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.38"; classtype:trojan-activity; sid:100000776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.218"; classtype:trojan-activity; sid:100000777; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.129"; classtype:trojan-activity; sid:100000778; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.18"; classtype:trojan-activity; sid:100000779; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.234"; classtype:trojan-activity; sid:100000780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.46"; classtype:trojan-activity; sid:100000781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.43"; classtype:trojan-activity; sid:100000781; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.80"; classtype:trojan-activity; sid:100000782; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.202"; classtype:trojan-activity; sid:100000783; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.90"; classtype:trojan-activity; sid:100000784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.222"; classtype:trojan-activity; sid:100000785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.248"; classtype:trojan-activity; sid:100000786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.34"; classtype:trojan-activity; sid:100000787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.19"; classtype:trojan-activity; sid:100000788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.232"; classtype:trojan-activity; sid:100000789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.250"; classtype:trojan-activity; sid:100000790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.72"; classtype:trojan-activity; sid:100000791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.219"; classtype:trojan-activity; sid:100000785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.19"; classtype:trojan-activity; sid:100000786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.196"; classtype:trojan-activity; sid:100000787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.232"; classtype:trojan-activity; sid:100000788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.250"; classtype:trojan-activity; sid:100000789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.72"; classtype:trojan-activity; sid:100000790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.224"; classtype:trojan-activity; sid:100000791; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.26"; classtype:trojan-activity; sid:100000792; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.86"; classtype:trojan-activity; sid:100000793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.13"; classtype:trojan-activity; sid:100000794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.135"; classtype:trojan-activity; sid:100000795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.14"; classtype:trojan-activity; sid:100000796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.50"; classtype:trojan-activity; sid:100000797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.54"; classtype:trojan-activity; sid:100000798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.9"; classtype:trojan-activity; sid:100000799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.163"; classtype:trojan-activity; sid:100000800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.183"; classtype:trojan-activity; sid:100000801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.189"; classtype:trojan-activity; sid:100000802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.217"; classtype:trojan-activity; sid:100000803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.46"; classtype:trojan-activity; sid:100000804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.71"; classtype:trojan-activity; sid:100000805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.117"; classtype:trojan-activity; sid:100000806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.126"; classtype:trojan-activity; sid:100000807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.231"; classtype:trojan-activity; sid:100000808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.194"; classtype:trojan-activity; sid:100000809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.34"; classtype:trojan-activity; sid:100000810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.71"; classtype:trojan-activity; sid:100000811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.120"; classtype:trojan-activity; sid:100000812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.135"; classtype:trojan-activity; sid:100000794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.14"; classtype:trojan-activity; sid:100000795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.50"; classtype:trojan-activity; sid:100000796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.9"; classtype:trojan-activity; sid:100000797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.177"; classtype:trojan-activity; sid:100000798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.31"; classtype:trojan-activity; sid:100000799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.189"; classtype:trojan-activity; sid:100000800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.217"; classtype:trojan-activity; sid:100000801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.23"; classtype:trojan-activity; sid:100000802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.46"; classtype:trojan-activity; sid:100000803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.71"; classtype:trojan-activity; sid:100000804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.117"; classtype:trojan-activity; sid:100000805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.126"; classtype:trojan-activity; sid:100000806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.231"; classtype:trojan-activity; sid:100000807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.194"; classtype:trojan-activity; sid:100000808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.53"; classtype:trojan-activity; sid:100000809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.71"; classtype:trojan-activity; sid:100000810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.120"; classtype:trojan-activity; sid:100000811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.198"; classtype:trojan-activity; sid:100000812; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.206"; classtype:trojan-activity; sid:100000813; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.51"; classtype:trojan-activity; sid:100000814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.93"; classtype:trojan-activity; sid:100000815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.94"; classtype:trojan-activity; sid:100000816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.107"; classtype:trojan-activity; sid:100000817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.176"; classtype:trojan-activity; sid:100000818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.183"; classtype:trojan-activity; sid:100000819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.232"; classtype:trojan-activity; sid:100000820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.114"; classtype:trojan-activity; sid:100000821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.56"; classtype:trojan-activity; sid:100000822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.74"; classtype:trojan-activity; sid:100000815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.93"; classtype:trojan-activity; sid:100000816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.94"; classtype:trojan-activity; sid:100000817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.107"; classtype:trojan-activity; sid:100000818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.176"; classtype:trojan-activity; sid:100000819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.183"; classtype:trojan-activity; sid:100000820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.52"; classtype:trojan-activity; sid:100000821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.162"; classtype:trojan-activity; sid:100000822; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.215"; classtype:trojan-activity; sid:100000823; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.151"; classtype:trojan-activity; sid:100000824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.32"; classtype:trojan-activity; sid:100000825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.48"; classtype:trojan-activity; sid:100000826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.5"; classtype:trojan-activity; sid:100000827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.135"; classtype:trojan-activity; sid:100000828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.233"; classtype:trojan-activity; sid:100000829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.35"; classtype:trojan-activity; sid:100000830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.203"; classtype:trojan-activity; sid:100000825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.32"; classtype:trojan-activity; sid:100000826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.43"; classtype:trojan-activity; sid:100000827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.5"; classtype:trojan-activity; sid:100000828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.135"; classtype:trojan-activity; sid:100000829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.233"; classtype:trojan-activity; sid:100000830; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.109"; classtype:trojan-activity; sid:100000831; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.187"; classtype:trojan-activity; sid:100000832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.254"; classtype:trojan-activity; sid:100000833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.71"; classtype:trojan-activity; sid:100000834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.71"; classtype:trojan-activity; sid:100000833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.90"; classtype:trojan-activity; sid:100000834; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.128"; classtype:trojan-activity; sid:100000835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.55"; classtype:trojan-activity; sid:100000836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.92"; classtype:trojan-activity; sid:100000837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.34"; classtype:trojan-activity; sid:100000838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.190"; classtype:trojan-activity; sid:100000839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.180"; classtype:trojan-activity; sid:100000840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.222"; classtype:trojan-activity; sid:100000841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.83"; classtype:trojan-activity; sid:100000842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.150"; classtype:trojan-activity; sid:100000843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.175"; classtype:trojan-activity; sid:100000844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.218"; classtype:trojan-activity; sid:100000845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.248"; classtype:trojan-activity; sid:100000846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.250"; classtype:trojan-activity; sid:100000847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.98"; classtype:trojan-activity; sid:100000848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.10"; classtype:trojan-activity; sid:100000849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.122"; classtype:trojan-activity; sid:100000850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.149"; classtype:trojan-activity; sid:100000851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.215"; classtype:trojan-activity; sid:100000852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.234"; classtype:trojan-activity; sid:100000853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.12"; classtype:trojan-activity; sid:100000854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.74"; classtype:trojan-activity; sid:100000855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.88"; classtype:trojan-activity; sid:100000856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.157"; classtype:trojan-activity; sid:100000857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.158"; classtype:trojan-activity; sid:100000858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.203"; classtype:trojan-activity; sid:100000859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.210"; classtype:trojan-activity; sid:100000860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.120"; classtype:trojan-activity; sid:100000861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.180"; classtype:trojan-activity; sid:100000862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.225"; classtype:trojan-activity; sid:100000863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.108"; classtype:trojan-activity; sid:100000864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.254"; classtype:trojan-activity; sid:100000865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.124"; classtype:trojan-activity; sid:100000866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.139"; classtype:trojan-activity; sid:100000867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.182"; classtype:trojan-activity; sid:100000868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.217"; classtype:trojan-activity; sid:100000869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.68"; classtype:trojan-activity; sid:100000870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.221"; classtype:trojan-activity; sid:100000871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.28"; classtype:trojan-activity; sid:100000872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.46"; classtype:trojan-activity; sid:100000873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.114"; classtype:trojan-activity; sid:100000874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.217"; classtype:trojan-activity; sid:100000875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.238"; classtype:trojan-activity; sid:100000876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.186"; classtype:trojan-activity; sid:100000877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.38"; classtype:trojan-activity; sid:100000878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.56"; classtype:trojan-activity; sid:100000879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.78"; classtype:trojan-activity; sid:100000880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.125"; classtype:trojan-activity; sid:100000881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.234"; classtype:trojan-activity; sid:100000882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.113"; classtype:trojan-activity; sid:100000883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.196"; classtype:trojan-activity; sid:100000884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.208"; classtype:trojan-activity; sid:100000885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.11"; classtype:trojan-activity; sid:100000886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.122"; classtype:trojan-activity; sid:100000887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.2"; classtype:trojan-activity; sid:100000888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.222"; classtype:trojan-activity; sid:100000889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.75"; classtype:trojan-activity; sid:100000890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.80"; classtype:trojan-activity; sid:100000891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.99"; classtype:trojan-activity; sid:100000892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.185"; classtype:trojan-activity; sid:100000893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.194"; classtype:trojan-activity; sid:100000894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.223"; classtype:trojan-activity; sid:100000895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.30"; classtype:trojan-activity; sid:100000896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.51"; classtype:trojan-activity; sid:100000897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.54"; classtype:trojan-activity; sid:100000898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.82"; classtype:trojan-activity; sid:100000899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.254"; classtype:trojan-activity; sid:100000900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.44"; classtype:trojan-activity; sid:100000901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.217"; classtype:trojan-activity; sid:100000902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.3"; classtype:trojan-activity; sid:100000903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.42"; classtype:trojan-activity; sid:100000904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.54"; classtype:trojan-activity; sid:100000905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.68"; classtype:trojan-activity; sid:100000906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.177"; classtype:trojan-activity; sid:100000907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.2"; classtype:trojan-activity; sid:100000908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.15"; classtype:trojan-activity; sid:100000909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.176"; classtype:trojan-activity; sid:100000910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.181"; classtype:trojan-activity; sid:100000911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.24"; classtype:trojan-activity; sid:100000912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.214"; classtype:trojan-activity; sid:100000913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.231"; classtype:trojan-activity; sid:100000914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.62"; classtype:trojan-activity; sid:100000915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.79"; classtype:trojan-activity; sid:100000916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.100"; classtype:trojan-activity; sid:100000917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.196"; classtype:trojan-activity; sid:100000918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.170"; classtype:trojan-activity; sid:100000919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.60"; classtype:trojan-activity; sid:100000920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.99"; classtype:trojan-activity; sid:100000921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.30"; classtype:trojan-activity; sid:100000922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.64"; classtype:trojan-activity; sid:100000923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.74"; classtype:trojan-activity; sid:100000924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.112"; classtype:trojan-activity; sid:100000925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.145"; classtype:trojan-activity; sid:100000926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.12"; classtype:trojan-activity; sid:100000927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.235"; classtype:trojan-activity; sid:100000928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.103"; classtype:trojan-activity; sid:100000929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.106"; classtype:trojan-activity; sid:100000930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.12"; classtype:trojan-activity; sid:100000931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.158"; classtype:trojan-activity; sid:100000932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.144"; classtype:trojan-activity; sid:100000933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.180"; classtype:trojan-activity; sid:100000934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.158"; classtype:trojan-activity; sid:100000935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.49"; classtype:trojan-activity; sid:100000936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.7"; classtype:trojan-activity; sid:100000937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.250"; classtype:trojan-activity; sid:100000938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.28"; classtype:trojan-activity; sid:100000939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.137"; classtype:trojan-activity; sid:100000940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.151"; classtype:trojan-activity; sid:100000941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.206"; classtype:trojan-activity; sid:100000942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.223"; classtype:trojan-activity; sid:100000943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.53"; classtype:trojan-activity; sid:100000944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.116"; classtype:trojan-activity; sid:100000945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.234"; classtype:trojan-activity; sid:100000946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.237"; classtype:trojan-activity; sid:100000947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.140"; classtype:trojan-activity; sid:100000948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.186"; classtype:trojan-activity; sid:100000949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.214"; classtype:trojan-activity; sid:100000950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.28"; classtype:trojan-activity; sid:100000951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.65"; classtype:trojan-activity; sid:100000952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.140"; classtype:trojan-activity; sid:100000953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.17"; classtype:trojan-activity; sid:100000954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.171"; classtype:trojan-activity; sid:100000955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.18"; classtype:trojan-activity; sid:100000956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.186"; classtype:trojan-activity; sid:100000957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.35"; classtype:trojan-activity; sid:100000958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.4"; classtype:trojan-activity; sid:100000959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.5"; classtype:trojan-activity; sid:100000960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.18"; classtype:trojan-activity; sid:100000961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.113"; classtype:trojan-activity; sid:100000962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.19"; classtype:trojan-activity; sid:100000963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.198"; classtype:trojan-activity; sid:100000964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.108"; classtype:trojan-activity; sid:100000965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.177"; classtype:trojan-activity; sid:100000966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.178"; classtype:trojan-activity; sid:100000967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.218"; classtype:trojan-activity; sid:100000968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.9"; classtype:trojan-activity; sid:100000969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.143"; classtype:trojan-activity; sid:100000970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.69"; classtype:trojan-activity; sid:100000971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.208"; classtype:trojan-activity; sid:100000972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.220"; classtype:trojan-activity; sid:100000973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.74.223"; classtype:trojan-activity; sid:100000974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.94"; classtype:trojan-activity; sid:100000975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.146"; classtype:trojan-activity; sid:100000976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.221"; classtype:trojan-activity; sid:100000977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.33"; classtype:trojan-activity; sid:100000978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.8"; classtype:trojan-activity; sid:100000979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.47"; classtype:trojan-activity; sid:100000980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.118"; classtype:trojan-activity; sid:100000981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.125"; classtype:trojan-activity; sid:100000982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.250"; classtype:trojan-activity; sid:100000983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.128"; classtype:trojan-activity; sid:100000984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.146"; classtype:trojan-activity; sid:100000985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.198"; classtype:trojan-activity; sid:100000986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.119"; classtype:trojan-activity; sid:100000987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.13"; classtype:trojan-activity; sid:100000988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.130"; classtype:trojan-activity; sid:100000989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.40"; classtype:trojan-activity; sid:100000990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.114"; classtype:trojan-activity; sid:100000991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.144"; classtype:trojan-activity; sid:100000992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.189"; classtype:trojan-activity; sid:100000993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.82.110"; classtype:trojan-activity; sid:100000994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.82.73"; classtype:trojan-activity; sid:100000995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.125"; classtype:trojan-activity; sid:100000996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.154"; classtype:trojan-activity; sid:100000997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.201"; classtype:trojan-activity; sid:100000998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.237"; classtype:trojan-activity; sid:100000999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.190"; classtype:trojan-activity; sid:100001000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.117"; classtype:trojan-activity; sid:100001001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.49"; classtype:trojan-activity; sid:100001002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.59"; classtype:trojan-activity; sid:100001003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.151"; classtype:trojan-activity; sid:100001004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.161"; classtype:trojan-activity; sid:100001005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.202"; classtype:trojan-activity; sid:100001006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.207"; classtype:trojan-activity; sid:100001007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.227"; classtype:trojan-activity; sid:100001008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.102"; classtype:trojan-activity; sid:100001009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.130"; classtype:trojan-activity; sid:100001010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.194"; classtype:trojan-activity; sid:100001011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.204"; classtype:trojan-activity; sid:100001012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.85"; classtype:trojan-activity; sid:100001013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.152"; classtype:trojan-activity; sid:100001014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.69"; classtype:trojan-activity; sid:100001015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.223"; classtype:trojan-activity; sid:100001016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.24"; classtype:trojan-activity; sid:100001017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.137"; classtype:trojan-activity; sid:100001018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.236"; classtype:trojan-activity; sid:100001019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.3"; classtype:trojan-activity; sid:100001020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.79"; classtype:trojan-activity; sid:100001021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.3"; classtype:trojan-activity; sid:100001022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.97"; classtype:trojan-activity; sid:100001023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.170"; classtype:trojan-activity; sid:100001024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.115"; classtype:trojan-activity; sid:100001025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.120"; classtype:trojan-activity; sid:100001026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.234"; classtype:trojan-activity; sid:100001027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.42"; classtype:trojan-activity; sid:100001028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.98"; classtype:trojan-activity; sid:100001029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.248"; classtype:trojan-activity; sid:100001030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.27"; classtype:trojan-activity; sid:100001031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.216"; classtype:trojan-activity; sid:100000836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.55"; classtype:trojan-activity; sid:100000837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.92"; classtype:trojan-activity; sid:100000838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.34"; classtype:trojan-activity; sid:100000839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.190"; classtype:trojan-activity; sid:100000840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.233"; classtype:trojan-activity; sid:100000841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.180"; classtype:trojan-activity; sid:100000842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.222"; classtype:trojan-activity; sid:100000843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.83"; classtype:trojan-activity; sid:100000844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.150"; classtype:trojan-activity; sid:100000845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.175"; classtype:trojan-activity; sid:100000846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.218"; classtype:trojan-activity; sid:100000847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.248"; classtype:trojan-activity; sid:100000848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.250"; classtype:trojan-activity; sid:100000849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.98"; classtype:trojan-activity; sid:100000850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.10"; classtype:trojan-activity; sid:100000851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.149"; classtype:trojan-activity; sid:100000852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.215"; classtype:trojan-activity; sid:100000853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.234"; classtype:trojan-activity; sid:100000854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.12"; classtype:trojan-activity; sid:100000855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.74"; classtype:trojan-activity; sid:100000856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.88"; classtype:trojan-activity; sid:100000857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.110"; classtype:trojan-activity; sid:100000858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.158"; classtype:trojan-activity; sid:100000859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.203"; classtype:trojan-activity; sid:100000860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.210"; classtype:trojan-activity; sid:100000861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.120"; classtype:trojan-activity; sid:100000862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.14"; classtype:trojan-activity; sid:100000863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.180"; classtype:trojan-activity; sid:100000864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.225"; classtype:trojan-activity; sid:100000865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.108"; classtype:trojan-activity; sid:100000866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.254"; classtype:trojan-activity; sid:100000867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.124"; classtype:trojan-activity; sid:100000868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.139"; classtype:trojan-activity; sid:100000869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.182"; classtype:trojan-activity; sid:100000870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.217"; classtype:trojan-activity; sid:100000871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.230"; classtype:trojan-activity; sid:100000872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.68"; classtype:trojan-activity; sid:100000873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.221"; classtype:trojan-activity; sid:100000874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.28"; classtype:trojan-activity; sid:100000875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.46"; classtype:trojan-activity; sid:100000876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.114"; classtype:trojan-activity; sid:100000877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.217"; classtype:trojan-activity; sid:100000878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.90"; classtype:trojan-activity; sid:100000879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.186"; classtype:trojan-activity; sid:100000880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.38"; classtype:trojan-activity; sid:100000881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.56"; classtype:trojan-activity; sid:100000882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.78"; classtype:trojan-activity; sid:100000883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.234"; classtype:trojan-activity; sid:100000884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.110"; classtype:trojan-activity; sid:100000885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.113"; classtype:trojan-activity; sid:100000886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.11"; classtype:trojan-activity; sid:100000887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.122"; classtype:trojan-activity; sid:100000888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.127"; classtype:trojan-activity; sid:100000889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.2"; classtype:trojan-activity; sid:100000890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.222"; classtype:trojan-activity; sid:100000891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.75"; classtype:trojan-activity; sid:100000892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.80"; classtype:trojan-activity; sid:100000893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.99"; classtype:trojan-activity; sid:100000894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.164"; classtype:trojan-activity; sid:100000895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.185"; classtype:trojan-activity; sid:100000896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.194"; classtype:trojan-activity; sid:100000897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.223"; classtype:trojan-activity; sid:100000898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.104"; classtype:trojan-activity; sid:100000899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.253"; classtype:trojan-activity; sid:100000900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.30"; classtype:trojan-activity; sid:100000901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.51"; classtype:trojan-activity; sid:100000902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.54"; classtype:trojan-activity; sid:100000903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.82"; classtype:trojan-activity; sid:100000904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.223"; classtype:trojan-activity; sid:100000905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.44"; classtype:trojan-activity; sid:100000906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.217"; classtype:trojan-activity; sid:100000907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.3"; classtype:trojan-activity; sid:100000908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.42"; classtype:trojan-activity; sid:100000909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.54"; classtype:trojan-activity; sid:100000910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.68"; classtype:trojan-activity; sid:100000911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.117"; classtype:trojan-activity; sid:100000912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.2"; classtype:trojan-activity; sid:100000913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.114"; classtype:trojan-activity; sid:100000914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.139"; classtype:trojan-activity; sid:100000915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.15"; classtype:trojan-activity; sid:100000916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.176"; classtype:trojan-activity; sid:100000917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.181"; classtype:trojan-activity; sid:100000918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.24"; classtype:trojan-activity; sid:100000919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.255"; classtype:trojan-activity; sid:100000920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.214"; classtype:trojan-activity; sid:100000921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.231"; classtype:trojan-activity; sid:100000922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.62"; classtype:trojan-activity; sid:100000923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.79"; classtype:trojan-activity; sid:100000924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.87"; classtype:trojan-activity; sid:100000925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.100"; classtype:trojan-activity; sid:100000926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.119"; classtype:trojan-activity; sid:100000927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.78"; classtype:trojan-activity; sid:100000928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.118"; classtype:trojan-activity; sid:100000929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.170"; classtype:trojan-activity; sid:100000930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.60"; classtype:trojan-activity; sid:100000931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.99"; classtype:trojan-activity; sid:100000932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.30"; classtype:trojan-activity; sid:100000933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.64"; classtype:trojan-activity; sid:100000934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.74"; classtype:trojan-activity; sid:100000935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.121"; classtype:trojan-activity; sid:100000936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.145"; classtype:trojan-activity; sid:100000937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.12"; classtype:trojan-activity; sid:100000938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.130"; classtype:trojan-activity; sid:100000939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.18"; classtype:trojan-activity; sid:100000940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.103"; classtype:trojan-activity; sid:100000941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.12"; classtype:trojan-activity; sid:100000942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.173"; classtype:trojan-activity; sid:100000943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.8"; classtype:trojan-activity; sid:100000944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.201"; classtype:trojan-activity; sid:100000945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.203"; classtype:trojan-activity; sid:100000946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.212"; classtype:trojan-activity; sid:100000947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.28"; classtype:trojan-activity; sid:100000948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.130"; classtype:trojan-activity; sid:100000949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.151"; classtype:trojan-activity; sid:100000950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.206"; classtype:trojan-activity; sid:100000951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.53"; classtype:trojan-activity; sid:100000952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.116"; classtype:trojan-activity; sid:100000953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.234"; classtype:trojan-activity; sid:100000954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.237"; classtype:trojan-activity; sid:100000955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.186"; classtype:trojan-activity; sid:100000956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.28"; classtype:trojan-activity; sid:100000957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.65"; classtype:trojan-activity; sid:100000958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.140"; classtype:trojan-activity; sid:100000959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.17"; classtype:trojan-activity; sid:100000960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.171"; classtype:trojan-activity; sid:100000961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.18"; classtype:trojan-activity; sid:100000962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.186"; classtype:trojan-activity; sid:100000963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.35"; classtype:trojan-activity; sid:100000964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.4"; classtype:trojan-activity; sid:100000965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.5"; classtype:trojan-activity; sid:100000966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.113"; classtype:trojan-activity; sid:100000967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.198"; classtype:trojan-activity; sid:100000968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.108"; classtype:trojan-activity; sid:100000969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.177"; classtype:trojan-activity; sid:100000970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.178"; classtype:trojan-activity; sid:100000971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.218"; classtype:trojan-activity; sid:100000972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.9"; classtype:trojan-activity; sid:100000973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.143"; classtype:trojan-activity; sid:100000974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.69"; classtype:trojan-activity; sid:100000975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.208"; classtype:trojan-activity; sid:100000976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.220"; classtype:trojan-activity; sid:100000977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.58"; classtype:trojan-activity; sid:100000978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.74.223"; classtype:trojan-activity; sid:100000979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.94"; classtype:trojan-activity; sid:100000980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.146"; classtype:trojan-activity; sid:100000981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.221"; classtype:trojan-activity; sid:100000982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.33"; classtype:trojan-activity; sid:100000983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.34"; classtype:trojan-activity; sid:100000984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.8"; classtype:trojan-activity; sid:100000985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.118"; classtype:trojan-activity; sid:100000986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.250"; classtype:trojan-activity; sid:100000987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.128"; classtype:trojan-activity; sid:100000988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.146"; classtype:trojan-activity; sid:100000989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.198"; classtype:trojan-activity; sid:100000990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.27"; classtype:trojan-activity; sid:100000991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.119"; classtype:trojan-activity; sid:100000992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.40"; classtype:trojan-activity; sid:100000993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.144"; classtype:trojan-activity; sid:100000994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.189"; classtype:trojan-activity; sid:100000995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.82.110"; classtype:trojan-activity; sid:100000996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.82.73"; classtype:trojan-activity; sid:100000997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.125"; classtype:trojan-activity; sid:100000998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.17"; classtype:trojan-activity; sid:100000999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.146"; classtype:trojan-activity; sid:100001000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.154"; classtype:trojan-activity; sid:100001001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.201"; classtype:trojan-activity; sid:100001002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.237"; classtype:trojan-activity; sid:100001003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.190"; classtype:trojan-activity; sid:100001004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.49"; classtype:trojan-activity; sid:100001005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.151"; classtype:trojan-activity; sid:100001006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.161"; classtype:trojan-activity; sid:100001007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.202"; classtype:trojan-activity; sid:100001008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.227"; classtype:trojan-activity; sid:100001009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.102"; classtype:trojan-activity; sid:100001010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.130"; classtype:trojan-activity; sid:100001011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.194"; classtype:trojan-activity; sid:100001012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.204"; classtype:trojan-activity; sid:100001013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.85"; classtype:trojan-activity; sid:100001014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.152"; classtype:trojan-activity; sid:100001015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.195"; classtype:trojan-activity; sid:100001016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.217"; classtype:trojan-activity; sid:100001017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.223"; classtype:trojan-activity; sid:100001018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.137"; classtype:trojan-activity; sid:100001019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.236"; classtype:trojan-activity; sid:100001020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.3"; classtype:trojan-activity; sid:100001021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.79"; classtype:trojan-activity; sid:100001022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.243"; classtype:trojan-activity; sid:100001023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.3"; classtype:trojan-activity; sid:100001024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.97"; classtype:trojan-activity; sid:100001025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.170"; classtype:trojan-activity; sid:100001026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.213"; classtype:trojan-activity; sid:100001027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.120"; classtype:trojan-activity; sid:100001028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.204"; classtype:trojan-activity; sid:100001029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.234"; classtype:trojan-activity; sid:100001030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.42"; classtype:trojan-activity; sid:100001031; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.105"; classtype:trojan-activity; sid:100001032; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.54"; classtype:trojan-activity; sid:100001033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.136"; classtype:trojan-activity; sid:100001034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.177"; classtype:trojan-activity; sid:100001035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.198"; classtype:trojan-activity; sid:100001036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.83"; classtype:trojan-activity; sid:100001034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.136"; classtype:trojan-activity; sid:100001035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.177"; classtype:trojan-activity; sid:100001036; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.225"; classtype:trojan-activity; sid:100001037; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.248"; classtype:trojan-activity; sid:100001038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.70"; classtype:trojan-activity; sid:100001039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.63"; classtype:trojan-activity; sid:100001040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.45"; classtype:trojan-activity; sid:100001041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.90"; classtype:trojan-activity; sid:100001042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.19.183.14"; classtype:trojan-activity; sid:100001043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.205.101.33"; classtype:trojan-activity; sid:100001044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.21.164.68"; classtype:trojan-activity; sid:100001045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.217.8.194"; classtype:trojan-activity; sid:100001046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.22.117.102"; classtype:trojan-activity; sid:100001047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.222.252.130"; classtype:trojan-activity; sid:100001048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.34.183.30"; classtype:trojan-activity; sid:100001049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.48.235.59"; classtype:trojan-activity; sid:100001050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.95.136.35"; classtype:trojan-activity; sid:100001051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.159.58.134"; classtype:trojan-activity; sid:100001052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.225.152.238"; classtype:trojan-activity; sid:100001053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.43.176.41"; classtype:trojan-activity; sid:100001054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.43.176.48"; classtype:trojan-activity; sid:100001055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.60.84.7"; classtype:trojan-activity; sid:100001056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.99.210.161"; classtype:trojan-activity; sid:100001057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.108.21.172"; classtype:trojan-activity; sid:100001058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.114.60.229"; classtype:trojan-activity; sid:100001059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.174.205.57"; classtype:trojan-activity; sid:100001060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.175.236.209"; classtype:trojan-activity; sid:100001061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.105.41"; classtype:trojan-activity; sid:100001062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.110.243"; classtype:trojan-activity; sid:100001063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.165.230"; classtype:trojan-activity; sid:100001064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.214.171"; classtype:trojan-activity; sid:100001065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.34.51"; classtype:trojan-activity; sid:100001066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.104.65"; classtype:trojan-activity; sid:100001067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.180.6"; classtype:trojan-activity; sid:100001068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.242.73"; classtype:trojan-activity; sid:100001069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.218.5.171"; classtype:trojan-activity; sid:100001070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.63"; classtype:trojan-activity; sid:100001039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.45"; classtype:trojan-activity; sid:100001040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.19.183.14"; classtype:trojan-activity; sid:100001041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.205.101.33"; classtype:trojan-activity; sid:100001042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.21.164.68"; classtype:trojan-activity; sid:100001043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.217.8.194"; classtype:trojan-activity; sid:100001044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.22.117.102"; classtype:trojan-activity; sid:100001045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.222.252.130"; classtype:trojan-activity; sid:100001046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.34.183.30"; classtype:trojan-activity; sid:100001047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.48.235.59"; classtype:trojan-activity; sid:100001048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.95.136.35"; classtype:trojan-activity; sid:100001049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.159.58.134"; classtype:trojan-activity; sid:100001050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.225.152.238"; classtype:trojan-activity; sid:100001051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.43.176.41"; classtype:trojan-activity; sid:100001052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.43.176.48"; classtype:trojan-activity; sid:100001053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.60.84.7"; classtype:trojan-activity; sid:100001054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.99.210.161"; classtype:trojan-activity; sid:100001055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.108.21.172"; classtype:trojan-activity; sid:100001056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.114.60.229"; classtype:trojan-activity; sid:100001057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.174.205.57"; classtype:trojan-activity; sid:100001058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.175.236.209"; classtype:trojan-activity; sid:100001059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.105.41"; classtype:trojan-activity; sid:100001060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.110.243"; classtype:trojan-activity; sid:100001061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.165.230"; classtype:trojan-activity; sid:100001062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.214.171"; classtype:trojan-activity; sid:100001063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.34.51"; classtype:trojan-activity; sid:100001064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.104.65"; classtype:trojan-activity; sid:100001065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.180.6"; classtype:trojan-activity; sid:100001066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.242.73"; classtype:trojan-activity; sid:100001067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.5.36"; classtype:trojan-activity; sid:100001068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.218.5.171"; classtype:trojan-activity; sid:100001069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.248.80.38"; classtype:trojan-activity; sid:100001070; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.111.36"; classtype:trojan-activity; sid:100001071; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.53.93"; classtype:trojan-activity; sid:100001072; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.94.170.166"; classtype:trojan-activity; sid:100001073; rev:1;) @@ -1090,226 +1090,226 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.236.4"; classtype:trojan-activity; sid:100001084; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.59.162"; classtype:trojan-activity; sid:100001085; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.177.134"; classtype:trojan-activity; sid:100001086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.88.240"; classtype:trojan-activity; sid:100001087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.88.247"; classtype:trojan-activity; sid:100001088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.115.176.253"; classtype:trojan-activity; sid:100001089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.102.190"; classtype:trojan-activity; sid:100001090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.35.52"; classtype:trojan-activity; sid:100001091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.200.55"; classtype:trojan-activity; sid:100001092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.22"; classtype:trojan-activity; sid:100001093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.192.88"; classtype:trojan-activity; sid:100001094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.34.180"; classtype:trojan-activity; sid:100001095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.73.158"; classtype:trojan-activity; sid:100001096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.254.7"; classtype:trojan-activity; sid:100001097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.87.210"; classtype:trojan-activity; sid:100001098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.87.246"; classtype:trojan-activity; sid:100001099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.213.136"; classtype:trojan-activity; sid:100001100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.160.98.250"; classtype:trojan-activity; sid:100001101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.233.0.252"; classtype:trojan-activity; sid:100001102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.235.252.31"; classtype:trojan-activity; sid:100001103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.53.197.62"; classtype:trojan-activity; sid:100001104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.59.170.157"; classtype:trojan-activity; sid:100001105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.88.27.89"; classtype:trojan-activity; sid:100001106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.104.83"; classtype:trojan-activity; sid:100001107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.109.169.45"; classtype:trojan-activity; sid:100001108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.17.145.112"; classtype:trojan-activity; sid:100001109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.144.204"; classtype:trojan-activity; sid:100001110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.146.216"; classtype:trojan-activity; sid:100001111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.109.216"; classtype:trojan-activity; sid:100001112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.14.20"; classtype:trojan-activity; sid:100001113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.97.40.9"; classtype:trojan-activity; sid:100001114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.164.185.41"; classtype:trojan-activity; sid:100001115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.175.115.10"; classtype:trojan-activity; sid:100001116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.74.149.230"; classtype:trojan-activity; sid:100001117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.106.209.68"; classtype:trojan-activity; sid:100001118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.107.3.8"; classtype:trojan-activity; sid:100001119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.117.2.107"; classtype:trojan-activity; sid:100001120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.172.110.209"; classtype:trojan-activity; sid:100001121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.172.110.235"; classtype:trojan-activity; sid:100001122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.174.101.41"; classtype:trojan-activity; sid:100001123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.181.10.234"; classtype:trojan-activity; sid:100001124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.112"; classtype:trojan-activity; sid:100001125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.23"; classtype:trojan-activity; sid:100001126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.54"; classtype:trojan-activity; sid:100001127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.77"; classtype:trojan-activity; sid:100001128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.221.3.244"; classtype:trojan-activity; sid:100001129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.222.58.152"; classtype:trojan-activity; sid:100001130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.224.129.224"; classtype:trojan-activity; sid:100001131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.224.129.235"; classtype:trojan-activity; sid:100001132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.228.141.74"; classtype:trojan-activity; sid:100001133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.245.96.94"; classtype:trojan-activity; sid:100001134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.26.113.95"; classtype:trojan-activity; sid:100001135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.34.16.231"; classtype:trojan-activity; sid:100001136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.55.1.182"; classtype:trojan-activity; sid:100001137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.68.230.207"; classtype:trojan-activity; sid:100001138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.81.154.208"; classtype:trojan-activity; sid:100001139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.81.157.186"; classtype:trojan-activity; sid:100001140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.185"; classtype:trojan-activity; sid:100001141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.213"; classtype:trojan-activity; sid:100001142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.160"; classtype:trojan-activity; sid:100001143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.161"; classtype:trojan-activity; sid:100001144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.219"; classtype:trojan-activity; sid:100001145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.80"; classtype:trojan-activity; sid:100001146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.151.144.85"; classtype:trojan-activity; sid:100001147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.219.164"; classtype:trojan-activity; sid:100001148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.112"; classtype:trojan-activity; sid:100001149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.77"; classtype:trojan-activity; sid:100001150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.91"; classtype:trojan-activity; sid:100001151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.253.150"; classtype:trojan-activity; sid:100001152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.225.120.173"; classtype:trojan-activity; sid:100001153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.232.44.86"; classtype:trojan-activity; sid:100001154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.28.60.184"; classtype:trojan-activity; sid:100001155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.34.4.40"; classtype:trojan-activity; sid:100001156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.73.188.132"; classtype:trojan-activity; sid:100001157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.73.188.134"; classtype:trojan-activity; sid:100001158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.12.10.98"; classtype:trojan-activity; sid:100001159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.135.141.192"; classtype:trojan-activity; sid:100001160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.188.124.229"; classtype:trojan-activity; sid:100001161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.233.234.215"; classtype:trojan-activity; sid:100001162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.21.14"; classtype:trojan-activity; sid:100001163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.231.246"; classtype:trojan-activity; sid:100001164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.13.179.87"; classtype:trojan-activity; sid:100001165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.138.200.32"; classtype:trojan-activity; sid:100001166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.152.41.141"; classtype:trojan-activity; sid:100001167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.178.50"; classtype:trojan-activity; sid:100001168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.179.127"; classtype:trojan-activity; sid:100001169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.30.30"; classtype:trojan-activity; sid:100001170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.36.163"; classtype:trojan-activity; sid:100001171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.242.242.144"; classtype:trojan-activity; sid:100001172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.69.251.12"; classtype:trojan-activity; sid:100001173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.83.202.25"; classtype:trojan-activity; sid:100001174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"189.201.250.184"; classtype:trojan-activity; sid:100001175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"189.252.184.115"; classtype:trojan-activity; sid:100001176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.0.42.106"; classtype:trojan-activity; sid:100001177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.109.178.139"; classtype:trojan-activity; sid:100001178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.110.161.252"; classtype:trojan-activity; sid:100001179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.111.151.164"; classtype:trojan-activity; sid:100001180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.119.207.58"; classtype:trojan-activity; sid:100001181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.12.99.194"; classtype:trojan-activity; sid:100001182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.160"; classtype:trojan-activity; sid:100001183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.3"; classtype:trojan-activity; sid:100001184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.37"; classtype:trojan-activity; sid:100001185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.41"; classtype:trojan-activity; sid:100001186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.42"; classtype:trojan-activity; sid:100001187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.76"; classtype:trojan-activity; sid:100001188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.20.14"; classtype:trojan-activity; sid:100001189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.141.117.41"; classtype:trojan-activity; sid:100001190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.147.16.184"; classtype:trojan-activity; sid:100001191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.159.240.9"; classtype:trojan-activity; sid:100001192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.210.214.130"; classtype:trojan-activity; sid:100001193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.177.39"; classtype:trojan-activity; sid:100001194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.226.63"; classtype:trojan-activity; sid:100001195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.49.207"; classtype:trojan-activity; sid:100001196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.214.24.194"; classtype:trojan-activity; sid:100001197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.216.140.123"; classtype:trojan-activity; sid:100001198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.65.206.162"; classtype:trojan-activity; sid:100001199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.73.12.149"; classtype:trojan-activity; sid:100001200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.92.4.231"; classtype:trojan-activity; sid:100001201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.135"; classtype:trojan-activity; sid:100001202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.200"; classtype:trojan-activity; sid:100001203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.41.33"; classtype:trojan-activity; sid:100001204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"191.255.248.220"; classtype:trojan-activity; sid:100001205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.153.57.94"; classtype:trojan-activity; sid:100001206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.210.175.130"; classtype:trojan-activity; sid:100001207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.220.55"; classtype:trojan-activity; sid:100001208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.228.67"; classtype:trojan-activity; sid:100001209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.99.240.77"; classtype:trojan-activity; sid:100001210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.113.107.243"; classtype:trojan-activity; sid:100001211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.147.142.230"; classtype:trojan-activity; sid:100001212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.15.36.167"; classtype:trojan-activity; sid:100001213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.152.35.139"; classtype:trojan-activity; sid:100001214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.38.20.199"; classtype:trojan-activity; sid:100001215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.139.126.51"; classtype:trojan-activity; sid:100001216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.228.231.218"; classtype:trojan-activity; sid:100001217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.24.94.187"; classtype:trojan-activity; sid:100001218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.202.26.182"; classtype:trojan-activity; sid:100001219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.218.48.82"; classtype:trojan-activity; sid:100001220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.148.90"; classtype:trojan-activity; sid:100001221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.166.203"; classtype:trojan-activity; sid:100001222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.159.2.106"; classtype:trojan-activity; sid:100001223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.50.27.115"; classtype:trojan-activity; sid:100001224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.133.218"; classtype:trojan-activity; sid:100001225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.174.104"; classtype:trojan-activity; sid:100001226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.207.121"; classtype:trojan-activity; sid:100001227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.251.105"; classtype:trojan-activity; sid:100001228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.132.132"; classtype:trojan-activity; sid:100001229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1am.co.nz"; classtype:trojan-activity; sid:100001230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.239.22.188"; classtype:trojan-activity; sid:100001231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.36.231.201"; classtype:trojan-activity; sid:100001232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.37.149.230"; classtype:trojan-activity; sid:100001233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.37.203.65"; classtype:trojan-activity; sid:100001234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.111.158"; classtype:trojan-activity; sid:100001235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.4.24"; classtype:trojan-activity; sid:100001236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.125.182"; classtype:trojan-activity; sid:100001237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.92.184"; classtype:trojan-activity; sid:100001238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.56.8.80"; classtype:trojan-activity; sid:100001239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.57.122.107"; classtype:trojan-activity; sid:100001240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.57.122.24"; classtype:trojan-activity; sid:100001241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.83.152.16"; classtype:trojan-activity; sid:100001242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"20.185.42.197"; classtype:trojan-activity; sid:100001243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.105.167.98"; classtype:trojan-activity; sid:100001244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.111.189.70"; classtype:trojan-activity; sid:100001245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.194.4.24"; classtype:trojan-activity; sid:100001246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.2.161.171"; classtype:trojan-activity; sid:100001247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.29.105.207"; classtype:trojan-activity; sid:100001248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.30.132.50"; classtype:trojan-activity; sid:100001249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.170.46.2"; classtype:trojan-activity; sid:100001250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.184.163.170"; classtype:trojan-activity; sid:100001251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.187.102.73"; classtype:trojan-activity; sid:100001252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.200.254.86"; classtype:trojan-activity; sid:100001253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.203.221.20"; classtype:trojan-activity; sid:100001254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.107.233.41"; classtype:trojan-activity; sid:100001255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.111.131.236"; classtype:trojan-activity; sid:100001256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.166.217.54"; classtype:trojan-activity; sid:100001257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.182.125.175"; classtype:trojan-activity; sid:100001258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.29.95.12"; classtype:trojan-activity; sid:100001259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.4.124.58"; classtype:trojan-activity; sid:100001260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.44.228.125"; classtype:trojan-activity; sid:100001261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.113.4.247"; classtype:trojan-activity; sid:100001087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.194.183"; classtype:trojan-activity; sid:100001088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.102.190"; classtype:trojan-activity; sid:100001089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.29.27"; classtype:trojan-activity; sid:100001090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.200.55"; classtype:trojan-activity; sid:100001091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.23.75"; classtype:trojan-activity; sid:100001092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.48.230"; classtype:trojan-activity; sid:100001093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.22"; classtype:trojan-activity; sid:100001094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.192.88"; classtype:trojan-activity; sid:100001095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.34.180"; classtype:trojan-activity; sid:100001096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.200.137"; classtype:trojan-activity; sid:100001097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.205.246"; classtype:trojan-activity; sid:100001098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.254.7"; classtype:trojan-activity; sid:100001099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.109.194"; classtype:trojan-activity; sid:100001100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.126.162"; classtype:trojan-activity; sid:100001101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.87.210"; classtype:trojan-activity; sid:100001102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.87.246"; classtype:trojan-activity; sid:100001103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.207.187"; classtype:trojan-activity; sid:100001104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.80.240"; classtype:trojan-activity; sid:100001105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.160.98.250"; classtype:trojan-activity; sid:100001106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.233.0.252"; classtype:trojan-activity; sid:100001107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.235.252.31"; classtype:trojan-activity; sid:100001108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.53.197.62"; classtype:trojan-activity; sid:100001109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.88.27.89"; classtype:trojan-activity; sid:100001110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.104.83"; classtype:trojan-activity; sid:100001111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.109.169.45"; classtype:trojan-activity; sid:100001112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.141.61.174"; classtype:trojan-activity; sid:100001113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.17.145.112"; classtype:trojan-activity; sid:100001114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.144.204"; classtype:trojan-activity; sid:100001115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.49.86.54"; classtype:trojan-activity; sid:100001116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.14.20"; classtype:trojan-activity; sid:100001117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.97.40.9"; classtype:trojan-activity; sid:100001118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.164.185.41"; classtype:trojan-activity; sid:100001119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.175.115.10"; classtype:trojan-activity; sid:100001120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.74.149.230"; classtype:trojan-activity; sid:100001121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.106.209.68"; classtype:trojan-activity; sid:100001122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.117.2.107"; classtype:trojan-activity; sid:100001123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.117.21.212"; classtype:trojan-activity; sid:100001124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.132.53.182"; classtype:trojan-activity; sid:100001125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.172.110.209"; classtype:trojan-activity; sid:100001126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.172.110.235"; classtype:trojan-activity; sid:100001127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.174.101.41"; classtype:trojan-activity; sid:100001128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.181.10.234"; classtype:trojan-activity; sid:100001129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.112"; classtype:trojan-activity; sid:100001130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.23"; classtype:trojan-activity; sid:100001131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.54"; classtype:trojan-activity; sid:100001132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.77"; classtype:trojan-activity; sid:100001133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.221.3.244"; classtype:trojan-activity; sid:100001134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.222.58.152"; classtype:trojan-activity; sid:100001135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.224.129.224"; classtype:trojan-activity; sid:100001136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.224.129.235"; classtype:trojan-activity; sid:100001137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.228.141.74"; classtype:trojan-activity; sid:100001138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.245.96.94"; classtype:trojan-activity; sid:100001139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.26.113.95"; classtype:trojan-activity; sid:100001140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.34.16.231"; classtype:trojan-activity; sid:100001141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.38.142.194"; classtype:trojan-activity; sid:100001142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.55.1.182"; classtype:trojan-activity; sid:100001143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.68.230.207"; classtype:trojan-activity; sid:100001144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.81.154.208"; classtype:trojan-activity; sid:100001145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.81.157.186"; classtype:trojan-activity; sid:100001146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.185"; classtype:trojan-activity; sid:100001147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.213"; classtype:trojan-activity; sid:100001148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.219"; classtype:trojan-activity; sid:100001149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.80"; classtype:trojan-activity; sid:100001150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.151.144.85"; classtype:trojan-activity; sid:100001151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.219.164"; classtype:trojan-activity; sid:100001152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.112"; classtype:trojan-activity; sid:100001153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.77"; classtype:trojan-activity; sid:100001154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.91"; classtype:trojan-activity; sid:100001155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.253.150"; classtype:trojan-activity; sid:100001156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.225.120.173"; classtype:trojan-activity; sid:100001157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.232.44.86"; classtype:trojan-activity; sid:100001158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.28.60.184"; classtype:trojan-activity; sid:100001159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.34.4.40"; classtype:trojan-activity; sid:100001160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.73.188.132"; classtype:trojan-activity; sid:100001161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.12.10.98"; classtype:trojan-activity; sid:100001162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.135.141.192"; classtype:trojan-activity; sid:100001163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.188.124.229"; classtype:trojan-activity; sid:100001164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.233.234.215"; classtype:trojan-activity; sid:100001165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.21.14"; classtype:trojan-activity; sid:100001166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.231.246"; classtype:trojan-activity; sid:100001167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.13.179.87"; classtype:trojan-activity; sid:100001168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.138.200.32"; classtype:trojan-activity; sid:100001169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.152.41.141"; classtype:trojan-activity; sid:100001170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.178.50"; classtype:trojan-activity; sid:100001171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.179.127"; classtype:trojan-activity; sid:100001172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.199.59"; classtype:trojan-activity; sid:100001173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.30.30"; classtype:trojan-activity; sid:100001174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.36.163"; classtype:trojan-activity; sid:100001175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.45.140"; classtype:trojan-activity; sid:100001176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.242.242.144"; classtype:trojan-activity; sid:100001177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.69.251.12"; classtype:trojan-activity; sid:100001178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.83.202.25"; classtype:trojan-activity; sid:100001179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"189.171.22.132"; classtype:trojan-activity; sid:100001180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"189.175.214.112"; classtype:trojan-activity; sid:100001181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"189.252.184.115"; classtype:trojan-activity; sid:100001182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.0.42.106"; classtype:trojan-activity; sid:100001183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.109.178.139"; classtype:trojan-activity; sid:100001184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.110.161.252"; classtype:trojan-activity; sid:100001185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.111.151.164"; classtype:trojan-activity; sid:100001186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.119.207.58"; classtype:trojan-activity; sid:100001187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.12.99.194"; classtype:trojan-activity; sid:100001188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.160"; classtype:trojan-activity; sid:100001189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.3"; classtype:trojan-activity; sid:100001190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.37"; classtype:trojan-activity; sid:100001191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.41"; classtype:trojan-activity; sid:100001192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.42"; classtype:trojan-activity; sid:100001193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.76"; classtype:trojan-activity; sid:100001194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.20.14"; classtype:trojan-activity; sid:100001195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.147.16.184"; classtype:trojan-activity; sid:100001196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.159.240.9"; classtype:trojan-activity; sid:100001197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.210.214.130"; classtype:trojan-activity; sid:100001198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.177.39"; classtype:trojan-activity; sid:100001199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.226.63"; classtype:trojan-activity; sid:100001200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.49.207"; classtype:trojan-activity; sid:100001201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.214.24.194"; classtype:trojan-activity; sid:100001202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.216.140.123"; classtype:trojan-activity; sid:100001203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.65.206.162"; classtype:trojan-activity; sid:100001204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.73.12.149"; classtype:trojan-activity; sid:100001205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.92.4.231"; classtype:trojan-activity; sid:100001206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.135"; classtype:trojan-activity; sid:100001207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.200"; classtype:trojan-activity; sid:100001208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.41.33"; classtype:trojan-activity; sid:100001209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"191.255.248.220"; classtype:trojan-activity; sid:100001210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.210.175.130"; classtype:trojan-activity; sid:100001211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.185.106"; classtype:trojan-activity; sid:100001212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.220.55"; classtype:trojan-activity; sid:100001213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.228.67"; classtype:trojan-activity; sid:100001214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.99.221.230"; classtype:trojan-activity; sid:100001215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.99.240.77"; classtype:trojan-activity; sid:100001216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.113.107.243"; classtype:trojan-activity; sid:100001217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.147.142.230"; classtype:trojan-activity; sid:100001218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.152.35.139"; classtype:trojan-activity; sid:100001219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.38.20.199"; classtype:trojan-activity; sid:100001220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.139.126.51"; classtype:trojan-activity; sid:100001221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.228.231.218"; classtype:trojan-activity; sid:100001222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.24.94.187"; classtype:trojan-activity; sid:100001223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.5.3.162"; classtype:trojan-activity; sid:100001224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.202.26.182"; classtype:trojan-activity; sid:100001225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.218.48.82"; classtype:trojan-activity; sid:100001226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.148.90"; classtype:trojan-activity; sid:100001227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.166.203"; classtype:trojan-activity; sid:100001228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.159.2.106"; classtype:trojan-activity; sid:100001229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.50.27.115"; classtype:trojan-activity; sid:100001230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.133.218"; classtype:trojan-activity; sid:100001231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.213.61"; classtype:trojan-activity; sid:100001232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.251.105"; classtype:trojan-activity; sid:100001233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1am.co.nz"; classtype:trojan-activity; sid:100001234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.239.22.188"; classtype:trojan-activity; sid:100001235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.36.231.201"; classtype:trojan-activity; sid:100001236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.37.149.230"; classtype:trojan-activity; sid:100001237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.111.158"; classtype:trojan-activity; sid:100001238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.4.24"; classtype:trojan-activity; sid:100001239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.125.182"; classtype:trojan-activity; sid:100001240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.92.184"; classtype:trojan-activity; sid:100001241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.56.8.80"; classtype:trojan-activity; sid:100001242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.57.122.107"; classtype:trojan-activity; sid:100001243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.57.122.24"; classtype:trojan-activity; sid:100001244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.83.152.16"; classtype:trojan-activity; sid:100001245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"20.185.42.197"; classtype:trojan-activity; sid:100001246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.105.167.98"; classtype:trojan-activity; sid:100001247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.111.189.70"; classtype:trojan-activity; sid:100001248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.194.4.24"; classtype:trojan-activity; sid:100001249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.29.105.207"; classtype:trojan-activity; sid:100001250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.30.132.50"; classtype:trojan-activity; sid:100001251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.170.46.2"; classtype:trojan-activity; sid:100001252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.184.163.170"; classtype:trojan-activity; sid:100001253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.187.102.73"; classtype:trojan-activity; sid:100001254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.200.254.86"; classtype:trojan-activity; sid:100001255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.203.221.20"; classtype:trojan-activity; sid:100001256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.107.233.41"; classtype:trojan-activity; sid:100001257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.111.131.236"; classtype:trojan-activity; sid:100001258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.166.217.54"; classtype:trojan-activity; sid:100001259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.29.95.12"; classtype:trojan-activity; sid:100001260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.4.124.58"; classtype:trojan-activity; sid:100001261; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.176.114"; classtype:trojan-activity; sid:100001262; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.191.174"; classtype:trojan-activity; sid:100001263; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.74.236.9"; classtype:trojan-activity; sid:100001264; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.109.201.243"; classtype:trojan-activity; sid:100001265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.159.80.128"; classtype:trojan-activity; sid:100001266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.159.80.129"; classtype:trojan-activity; sid:100001267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.159.80.164"; classtype:trojan-activity; sid:100001268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.170.123.78"; classtype:trojan-activity; sid:100001269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.189.156.107"; classtype:trojan-activity; sid:100001270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.204.232.18"; classtype:trojan-activity; sid:100001271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.229.21.56"; classtype:trojan-activity; sid:100001272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.236.190.28"; classtype:trojan-activity; sid:100001273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.70.166.107"; classtype:trojan-activity; sid:100001274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.77.80.159"; classtype:trojan-activity; sid:100001275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.119.166"; classtype:trojan-activity; sid:100001276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.171.138"; classtype:trojan-activity; sid:100001277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.82.36.34"; classtype:trojan-activity; sid:100001278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.93.6.28"; classtype:trojan-activity; sid:100001279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"204.195.116.171"; classtype:trojan-activity; sid:100001280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.248.137.132"; classtype:trojan-activity; sid:100001281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.5.32.6"; classtype:trojan-activity; sid:100001282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"208.163.58.18"; classtype:trojan-activity; sid:100001283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"208.75.27.157"; classtype:trojan-activity; sid:100001284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.190"; classtype:trojan-activity; sid:100001285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.31"; classtype:trojan-activity; sid:100001286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.146.98.50"; classtype:trojan-activity; sid:100001287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.124.149.19"; classtype:trojan-activity; sid:100001288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.180.237.212"; classtype:trojan-activity; sid:100001289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.152.122"; classtype:trojan-activity; sid:100001290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.153.142"; classtype:trojan-activity; sid:100001291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.237.70"; classtype:trojan-activity; sid:100001292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.130.69.205"; classtype:trojan-activity; sid:100001266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.159.80.128"; classtype:trojan-activity; sid:100001267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.159.80.129"; classtype:trojan-activity; sid:100001268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.159.80.164"; classtype:trojan-activity; sid:100001269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.170.123.78"; classtype:trojan-activity; sid:100001270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.189.156.107"; classtype:trojan-activity; sid:100001271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.204.232.18"; classtype:trojan-activity; sid:100001272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.229.21.56"; classtype:trojan-activity; sid:100001273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.236.190.28"; classtype:trojan-activity; sid:100001274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.70.166.107"; classtype:trojan-activity; sid:100001275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.77.80.159"; classtype:trojan-activity; sid:100001276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.119.166"; classtype:trojan-activity; sid:100001277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.171.138"; classtype:trojan-activity; sid:100001278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.82.36.34"; classtype:trojan-activity; sid:100001279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.93.6.28"; classtype:trojan-activity; sid:100001280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"204.195.116.171"; classtype:trojan-activity; sid:100001281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.248.137.132"; classtype:trojan-activity; sid:100001282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.5.32.6"; classtype:trojan-activity; sid:100001283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"208.163.58.18"; classtype:trojan-activity; sid:100001284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"208.75.27.157"; classtype:trojan-activity; sid:100001285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.190"; classtype:trojan-activity; sid:100001286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.31"; classtype:trojan-activity; sid:100001287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.146.98.50"; classtype:trojan-activity; sid:100001288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.124.149.19"; classtype:trojan-activity; sid:100001289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.180.237.212"; classtype:trojan-activity; sid:100001290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.152.122"; classtype:trojan-activity; sid:100001291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.153.142"; classtype:trojan-activity; sid:100001292; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.245.109"; classtype:trojan-activity; sid:100001293; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.68.242.114"; classtype:trojan-activity; sid:100001294; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.132.204"; classtype:trojan-activity; sid:100001295; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.75.220"; classtype:trojan-activity; sid:100001296; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.200.160.239"; classtype:trojan-activity; sid:100001297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.204.215.157"; classtype:trojan-activity; sid:100001298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.66.179"; classtype:trojan-activity; sid:100001299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.93.93"; classtype:trojan-activity; sid:100001300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.216.66.105"; classtype:trojan-activity; sid:100001301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.114.96"; classtype:trojan-activity; sid:100001302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.120.13"; classtype:trojan-activity; sid:100001303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.246.137"; classtype:trojan-activity; sid:100001304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.238.83.238"; classtype:trojan-activity; sid:100001305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.5.96"; classtype:trojan-activity; sid:100001306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.203.111.207"; classtype:trojan-activity; sid:100001298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.204.215.157"; classtype:trojan-activity; sid:100001299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.66.179"; classtype:trojan-activity; sid:100001300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.93.93"; classtype:trojan-activity; sid:100001301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.216.66.105"; classtype:trojan-activity; sid:100001302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.114.96"; classtype:trojan-activity; sid:100001303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.120.13"; classtype:trojan-activity; sid:100001304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.246.137"; classtype:trojan-activity; sid:100001305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.238.83.238"; classtype:trojan-activity; sid:100001306; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.122.86.105"; classtype:trojan-activity; sid:100001307; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.156.215.178"; classtype:trojan-activity; sid:100001308; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.46.197.114"; classtype:trojan-activity; sid:100001309; rev:1;) @@ -1319,7 +1319,7 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.14.173.117"; classtype:trojan-activity; sid:100001313; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.190.193"; classtype:trojan-activity; sid:100001314; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.160"; classtype:trojan-activity; sid:100001315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.99"; classtype:trojan-activity; sid:100001316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.20"; classtype:trojan-activity; sid:100001316; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.225"; classtype:trojan-activity; sid:100001317; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.51"; classtype:trojan-activity; sid:100001318; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.202"; classtype:trojan-activity; sid:100001319; rev:1;) @@ -1336,7 +1336,7 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.227"; classtype:trojan-activity; sid:100001330; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.176"; classtype:trojan-activity; sid:100001331; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.201"; classtype:trojan-activity; sid:100001332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.7"; classtype:trojan-activity; sid:100001333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.204"; classtype:trojan-activity; sid:100001333; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.250"; classtype:trojan-activity; sid:100001334; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.46"; classtype:trojan-activity; sid:100001335; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.189.178.163"; classtype:trojan-activity; sid:100001336; rev:1;) @@ -1356,21 +1356,21 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.2.40.34"; classtype:trojan-activity; sid:100001350; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.234.165.18"; classtype:trojan-activity; sid:100001351; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.238.246.3"; classtype:trojan-activity; sid:100001352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.32.118.1"; classtype:trojan-activity; sid:100001353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.207.119"; classtype:trojan-activity; sid:100001354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.227.133"; classtype:trojan-activity; sid:100001355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.68.35"; classtype:trojan-activity; sid:100001356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.81.81"; classtype:trojan-activity; sid:100001357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.56.93.129"; classtype:trojan-activity; sid:100001358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.59.116.203"; classtype:trojan-activity; sid:100001359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.79.103.159"; classtype:trojan-activity; sid:100001360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.93.102.63"; classtype:trojan-activity; sid:100001361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.93.102.75"; classtype:trojan-activity; sid:100001362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.207.119"; classtype:trojan-activity; sid:100001353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.227.133"; classtype:trojan-activity; sid:100001354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.68.35"; classtype:trojan-activity; sid:100001355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.81.81"; classtype:trojan-activity; sid:100001356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.56.93.129"; classtype:trojan-activity; sid:100001357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.59.116.203"; classtype:trojan-activity; sid:100001358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.79.103.159"; classtype:trojan-activity; sid:100001359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.93.102.63"; classtype:trojan-activity; sid:100001360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.93.102.75"; classtype:trojan-activity; sid:100001361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.113.171"; classtype:trojan-activity; sid:100001362; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.127.194"; classtype:trojan-activity; sid:100001363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.137.93"; classtype:trojan-activity; sid:100001364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.73.171"; classtype:trojan-activity; sid:100001365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.136.212"; classtype:trojan-activity; sid:100001366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.139.165"; classtype:trojan-activity; sid:100001367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.226.205"; classtype:trojan-activity; sid:100001364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.136.212"; classtype:trojan-activity; sid:100001365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.14.239"; classtype:trojan-activity; sid:100001366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.178.196"; classtype:trojan-activity; sid:100001367; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.37.210"; classtype:trojan-activity; sid:100001368; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.241.6.180"; classtype:trojan-activity; sid:100001369; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.148"; classtype:trojan-activity; sid:100001370; rev:1;) @@ -1385,44 +1385,44 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.85.145.194"; classtype:trojan-activity; sid:100001379; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"21robo.com"; classtype:trojan-activity; sid:100001380; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.126.237.74"; classtype:trojan-activity; sid:100001381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.132.106.247"; classtype:trojan-activity; sid:100001382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.173.160.185"; classtype:trojan-activity; sid:100001383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.200.22.163"; classtype:trojan-activity; sid:100001384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.81.134.72"; classtype:trojan-activity; sid:100001385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.90.159.188"; classtype:trojan-activity; sid:100001386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.124.78.15"; classtype:trojan-activity; sid:100001387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.13.150.74"; classtype:trojan-activity; sid:100001388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.162.20"; classtype:trojan-activity; sid:100001389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.173.160.185"; classtype:trojan-activity; sid:100001382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.200.22.163"; classtype:trojan-activity; sid:100001383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.81.134.72"; classtype:trojan-activity; sid:100001384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.90.159.188"; classtype:trojan-activity; sid:100001385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.124.78.15"; classtype:trojan-activity; sid:100001386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.13.150.74"; classtype:trojan-activity; sid:100001387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.162.20"; classtype:trojan-activity; sid:100001388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.47.204"; classtype:trojan-activity; sid:100001389; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.127.60"; classtype:trojan-activity; sid:100001390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.3.50"; classtype:trojan-activity; sid:100001391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.157.191.178"; classtype:trojan-activity; sid:100001392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.136.213"; classtype:trojan-activity; sid:100001393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.201.54.97"; classtype:trojan-activity; sid:100001394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.202.232.230"; classtype:trojan-activity; sid:100001395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.130.147"; classtype:trojan-activity; sid:100001396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.163.81"; classtype:trojan-activity; sid:100001397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.197.120"; classtype:trojan-activity; sid:100001398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.251.109"; classtype:trojan-activity; sid:100001399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.116.167"; classtype:trojan-activity; sid:100001400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.172.207"; classtype:trojan-activity; sid:100001401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.184.31"; classtype:trojan-activity; sid:100001402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.252.64"; classtype:trojan-activity; sid:100001403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.8.64"; classtype:trojan-activity; sid:100001404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.232.183.167"; classtype:trojan-activity; sid:100001405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.235.137.36"; classtype:trojan-activity; sid:100001406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.68.16"; classtype:trojan-activity; sid:100001407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.108.17.64"; classtype:trojan-activity; sid:100001408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.118.248.149"; classtype:trojan-activity; sid:100001409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.119.65.145"; classtype:trojan-activity; sid:100001410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.132.125.138"; classtype:trojan-activity; sid:100001411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.9.5"; classtype:trojan-activity; sid:100001412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.122.105"; classtype:trojan-activity; sid:100001413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.139.86"; classtype:trojan-activity; sid:100001414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.170.17"; classtype:trojan-activity; sid:100001415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.182.72"; classtype:trojan-activity; sid:100001391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.3.50"; classtype:trojan-activity; sid:100001392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.157.191.178"; classtype:trojan-activity; sid:100001393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.136.213"; classtype:trojan-activity; sid:100001394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.201.54.97"; classtype:trojan-activity; sid:100001395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.202.232.230"; classtype:trojan-activity; sid:100001396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.130.147"; classtype:trojan-activity; sid:100001397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.163.81"; classtype:trojan-activity; sid:100001398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.197.120"; classtype:trojan-activity; sid:100001399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.251.109"; classtype:trojan-activity; sid:100001400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.116.167"; classtype:trojan-activity; sid:100001401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.172.207"; classtype:trojan-activity; sid:100001402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.184.31"; classtype:trojan-activity; sid:100001403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.252.64"; classtype:trojan-activity; sid:100001404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.8.64"; classtype:trojan-activity; sid:100001405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.232.183.167"; classtype:trojan-activity; sid:100001406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.235.137.36"; classtype:trojan-activity; sid:100001407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.68.16"; classtype:trojan-activity; sid:100001408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.107.145.56"; classtype:trojan-activity; sid:100001409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.108.17.64"; classtype:trojan-activity; sid:100001410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.118.248.149"; classtype:trojan-activity; sid:100001411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.119.65.145"; classtype:trojan-activity; sid:100001412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.9.5"; classtype:trojan-activity; sid:100001413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.122.105"; classtype:trojan-activity; sid:100001414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.139.86"; classtype:trojan-activity; sid:100001415; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.72.66"; classtype:trojan-activity; sid:100001416; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.133.186"; classtype:trojan-activity; sid:100001417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.17.203"; classtype:trojan-activity; sid:100001418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.139.21.190"; classtype:trojan-activity; sid:100001419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.139.21.190"; classtype:trojan-activity; sid:100001418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.163.181"; classtype:trojan-activity; sid:100001419; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.17.245"; classtype:trojan-activity; sid:100001420; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.187.9.178"; classtype:trojan-activity; sid:100001421; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.211.72.66"; classtype:trojan-activity; sid:100001422; rev:1;) @@ -1445,9 +1445,9 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.24.213.121"; classtype:trojan-activity; sid:100001439; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.149.13"; classtype:trojan-activity; sid:100001440; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.21.167"; classtype:trojan-activity; sid:100001441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.92.213.108"; classtype:trojan-activity; sid:100001442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.94.190.101"; classtype:trojan-activity; sid:100001443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.95.122.24"; classtype:trojan-activity; sid:100001444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.94.190.101"; classtype:trojan-activity; sid:100001442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.95.122.24"; classtype:trojan-activity; sid:100001443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.95.122.25"; classtype:trojan-activity; sid:100001444; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.103.74.180"; classtype:trojan-activity; sid:100001445; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.11.141.134"; classtype:trojan-activity; sid:100001446; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.119.158.74"; classtype:trojan-activity; sid:100001447; rev:1;) @@ -1518,2510 +1518,2532 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.255.202"; classtype:trojan-activity; sid:100001512; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.66.112"; classtype:trojan-activity; sid:100001513; rev:1;) alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.84.74"; classtype:trojan-activity; sid:100001514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.214.37.129"; classtype:trojan-activity; sid:100001515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.139.242"; classtype:trojan-activity; sid:100001516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.190.172"; classtype:trojan-activity; sid:100001517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.212.209"; classtype:trojan-activity; sid:100001518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.253.149"; classtype:trojan-activity; sid:100001519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.71.243"; classtype:trojan-activity; sid:100001520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.98.242"; classtype:trojan-activity; sid:100001521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.144.66"; classtype:trojan-activity; sid:100001522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.225.28"; classtype:trojan-activity; sid:100001523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.227.95"; classtype:trojan-activity; sid:100001524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.234.98"; classtype:trojan-activity; sid:100001525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.191.58"; classtype:trojan-activity; sid:100001526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.135.3"; classtype:trojan-activity; sid:100001527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.132.71"; classtype:trojan-activity; sid:100001528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.151.83"; classtype:trojan-activity; sid:100001529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.160.112"; classtype:trojan-activity; sid:100001530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.176.72"; classtype:trojan-activity; sid:100001531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.83.244"; classtype:trojan-activity; sid:100001532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.20.66"; classtype:trojan-activity; sid:100001533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.249.0"; classtype:trojan-activity; sid:100001534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.83.170"; classtype:trojan-activity; sid:100001535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.85.168"; classtype:trojan-activity; sid:100001536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.221.239.223"; classtype:trojan-activity; sid:100001537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.221.242.95"; classtype:trojan-activity; sid:100001538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.76.80"; classtype:trojan-activity; sid:100001539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.223.242.164"; classtype:trojan-activity; sid:100001540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.129.198"; classtype:trojan-activity; sid:100001541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.154.13"; classtype:trojan-activity; sid:100001542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.212.124"; classtype:trojan-activity; sid:100001543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.58.5"; classtype:trojan-activity; sid:100001544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.40.120.108"; classtype:trojan-activity; sid:100001545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.40.73.175"; classtype:trojan-activity; sid:100001546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.36.97"; classtype:trojan-activity; sid:100001547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.45.90.246"; classtype:trojan-activity; sid:100001548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.44.190"; classtype:trojan-activity; sid:100001549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.0.98.131"; classtype:trojan-activity; sid:100001550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.11.51.57"; classtype:trojan-activity; sid:100001551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.13.23.180"; classtype:trojan-activity; sid:100001552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.124.130"; classtype:trojan-activity; sid:100001553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.146.199"; classtype:trojan-activity; sid:100001554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.179.83"; classtype:trojan-activity; sid:100001555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.184.59"; classtype:trojan-activity; sid:100001556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.191.243"; classtype:trojan-activity; sid:100001557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.194.67"; classtype:trojan-activity; sid:100001558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.216.132"; classtype:trojan-activity; sid:100001559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.219.28"; classtype:trojan-activity; sid:100001560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.24.115"; classtype:trojan-activity; sid:100001561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.30.65"; classtype:trojan-activity; sid:100001562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.65.233"; classtype:trojan-activity; sid:100001563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.79.66"; classtype:trojan-activity; sid:100001564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.94.16"; classtype:trojan-activity; sid:100001565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.179.201.26"; classtype:trojan-activity; sid:100001566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.195.84.250"; classtype:trojan-activity; sid:100001567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.138"; classtype:trojan-activity; sid:100001568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.28.7.159"; classtype:trojan-activity; sid:100001569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.30.119.23"; classtype:trojan-activity; sid:100001570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32.208.157.193"; classtype:trojan-activity; sid:100001571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32792.prolocksmithwinterpark.com"; classtype:trojan-activity; sid:100001572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"34.122.44.188"; classtype:trojan-activity; sid:100001573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"34.126.93.163"; classtype:trojan-activity; sid:100001574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"35.184.169.169"; classtype:trojan-activity; sid:100001575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.108.231.218"; classtype:trojan-activity; sid:100001576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.248.83.98"; classtype:trojan-activity; sid:100001577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.250.203.246"; classtype:trojan-activity; sid:100001578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.157.225"; classtype:trojan-activity; sid:100001579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.18.18"; classtype:trojan-activity; sid:100001580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.51.244"; classtype:trojan-activity; sid:100001581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.255.90.219"; classtype:trojan-activity; sid:100001582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.32.28.18"; classtype:trojan-activity; sid:100001583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.160.167"; classtype:trojan-activity; sid:100001584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.34.150.236"; classtype:trojan-activity; sid:100001585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.65.216.145"; classtype:trojan-activity; sid:100001586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.105.159"; classtype:trojan-activity; sid:100001587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.133.125"; classtype:trojan-activity; sid:100001588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.139.36"; classtype:trojan-activity; sid:100001589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.89.18.133"; classtype:trojan-activity; sid:100001590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.91.89.187"; classtype:trojan-activity; sid:100001591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360.lcy2zzx.pw"; classtype:trojan-activity; sid:100001592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360down7.miiyun.cn"; classtype:trojan-activity; sid:100001593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.222.98.51"; classtype:trojan-activity; sid:100001594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.233.60.68"; classtype:trojan-activity; sid:100001595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.179.221"; classtype:trojan-activity; sid:100001596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.180.172"; classtype:trojan-activity; sid:100001597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.44.238.35"; classtype:trojan-activity; sid:100001598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.116.243"; classtype:trojan-activity; sid:100001599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.14.36"; classtype:trojan-activity; sid:100001600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.245.254"; classtype:trojan-activity; sid:100001601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.98.136"; classtype:trojan-activity; sid:100001602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.114.137.102"; classtype:trojan-activity; sid:100001603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.115.0.100"; classtype:trojan-activity; sid:100001604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.117.31.162"; classtype:trojan-activity; sid:100001605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.162.104.119"; classtype:trojan-activity; sid:100001606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.162.98.216"; classtype:trojan-activity; sid:100001607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.164.112.139"; classtype:trojan-activity; sid:100001608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.196.34"; classtype:trojan-activity; sid:100001609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.104.83"; classtype:trojan-activity; sid:100001610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.125.186"; classtype:trojan-activity; sid:100001611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.146.60"; classtype:trojan-activity; sid:100001612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.206.228"; classtype:trojan-activity; sid:100001613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.171.125"; classtype:trojan-activity; sid:100001614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.249.255"; classtype:trojan-activity; sid:100001615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.60.61"; classtype:trojan-activity; sid:100001616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.167.202"; classtype:trojan-activity; sid:100001617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.67.64"; classtype:trojan-activity; sid:100001618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.10.198"; classtype:trojan-activity; sid:100001619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.163.231"; classtype:trojan-activity; sid:100001620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.168.234"; classtype:trojan-activity; sid:100001621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.203.225"; classtype:trojan-activity; sid:100001622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.215.212"; classtype:trojan-activity; sid:100001623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.194.65"; classtype:trojan-activity; sid:100001624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.78.251"; classtype:trojan-activity; sid:100001625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.113.201"; classtype:trojan-activity; sid:100001626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.114.45"; classtype:trojan-activity; sid:100001627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.150.203"; classtype:trojan-activity; sid:100001628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.123.189"; classtype:trojan-activity; sid:100001629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.166.31"; classtype:trojan-activity; sid:100001630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.218.46"; classtype:trojan-activity; sid:100001631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.91.244"; classtype:trojan-activity; sid:100001632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.93.171"; classtype:trojan-activity; sid:100001633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.127.214"; classtype:trojan-activity; sid:100001634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.18.140"; classtype:trojan-activity; sid:100001635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.191.137"; classtype:trojan-activity; sid:100001636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.205.255"; classtype:trojan-activity; sid:100001637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.24.54"; classtype:trojan-activity; sid:100001638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.36.151"; classtype:trojan-activity; sid:100001639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.37.182"; classtype:trojan-activity; sid:100001640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.251.0"; classtype:trojan-activity; sid:100001641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.27.15"; classtype:trojan-activity; sid:100001642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.29.231"; classtype:trojan-activity; sid:100001643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.70.88"; classtype:trojan-activity; sid:100001644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.83.185.108"; classtype:trojan-activity; sid:100001645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.83.94.11"; classtype:trojan-activity; sid:100001646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.115.152"; classtype:trojan-activity; sid:100001647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.85.54.4"; classtype:trojan-activity; sid:100001648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.211.20"; classtype:trojan-activity; sid:100001649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.234.187"; classtype:trojan-activity; sid:100001650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.78.244"; classtype:trojan-activity; sid:100001651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.93.109"; classtype:trojan-activity; sid:100001652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.96.227"; classtype:trojan-activity; sid:100001653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.143.176"; classtype:trojan-activity; sid:100001654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.233.131"; classtype:trojan-activity; sid:100001655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.67.238"; classtype:trojan-activity; sid:100001656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.72.9"; classtype:trojan-activity; sid:100001657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.145.11"; classtype:trojan-activity; sid:100001658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.36"; classtype:trojan-activity; sid:100001659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.63.23"; classtype:trojan-activity; sid:100001660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.90.86.212"; classtype:trojan-activity; sid:100001661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"40.88.2.151"; classtype:trojan-activity; sid:100001662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.139.209.46"; classtype:trojan-activity; sid:100001663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.165.130.43"; classtype:trojan-activity; sid:100001664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.190.63.174"; classtype:trojan-activity; sid:100001665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.193.192.100"; classtype:trojan-activity; sid:100001666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.219.185.171"; classtype:trojan-activity; sid:100001667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.226.60.115"; classtype:trojan-activity; sid:100001668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.147"; classtype:trojan-activity; sid:100001669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.152"; classtype:trojan-activity; sid:100001670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.204"; classtype:trojan-activity; sid:100001671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.19.146"; classtype:trojan-activity; sid:100001672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.19.206"; classtype:trojan-activity; sid:100001673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.28"; classtype:trojan-activity; sid:100001674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.60"; classtype:trojan-activity; sid:100001675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.198"; classtype:trojan-activity; sid:100001676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.202.101.181"; classtype:trojan-activity; sid:100001677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.202.101.199"; classtype:trojan-activity; sid:100001678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.176.27"; classtype:trojan-activity; sid:100001679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.40.143"; classtype:trojan-activity; sid:100001680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.60.114"; classtype:trojan-activity; sid:100001681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.161.72"; classtype:trojan-activity; sid:100001682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.212.157"; classtype:trojan-activity; sid:100001683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.238.141.250"; classtype:trojan-activity; sid:100001684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.56.15.227"; classtype:trojan-activity; sid:100001685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.61.99.155"; classtype:trojan-activity; sid:100001686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.82.217.241"; classtype:trojan-activity; sid:100001687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.230.207.204"; classtype:trojan-activity; sid:100001688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.241.106.183"; classtype:trojan-activity; sid:100001689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.252.8.94"; classtype:trojan-activity; sid:100001690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.203.192"; classtype:trojan-activity; sid:100001691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.135.134.228"; classtype:trojan-activity; sid:100001692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.178"; classtype:trojan-activity; sid:100001693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.182"; classtype:trojan-activity; sid:100001694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.204"; classtype:trojan-activity; sid:100001695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.224.165"; classtype:trojan-activity; sid:100001696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.141.84.184"; classtype:trojan-activity; sid:100001697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.118"; classtype:trojan-activity; sid:100001698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.135"; classtype:trojan-activity; sid:100001699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.213"; classtype:trojan-activity; sid:100001700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.27"; classtype:trojan-activity; sid:100001701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.47"; classtype:trojan-activity; sid:100001702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.94"; classtype:trojan-activity; sid:100001703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.248"; classtype:trojan-activity; sid:100001704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.109.205"; classtype:trojan-activity; sid:100001705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.110.146"; classtype:trojan-activity; sid:100001706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.130"; classtype:trojan-activity; sid:100001707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.22.209.58"; classtype:trojan-activity; sid:100001708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.229.53.148"; classtype:trojan-activity; sid:100001709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.27.253.137"; classtype:trojan-activity; sid:100001710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.51.104.59"; classtype:trojan-activity; sid:100001711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.85.90.131"; classtype:trojan-activity; sid:100001712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.9.148.37"; classtype:trojan-activity; sid:100001713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.92.108.35"; classtype:trojan-activity; sid:100001714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.95.169.143"; classtype:trojan-activity; sid:100001715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.95.169.147"; classtype:trojan-activity; sid:100001716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.95.169.153"; classtype:trojan-activity; sid:100001717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.172.75.231"; classtype:trojan-activity; sid:100001718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.182.173.247"; classtype:trojan-activity; sid:100001719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.20.63.218"; classtype:trojan-activity; sid:100001720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.214.27.4"; classtype:trojan-activity; sid:100001721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.214.35.50"; classtype:trojan-activity; sid:100001722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.236.65.83"; classtype:trojan-activity; sid:100001723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.24.130.254"; classtype:trojan-activity; sid:100001724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.241.120.165"; classtype:trojan-activity; sid:100001725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.243.179.115"; classtype:trojan-activity; sid:100001726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.249.33.79"; classtype:trojan-activity; sid:100001727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.25.242.211"; classtype:trojan-activity; sid:100001728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.118.86"; classtype:trojan-activity; sid:100001729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.86.128"; classtype:trojan-activity; sid:100001730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.97.76.242"; classtype:trojan-activity; sid:100001731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.145.152.26"; classtype:trojan-activity; sid:100001732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.151.23.172"; classtype:trojan-activity; sid:100001733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.157.97.71"; classtype:trojan-activity; sid:100001734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.16.131.51"; classtype:trojan-activity; sid:100001735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.21.202.98"; classtype:trojan-activity; sid:100001736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.46.231.38"; classtype:trojan-activity; sid:100001737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.162.113"; classtype:trojan-activity; sid:100001738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.87.36"; classtype:trojan-activity; sid:100001739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.143.43.93"; classtype:trojan-activity; sid:100001740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.156.35.166"; classtype:trojan-activity; sid:100001741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.158.201.200"; classtype:trojan-activity; sid:100001742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.158.201.218"; classtype:trojan-activity; sid:100001743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.20.121"; classtype:trojan-activity; sid:100001744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.21.3"; classtype:trojan-activity; sid:100001745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.174.182.99"; classtype:trojan-activity; sid:100001746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.170.49"; classtype:trojan-activity; sid:100001747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.178.183"; classtype:trojan-activity; sid:100001748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.179.129"; classtype:trojan-activity; sid:100001749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.14.122.233"; classtype:trojan-activity; sid:100001750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.188.62.111"; classtype:trojan-activity; sid:100001751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.95.226.154"; classtype:trojan-activity; sid:100001752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.115.174.106"; classtype:trojan-activity; sid:100001753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.121.91.255"; classtype:trojan-activity; sid:100001754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.247.83.66"; classtype:trojan-activity; sid:100001755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.252.47.29"; classtype:trojan-activity; sid:100001756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"51.89.77.2"; classtype:trojan-activity; sid:100001757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.114.136"; classtype:trojan-activity; sid:100001758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.180.122"; classtype:trojan-activity; sid:100001759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.114.246.26"; classtype:trojan-activity; sid:100001760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.162.92"; classtype:trojan-activity; sid:100001761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.174.4"; classtype:trojan-activity; sid:100001762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.125.191.4"; classtype:trojan-activity; sid:100001763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.126.247.118"; classtype:trojan-activity; sid:100001764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.141.122.109"; classtype:trojan-activity; sid:100001765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.166.120"; classtype:trojan-activity; sid:100001766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.200.124"; classtype:trojan-activity; sid:100001767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.218.67.253"; classtype:trojan-activity; sid:100001768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.22.212.107"; classtype:trojan-activity; sid:100001769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.226.129.29"; classtype:trojan-activity; sid:100001770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.230.89.42"; classtype:trojan-activity; sid:100001771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.237.125.4"; classtype:trojan-activity; sid:100001772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.238.42.192"; classtype:trojan-activity; sid:100001773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.240.147.97"; classtype:trojan-activity; sid:100001774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.241.78.55"; classtype:trojan-activity; sid:100001775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.242.91.219"; classtype:trojan-activity; sid:100001776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.73.208"; classtype:trojan-activity; sid:100001777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.75.128"; classtype:trojan-activity; sid:100001778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.80.36"; classtype:trojan-activity; sid:100001779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.252.176.140"; classtype:trojan-activity; sid:100001780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.253.15.184"; classtype:trojan-activity; sid:100001781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.51.219.200"; classtype:trojan-activity; sid:100001782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.153"; classtype:trojan-activity; sid:100001783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.39"; classtype:trojan-activity; sid:100001784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.0.211.161"; classtype:trojan-activity; sid:100001785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.102.168.189"; classtype:trojan-activity; sid:100001786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.126.26.220"; classtype:trojan-activity; sid:100001787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.202.3"; classtype:trojan-activity; sid:100001788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.214.4"; classtype:trojan-activity; sid:100001789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.237.51"; classtype:trojan-activity; sid:100001790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.246.125"; classtype:trojan-activity; sid:100001791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.173.135.51"; classtype:trojan-activity; sid:100001792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.175.63.177"; classtype:trojan-activity; sid:100001793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.23.114.97"; classtype:trojan-activity; sid:100001794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.26.181.228"; classtype:trojan-activity; sid:100001795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.30.12.254"; classtype:trojan-activity; sid:100001796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.60.117.163"; classtype:trojan-activity; sid:100001797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.13.61.12"; classtype:trojan-activity; sid:100001798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.122.57"; classtype:trojan-activity; sid:100001799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.216.23"; classtype:trojan-activity; sid:100001800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.233.94"; classtype:trojan-activity; sid:100001801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.6.112"; classtype:trojan-activity; sid:100001802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.100.83"; classtype:trojan-activity; sid:100001803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.111.39"; classtype:trojan-activity; sid:100001804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.206.246"; classtype:trojan-activity; sid:100001805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.218.31"; classtype:trojan-activity; sid:100001806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.220.167"; classtype:trojan-activity; sid:100001807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.254.178"; classtype:trojan-activity; sid:100001808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.83.55"; classtype:trojan-activity; sid:100001809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.214.85.149"; classtype:trojan-activity; sid:100001810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.177.196"; classtype:trojan-activity; sid:100001811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.86.208"; classtype:trojan-activity; sid:100001812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.220.159.240"; classtype:trojan-activity; sid:100001813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.15.104"; classtype:trojan-activity; sid:100001814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.39.88"; classtype:trojan-activity; sid:100001815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.4.72"; classtype:trojan-activity; sid:100001816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.51.127"; classtype:trojan-activity; sid:100001817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.60.174"; classtype:trojan-activity; sid:100001818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.8.81"; classtype:trojan-activity; sid:100001819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.254.36.135"; classtype:trojan-activity; sid:100001820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.10.121"; classtype:trojan-activity; sid:100001821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.8.43"; classtype:trojan-activity; sid:100001822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.146.108.150"; classtype:trojan-activity; sid:100001823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.91.194"; classtype:trojan-activity; sid:100001824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.247.224.66"; classtype:trojan-activity; sid:100001825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.101.143"; classtype:trojan-activity; sid:100001826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.241.252"; classtype:trojan-activity; sid:100001827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.57.40"; classtype:trojan-activity; sid:100001828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.9.166"; classtype:trojan-activity; sid:100001829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.98.43"; classtype:trojan-activity; sid:100001830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.99.161"; classtype:trojan-activity; sid:100001831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.117.152"; classtype:trojan-activity; sid:100001832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.249.58"; classtype:trojan-activity; sid:100001833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.74.236"; classtype:trojan-activity; sid:100001834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.103.56"; classtype:trojan-activity; sid:100001835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.180.67"; classtype:trojan-activity; sid:100001836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.181.7"; classtype:trojan-activity; sid:100001837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.57.96.116"; classtype:trojan-activity; sid:100001838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.170.60"; classtype:trojan-activity; sid:100001839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.73.220"; classtype:trojan-activity; sid:100001840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.61.218.23"; classtype:trojan-activity; sid:100001841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.65.172.121"; classtype:trojan-activity; sid:100001842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.0.22"; classtype:trojan-activity; sid:100001843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.104.46"; classtype:trojan-activity; sid:100001844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.110.59"; classtype:trojan-activity; sid:100001845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.195"; classtype:trojan-activity; sid:100001846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.255.60"; classtype:trojan-activity; sid:100001847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.45.130"; classtype:trojan-activity; sid:100001848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.98.144.75"; classtype:trojan-activity; sid:100001849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.1.98.131"; classtype:trojan-activity; sid:100001850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.141.73.58"; classtype:trojan-activity; sid:100001851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.131.205"; classtype:trojan-activity; sid:100001852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.143.46"; classtype:trojan-activity; sid:100001853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.31.126.33"; classtype:trojan-activity; sid:100001854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.149.66"; classtype:trojan-activity; sid:100001855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.43.207.148"; classtype:trojan-activity; sid:100001856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.90.165.236"; classtype:trojan-activity; sid:100001857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"63.245.122.93"; classtype:trojan-activity; sid:100001858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"64.233.154.99"; classtype:trojan-activity; sid:100001859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.125.128.196"; classtype:trojan-activity; sid:100001860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.26.155.131"; classtype:trojan-activity; sid:100001861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.35.61.255"; classtype:trojan-activity; sid:100001862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.108.199.144"; classtype:trojan-activity; sid:100001863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.57.55.210"; classtype:trojan-activity; sid:100001864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.74.7.197"; classtype:trojan-activity; sid:100001865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.91.21.31"; classtype:trojan-activity; sid:100001866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.97.181.196"; classtype:trojan-activity; sid:100001867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.245.151.203"; classtype:trojan-activity; sid:100001868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.8.138.101"; classtype:trojan-activity; sid:100001869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.83.49.234"; classtype:trojan-activity; sid:100001870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.84.138.165"; classtype:trojan-activity; sid:100001871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.148.103.248"; classtype:trojan-activity; sid:100001872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.174.182.226"; classtype:trojan-activity; sid:100001873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.175.107.153"; classtype:trojan-activity; sid:100001874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.188.144.143"; classtype:trojan-activity; sid:100001875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.204.88.29"; classtype:trojan-activity; sid:100001876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.119.241"; classtype:trojan-activity; sid:100001877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.78.33.33"; classtype:trojan-activity; sid:100001878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.115.37.205"; classtype:trojan-activity; sid:100001879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.120.237.255"; classtype:trojan-activity; sid:100001880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.123.245.151"; classtype:trojan-activity; sid:100001881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.124.231.110"; classtype:trojan-activity; sid:100001882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.127.214.47"; classtype:trojan-activity; sid:100001883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.146.232.34"; classtype:trojan-activity; sid:100001884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.165.173.49"; classtype:trojan-activity; sid:100001885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.196.158.227"; classtype:trojan-activity; sid:100001886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.222.157.166"; classtype:trojan-activity; sid:100001887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.229.0.133"; classtype:trojan-activity; sid:100001888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.63.73.234"; classtype:trojan-activity; sid:100001889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.115.194"; classtype:trojan-activity; sid:100001890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.227.186"; classtype:trojan-activity; sid:100001891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.76.240.206"; classtype:trojan-activity; sid:100001892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.115.31.30"; classtype:trojan-activity; sid:100001893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.118.240.88"; classtype:trojan-activity; sid:100001894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.167.10.180"; classtype:trojan-activity; sid:100001895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.236.190.250"; classtype:trojan-activity; sid:100001896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.25.5.105"; classtype:trojan-activity; sid:100001897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.93.129.118"; classtype:trojan-activity; sid:100001898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.127.148.69"; classtype:trojan-activity; sid:100001899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.146.190.91"; classtype:trojan-activity; sid:100001900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.204.63.239"; classtype:trojan-activity; sid:100001901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.34.191.213"; classtype:trojan-activity; sid:100001902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.40.234.166"; classtype:trojan-activity; sid:100001903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.106.142"; classtype:trojan-activity; sid:100001904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.2.122"; classtype:trojan-activity; sid:100001905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.235.106"; classtype:trojan-activity; sid:100001906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.47.133.58"; classtype:trojan-activity; sid:100001907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.71.60.69"; classtype:trojan-activity; sid:100001908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.85.106.211"; classtype:trojan-activity; sid:100001909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.17.22.30"; classtype:trojan-activity; sid:100001910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.180.98"; classtype:trojan-activity; sid:100001911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.200.62"; classtype:trojan-activity; sid:100001912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.202.249.109"; classtype:trojan-activity; sid:100001913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.214.69.226"; classtype:trojan-activity; sid:100001914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.229.230.118"; classtype:trojan-activity; sid:100001915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.31.40.122"; classtype:trojan-activity; sid:100001916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.112.123.203"; classtype:trojan-activity; sid:100001917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.204.216.103"; classtype:trojan-activity; sid:100001918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.31.139.77"; classtype:trojan-activity; sid:100001919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.70.164.42"; classtype:trojan-activity; sid:100001920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.101.1.159"; classtype:trojan-activity; sid:100001921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.108.224.112"; classtype:trojan-activity; sid:100001922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.195.115.176"; classtype:trojan-activity; sid:100001923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.199.84.77"; classtype:trojan-activity; sid:100001924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.64.139.223"; classtype:trojan-activity; sid:100001925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.75.165.81"; classtype:trojan-activity; sid:100001926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.127.141.52"; classtype:trojan-activity; sid:100001927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.99.213.61"; classtype:trojan-activity; sid:100001928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.170.11.82"; classtype:trojan-activity; sid:100001929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.178.22.145"; classtype:trojan-activity; sid:100001930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.217.92.231"; classtype:trojan-activity; sid:100001931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.250.199.133"; classtype:trojan-activity; sid:100001932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.254.129.227"; classtype:trojan-activity; sid:100001933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.84.134.33"; classtype:trojan-activity; sid:100001934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.89.107.69"; classtype:trojan-activity; sid:100001935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.95.12.137"; classtype:trojan-activity; sid:100001936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.111.182.31"; classtype:trojan-activity; sid:100001937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.237.25.210"; classtype:trojan-activity; sid:100001938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.50.153"; classtype:trojan-activity; sid:100001939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.89.203.238"; classtype:trojan-activity; sid:100001940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77st.net"; classtype:trojan-activity; sid:100001941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.138.98.134"; classtype:trojan-activity; sid:100001942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.145.224.45"; classtype:trojan-activity; sid:100001943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.141.144"; classtype:trojan-activity; sid:100001944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.41.200"; classtype:trojan-activity; sid:100001945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.106.235"; classtype:trojan-activity; sid:100001946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.168.64"; classtype:trojan-activity; sid:100001947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.188.141"; classtype:trojan-activity; sid:100001948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.104.157"; classtype:trojan-activity; sid:100001949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.176.163"; classtype:trojan-activity; sid:100001950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.27.157"; classtype:trojan-activity; sid:100001951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.23.172.81"; classtype:trojan-activity; sid:100001952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.8.225.77"; classtype:trojan-activity; sid:100001953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.11.195.121"; classtype:trojan-activity; sid:100001954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.147.123.48"; classtype:trojan-activity; sid:100001955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.175.42.244"; classtype:trojan-activity; sid:100001956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.21.84.63"; classtype:trojan-activity; sid:100001957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.7.170.58"; classtype:trojan-activity; sid:100001958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.79.58.94"; classtype:trojan-activity; sid:100001959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.8.70.162"; classtype:trojan-activity; sid:100001960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.9.88.185"; classtype:trojan-activity; sid:100001961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.107.89.207"; classtype:trojan-activity; sid:100001962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.19.101.218"; classtype:trojan-activity; sid:100001963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.211.181.77"; classtype:trojan-activity; sid:100001964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.217.12.7"; classtype:trojan-activity; sid:100001965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.99.128.61"; classtype:trojan-activity; sid:100001966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.136.146.213"; classtype:trojan-activity; sid:100001967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.165.44.109"; classtype:trojan-activity; sid:100001968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.191.40.58"; classtype:trojan-activity; sid:100001969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.198.7.22"; classtype:trojan-activity; sid:100001970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.141.184"; classtype:trojan-activity; sid:100001971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.215.199.29"; classtype:trojan-activity; sid:100001972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.187.113"; classtype:trojan-activity; sid:100001973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.195.216"; classtype:trojan-activity; sid:100001974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.229.230.103"; classtype:trojan-activity; sid:100001975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.244.219.41"; classtype:trojan-activity; sid:100001976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.246.225.203"; classtype:trojan-activity; sid:100001977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.30.177.68"; classtype:trojan-activity; sid:100001978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.92.36.96"; classtype:trojan-activity; sid:100001979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.103.108.72"; classtype:trojan-activity; sid:100001980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.135.196.130"; classtype:trojan-activity; sid:100001981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.212.178"; classtype:trojan-activity; sid:100001982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.85.112"; classtype:trojan-activity; sid:100001983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.207.61.194"; classtype:trojan-activity; sid:100001984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.209.250.155"; classtype:trojan-activity; sid:100001985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.211.156.38"; classtype:trojan-activity; sid:100001986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.59.31.181"; classtype:trojan-activity; sid:100001987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.110.252"; classtype:trojan-activity; sid:100001988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.53.77"; classtype:trojan-activity; sid:100001989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.138.72"; classtype:trojan-activity; sid:100001990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.139.92"; classtype:trojan-activity; sid:100001991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.154.214"; classtype:trojan-activity; sid:100001992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.187.109"; classtype:trojan-activity; sid:100001993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.100.54"; classtype:trojan-activity; sid:100001994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.102.84"; classtype:trojan-activity; sid:100001995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.106.65"; classtype:trojan-activity; sid:100001996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.108.172"; classtype:trojan-activity; sid:100001997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.131.158"; classtype:trojan-activity; sid:100001998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.134.66"; classtype:trojan-activity; sid:100001999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.19.42"; classtype:trojan-activity; sid:100002000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.197.254"; classtype:trojan-activity; sid:100002001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.215.149"; classtype:trojan-activity; sid:100002002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.232.68"; classtype:trojan-activity; sid:100002003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.234.195"; classtype:trojan-activity; sid:100002004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.246.96"; classtype:trojan-activity; sid:100002005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.28.57"; classtype:trojan-activity; sid:100002006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.4.57"; classtype:trojan-activity; sid:100002007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.55.84"; classtype:trojan-activity; sid:100002008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.73.245"; classtype:trojan-activity; sid:100002009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.98.51"; classtype:trojan-activity; sid:100002010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.165.237.163"; classtype:trojan-activity; sid:100002011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.147.99"; classtype:trojan-activity; sid:100002012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.218.42"; classtype:trojan-activity; sid:100002013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.242.253.154"; classtype:trojan-activity; sid:100002014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.252.9.37"; classtype:trojan-activity; sid:100002015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.210.219.213"; classtype:trojan-activity; sid:100002016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.50.118"; classtype:trojan-activity; sid:100002017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.95.204"; classtype:trojan-activity; sid:100002018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.238.24.35"; classtype:trojan-activity; sid:100002019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.247.83.74"; classtype:trojan-activity; sid:100002020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.254.39.129"; classtype:trojan-activity; sid:100002021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.33.111.227"; classtype:trojan-activity; sid:100002022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.40.127.242"; classtype:trojan-activity; sid:100002023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.42.20.217"; classtype:trojan-activity; sid:100002024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; classtype:trojan-activity; sid:100002025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.11.216"; classtype:trojan-activity; sid:100002026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.123.251"; classtype:trojan-activity; sid:100002027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.135.187"; classtype:trojan-activity; sid:100002028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.180.33"; classtype:trojan-activity; sid:100002029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.208.25"; classtype:trojan-activity; sid:100002030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.224.141"; classtype:trojan-activity; sid:100002031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.241.2"; classtype:trojan-activity; sid:100002032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.108.133.19"; classtype:trojan-activity; sid:100002033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.214.149.236"; classtype:trojan-activity; sid:100002034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.241.39.182"; classtype:trojan-activity; sid:100002035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.64.181.50"; classtype:trojan-activity; sid:100002036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.74.215.180"; classtype:trojan-activity; sid:100002037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.130.227"; classtype:trojan-activity; sid:100002038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"86.35.43.220"; classtype:trojan-activity; sid:100002039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.172.19.130"; classtype:trojan-activity; sid:100002040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87du.vip"; classtype:trojan-activity; sid:100002041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.119.171.253"; classtype:trojan-activity; sid:100002042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.129.208.43"; classtype:trojan-activity; sid:100002043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.208.71"; classtype:trojan-activity; sid:100002044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.219.179"; classtype:trojan-activity; sid:100002045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.218.17.149"; classtype:trojan-activity; sid:100002046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.225.222.128"; classtype:trojan-activity; sid:100002047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.247.96.19"; classtype:trojan-activity; sid:100002048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.51.139"; classtype:trojan-activity; sid:100002049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.249.13.164"; classtype:trojan-activity; sid:100002050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.249.244.180"; classtype:trojan-activity; sid:100002051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.204.12"; classtype:trojan-activity; sid:100002052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.226.26"; classtype:trojan-activity; sid:100002053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.240.245"; classtype:trojan-activity; sid:100002054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.254.90"; classtype:trojan-activity; sid:100002055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.122.183.130"; classtype:trojan-activity; sid:100002056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.136.197.170"; classtype:trojan-activity; sid:100002057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.22.152.244"; classtype:trojan-activity; sid:100002058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.237.84.19"; classtype:trojan-activity; sid:100002059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.248.112.202"; classtype:trojan-activity; sid:100002060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.29.213.33"; classtype:trojan-activity; sid:100002061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.85.166"; classtype:trojan-activity; sid:100002062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.87.5"; classtype:trojan-activity; sid:100002063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8poieq.bn.files.1drv.com"; classtype:trojan-activity; sid:100002064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"90.152.144.139"; classtype:trojan-activity; sid:100002065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.132.197.39"; classtype:trojan-activity; sid:100002066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.138.215.5"; classtype:trojan-activity; sid:100002067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.177.139.132"; classtype:trojan-activity; sid:100002068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.187.103.32"; classtype:trojan-activity; sid:100002069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.212.150.241"; classtype:trojan-activity; sid:100002070; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.217.104.185"; classtype:trojan-activity; sid:100002071; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.233.112.188"; classtype:trojan-activity; sid:100002072; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.234.60.94"; classtype:trojan-activity; sid:100002073; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.244.169.139"; classtype:trojan-activity; sid:100002074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.92.16.244"; classtype:trojan-activity; sid:100002075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.114.191.82"; classtype:trojan-activity; sid:100002076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.241.78.114"; classtype:trojan-activity; sid:100002077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.27.246.202"; classtype:trojan-activity; sid:100002078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.54.237.237"; classtype:trojan-activity; sid:100002079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.83.62.139"; classtype:trojan-activity; sid:100002080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.85.18.138"; classtype:trojan-activity; sid:100002081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.159.169.190"; classtype:trojan-activity; sid:100002082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.173.235.110"; classtype:trojan-activity; sid:100002083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.21.224.154"; classtype:trojan-activity; sid:100002084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.39.115.176"; classtype:trojan-activity; sid:100002085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.39.79.41"; classtype:trojan-activity; sid:100002086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.137.16"; classtype:trojan-activity; sid:100002087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.182.249"; classtype:trojan-activity; sid:100002088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.206.56"; classtype:trojan-activity; sid:100002089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.57.43.233"; classtype:trojan-activity; sid:100002090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.73.99.102"; classtype:trojan-activity; sid:100002091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.136.69.199"; classtype:trojan-activity; sid:100002092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.143.53.34"; classtype:trojan-activity; sid:100002093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.17.170"; classtype:trojan-activity; sid:100002094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.200.16.22"; classtype:trojan-activity; sid:100002095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.224.83.208"; classtype:trojan-activity; sid:100002096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.53.120.109"; classtype:trojan-activity; sid:100002097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.85.0.3"; classtype:trojan-activity; sid:100002098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.132.129.250"; classtype:trojan-activity; sid:100002099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.133.158.20"; classtype:trojan-activity; sid:100002100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.154.20.231"; classtype:trojan-activity; sid:100002101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.158.19.130"; classtype:trojan-activity; sid:100002102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.113.227"; classtype:trojan-activity; sid:100002103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.201.34"; classtype:trojan-activity; sid:100002104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.60.146.134"; classtype:trojan-activity; sid:100002105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.66.196.63"; classtype:trojan-activity; sid:100002106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.9.111.51"; classtype:trojan-activity; sid:100002107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.9.120.40"; classtype:trojan-activity; sid:100002108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.239.73.246"; classtype:trojan-activity; sid:100002109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.47.147.169"; classtype:trojan-activity; sid:100002110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.68.140.254"; classtype:trojan-activity; sid:100002111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.96.199.75"; classtype:trojan-activity; sid:100002112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.0.210.218"; classtype:trojan-activity; sid:100002113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.113.239.207"; classtype:trojan-activity; sid:100002114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.116.72.119"; classtype:trojan-activity; sid:100002115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.128.147.115"; classtype:trojan-activity; sid:100002116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.178.242.44"; classtype:trojan-activity; sid:100002117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.30.24.54"; classtype:trojan-activity; sid:100002118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.150.245.203"; classtype:trojan-activity; sid:100002119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.33.195.164"; classtype:trojan-activity; sid:100002120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"a.stro.lo.gy.t.em.r@zytrox.tk"; classtype:trojan-activity; sid:100002121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aatreefelling.co.za"; classtype:trojan-activity; sid:100002122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abcd.bg"; classtype:trojan-activity; sid:100002123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abissnet.net"; classtype:trojan-activity; sid:100002124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aboveandbelow.com.au"; classtype:trojan-activity; sid:100002125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absoftechworld.com"; classtype:trojan-activity; sid:100002126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abyssos.eu"; classtype:trojan-activity; sid:100002127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"academyshademani.com"; classtype:trojan-activity; sid:100002128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acbick.com"; classtype:trojan-activity; sid:100002129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"accesslinksgroup.com"; classtype:trojan-activity; sid:100002130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acellr.co.uk"; classtype:trojan-activity; sid:100002131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acteon.com.ar"; classtype:trojan-activity; sid:100002132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"addahealingmusic.com"; classtype:trojan-activity; sid:100002133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.com"; classtype:trojan-activity; sid:100002134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.memengers.com"; classtype:trojan-activity; sid:100002135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.erapor.smk-alasror.net"; classtype:trojan-activity; sid:100002136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.gentbcn.org"; classtype:trojan-activity; sid:100002137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.grandoceanvilla.com"; classtype:trojan-activity; sid:100002138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admission.kmctartskuttippuram.org"; classtype:trojan-activity; sid:100002139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adventureexplorer.in"; classtype:trojan-activity; sid:100002140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aeropilates.cl"; classtype:trojan-activity; sid:100002141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afnan-amc.com"; classtype:trojan-activity; sid:100002142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afrimedspecialist.com"; classtype:trojan-activity; sid:100002143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agemn.co.za"; classtype:trojan-activity; sid:100002144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenciadigitalwdys.com"; classtype:trojan-activity; sid:100002145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenda.gmelloinformatica.com.br"; classtype:trojan-activity; sid:100002146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agentt.ac.ug"; classtype:trojan-activity; sid:100002147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agile8studio.com"; classtype:trojan-activity; sid:100002148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aiecons.com"; classtype:trojan-activity; sid:100002149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aiqtest.com"; classtype:trojan-activity; sid:100002150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajpharmaholding.com"; classtype:trojan-activity; sid:100002151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"akdvidyalaya.com"; classtype:trojan-activity; sid:100002152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alasdemariposas.org"; classtype:trojan-activity; sid:100002153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alberts.diamondrelationscrm.us"; classtype:trojan-activity; sid:100002154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alemelektronik.com"; classtype:trojan-activity; sid:100002155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alena1971.es"; classtype:trojan-activity; sid:100002156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alexdubai.com.aldiabsteel.com"; classtype:trojan-activity; sid:100002157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alka.institute"; classtype:trojan-activity; sid:100002158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"allforcreative.com.au"; classtype:trojan-activity; sid:100002159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alltheway.travel"; classtype:trojan-activity; sid:100002160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alpaylar.com.tr"; classtype:trojan-activity; sid:100002161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alumni.hildred.ibbott@46.249.33.79"; classtype:trojan-activity; sid:100002162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"am-concepts.ca"; classtype:trojan-activity; sid:100002163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarresdeamorymaestroshechiceros.com"; classtype:trojan-activity; sid:100002164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarteargentina.com.ar"; classtype:trojan-activity; sid:100002165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amos524.org"; classtype:trojan-activity; sid:100002166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ams.alvinasschools.org.ng"; classtype:trojan-activity; sid:100002167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anadelgbt.org"; classtype:trojan-activity; sid:100002168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anantam.net.in"; classtype:trojan-activity; sid:100002169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreelapeyre.com"; classtype:trojan-activity; sid:100002170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andremaraisbeleggings.co.za"; classtype:trojan-activity; sid:100002171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ac.ug"; classtype:trojan-activity; sid:100002172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ug"; classtype:trojan-activity; sid:100002173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreshconcejal.solucioneslink.com"; classtype:trojan-activity; sid:100002174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelsdetour.com"; classtype:trojan-activity; sid:100002175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anurontv.com"; classtype:trojan-activity; sid:100002176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anysbergbiltong.co.za"; classtype:trojan-activity; sid:100002177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apartamentoscitta.com"; classtype:trojan-activity; sid:100002178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api-ms.cobainaja.id"; classtype:trojan-activity; sid:100002179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.cstdevs.com"; classtype:trojan-activity; sid:100002180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apoolcondo.com"; classtype:trojan-activity; sid:100002181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.adsensearticle.com"; classtype:trojan-activity; sid:100002182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.explicitsurveys.co.uk"; classtype:trojan-activity; sid:100002183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.prerana.info"; classtype:trojan-activity; sid:100002184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apps.saintsoporte.com"; classtype:trojan-activity; sid:100002185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aps-scribe.com"; classtype:trojan-activity; sid:100002186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aps-sv.com"; classtype:trojan-activity; sid:100002187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"artedibujoyarquitectura.com"; classtype:trojan-activity; sid:100002188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"arwenyapi.com"; classtype:trojan-activity; sid:100002189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ask-regard.call-save.biz"; classtype:trojan-activity; sid:100002190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"asucssa.live"; classtype:trojan-activity; sid:100002191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atfile.com"; classtype:trojan-activity; sid:100002192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"athenacapsg.com"; classtype:trojan-activity; sid:100002193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atlasconcreteworks.com"; classtype:trojan-activity; sid:100002194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"attach.66rpg.com"; classtype:trojan-activity; sid:100002195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atteuqpotentialunlimited.com"; classtype:trojan-activity; sid:100002196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"augustair.com"; classtype:trojan-activity; sid:100002197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aulist.com"; classtype:trojan-activity; sid:100002198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"australianpga.com.au"; classtype:trojan-activity; sid:100002199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"automaticrefreshments.com"; classtype:trojan-activity; sid:100002200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"avadhanagames.com"; classtype:trojan-activity; sid:100002201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aventuramotorhome.com"; classtype:trojan-activity; sid:100002202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ayahuascasp.com.br"; classtype:trojan-activity; sid:100002203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ayamallah.com"; classtype:trojan-activity; sid:100002204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aycconsultoriaempresarial.com"; classtype:trojan-activity; sid:100002205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azmeasurement.com"; classtype:trojan-activity; sid:100002206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azraktours.com"; classtype:trojan-activity; sid:100002207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"b.r.uce.lee.b.es.t@zytrox.tk"; classtype:trojan-activity; sid:100002208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"b2b.toptanakaryakit.com.tr"; classtype:trojan-activity; sid:100002209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"backgrounds.pk"; classtype:trojan-activity; sid:100002210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"badeggdesign.com"; classtype:trojan-activity; sid:100002211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"balealgodon.mx"; classtype:trojan-activity; sid:100002212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bangkok-orchids.com"; classtype:trojan-activity; sid:100002213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bangladeshunbound.com"; classtype:trojan-activity; sid:100002214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bary.sz4h.com"; classtype:trojan-activity; sid:100002215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bash.givemexyz.in"; classtype:trojan-activity; sid:100002216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; classtype:trojan-activity; sid:100002217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bavhome.com"; classtype:trojan-activity; sid:100002218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bbia.co.uk"; classtype:trojan-activity; sid:100002219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcmt.elin.co.za"; classtype:trojan-activity; sid:100002220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcrg.co.za"; classtype:trojan-activity; sid:100002221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bdnextrend.xyz"; classtype:trojan-activity; sid:100002222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beanx88.xyz"; classtype:trojan-activity; sid:100002223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bearcatpumps.com.cn"; classtype:trojan-activity; sid:100002224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beautincollagen.rs"; classtype:trojan-activity; sid:100002225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beautymomentsgt.de"; classtype:trojan-activity; sid:100002226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bekape.co.id"; classtype:trojan-activity; sid:100002227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beor360.com"; classtype:trojan-activity; sid:100002228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bespokeweddings.ie"; classtype:trojan-activity; sid:100002229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bestcarenepal.com"; classtype:trojan-activity; sid:100002230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betone.co.kr"; classtype:trojan-activity; sid:100002231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betycopaints.com"; classtype:trojan-activity; sid:100002232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beveragesmiami.solucioneslink.com"; classtype:trojan-activity; sid:100002233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bhavaniengineering.com"; classtype:trojan-activity; sid:100002234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bigmikesupplies.co.za"; classtype:trojan-activity; sid:100002235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilbosaquet.ug"; classtype:trojan-activity; sid:100002236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilhen.co.za"; classtype:trojan-activity; sid:100002237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"billing.rahitechnosoft.com"; classtype:trojan-activity; sid:100002238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"binoy.stalphonsamissionva.org"; classtype:trojan-activity; sid:100002239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"biometrico.gpotecnosystems.com"; classtype:trojan-activity; sid:100002240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bioskey.com"; classtype:trojan-activity; sid:100002241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birdi.elin.co.za"; classtype:trojan-activity; sid:100002242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birminghamlink.org"; classtype:trojan-activity; sid:100002243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bizztradingbot.nl"; classtype:trojan-activity; sid:100002244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bl4n3.zadns.co.za"; classtype:trojan-activity; sid:100002245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.callensaxen.com"; classtype:trojan-activity; sid:100002246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.difusodesign.com"; classtype:trojan-activity; sid:100002247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.oyinblogs.com"; classtype:trojan-activity; sid:100002248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.takbelit.com"; classtype:trojan-activity; sid:100002249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bmlifestyle.co.uk"; classtype:trojan-activity; sid:100002250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"boatpecas.com.br"; classtype:trojan-activity; sid:100002251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bodenstein.co.za"; classtype:trojan-activity; sid:100002252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bodylanguage.santulan.co.in"; classtype:trojan-activity; sid:100002253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"booksearch.com"; classtype:trojan-activity; sid:100002254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bophelocare.co.za"; classtype:trojan-activity; sid:100002255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bounces.mi-fs.com"; classtype:trojan-activity; sid:100002256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"boutiqueofferte.com"; classtype:trojan-activity; sid:100002257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bpo.correct.go.th"; classtype:trojan-activity; sid:100002258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bradleyinstitute.co.za"; classtype:trojan-activity; sid:100002259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brandtrust.com.pk"; classtype:trojan-activity; sid:100002260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"braunfinancial.com.au"; classtype:trojan-activity; sid:100002261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brendanquine.com"; classtype:trojan-activity; sid:100002262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brideofmessiah.com"; classtype:trojan-activity; sid:100002263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightaffiliatesales.org"; classtype:trojan-activity; sid:100002264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightmega.com"; classtype:trojan-activity; sid:100002265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightstarshop.com"; classtype:trojan-activity; sid:100002266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"browardinsurancemiami.solucioneslink.com"; classtype:trojan-activity; sid:100002267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bt2.elin.co.za"; classtype:trojan-activity; sid:100002268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"btdapi.robotake.com"; classtype:trojan-activity; sid:100002269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buigiaphat.com.vn"; classtype:trojan-activity; sid:100002270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bullseyemedia.in"; classtype:trojan-activity; sid:100002271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"busandvanrentalmalaysia.com"; classtype:trojan-activity; sid:100002272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buscascolegios.diit.cl"; classtype:trojan-activity; sid:100002273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"business.softberg.ro"; classtype:trojan-activity; sid:100002274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"business2.softberg.ro"; classtype:trojan-activity; sid:100002275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c.ompact.i.o.np.d.yu@zytrox.tk"; classtype:trojan-activity; sid:100002276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c.oooooooooo.ga"; classtype:trojan-activity; sid:100002277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c0140529.ferozo.com"; classtype:trojan-activity; sid:100002278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"caballo.com.au"; classtype:trojan-activity; sid:100002279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cacaoprojects.com"; classtype:trojan-activity; sid:100002280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"calgaryautorepairservice.com"; classtype:trojan-activity; sid:100002281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"callbury.in"; classtype:trojan-activity; sid:100002282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"camminachetipassa.it"; classtype:trojan-activity; sid:100002283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"canadianwork.cc"; classtype:trojan-activity; sid:100002284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capitalgroup-kw.com"; classtype:trojan-activity; sid:100002285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capoeiraventrelivre.com"; classtype:trojan-activity; sid:100002286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cashyinvestment.org"; classtype:trojan-activity; sid:100002287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"catchpoolshetlands.co.uk"; classtype:trojan-activity; sid:100002288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cazyacustomfurniture.com"; classtype:trojan-activity; sid:100002289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cbn.hypervoizd.com"; classtype:trojan-activity; sid:100002290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ccauthority.net"; classtype:trojan-activity; sid:100002291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cdaonline.com.ar"; classtype:trojan-activity; sid:100002292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cdn-10049480.file.myqcloud.com"; classtype:trojan-activity; sid:100002293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cec.asso.ac-amiens.fr"; classtype:trojan-activity; sid:100002294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cellas.sk"; classtype:trojan-activity; sid:100002295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cendekiabinaaksara.com"; classtype:trojan-activity; sid:100002296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cfs5.tistory.com"; classtype:trojan-activity; sid:100002297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ch.rmu.ac.th"; classtype:trojan-activity; sid:100002298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"changematterscounselling.com"; classtype:trojan-activity; sid:100002299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chardhamdodham.com"; classtype:trojan-activity; sid:100002300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chezalice.co.za"; classtype:trojan-activity; sid:100002301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"childselect.com"; classtype:trojan-activity; sid:100002302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile.myvnc.com"; classtype:trojan-activity; sid:100002303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile80.myvnc.com"; classtype:trojan-activity; sid:100002304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cible-energy.com"; classtype:trojan-activity; sid:100002305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cifeer.net"; classtype:trojan-activity; sid:100002306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citihits.lk"; classtype:trojan-activity; sid:100002307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citssolutions.co.za"; classtype:trojan-activity; sid:100002308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citycapproperty.ru"; classtype:trojan-activity; sid:100002309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cityglobalgospel.com"; classtype:trojan-activity; sid:100002310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"civi.istmejia.com"; classtype:trojan-activity; sid:100002311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cleanbydesignllc.com"; classtype:trojan-activity; sid:100002312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cloud.fc.co.mz"; classtype:trojan-activity; sid:100002313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cnc.tacobelllover.tk"; classtype:trojan-activity; sid:100002314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"codsambal.com"; classtype:trojan-activity; sid:100002315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colinde.pricesne.com"; classtype:trojan-activity; sid:100002316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colorpak.pl"; classtype:trojan-activity; sid:100002317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"community.reimclub.com"; classtype:trojan-activity; sid:100002318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"competancy.indigoconsult.net"; classtype:trojan-activity; sid:100002319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"conceptimagine.ro"; classtype:trojan-activity; sid:100002320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"config.cqhbkjzx.com"; classtype:trojan-activity; sid:100002321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"connectcapital.com.br"; classtype:trojan-activity; sid:100002322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"constructoralyon.com"; classtype:trojan-activity; sid:100002323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"consulateins.solucioneslink.com"; classtype:trojan-activity; sid:100002324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"contributeindustry.com"; classtype:trojan-activity; sid:100002325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"copelandscapes.com"; classtype:trojan-activity; sid:100002326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"coulsongraphics.com"; classtype:trojan-activity; sid:100002327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"count.mail.163.com.impactmedfoundation.com"; classtype:trojan-activity; sid:100002328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"covid19.cyberschool.or.id"; classtype:trojan-activity; sid:100002329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cr-sq.com"; classtype:trojan-activity; sid:100002330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"craftech.nxtnet.ga"; classtype:trojan-activity; sid:100002331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crearechile.cl"; classtype:trojan-activity; sid:100002332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"creationskateboards.com"; classtype:trojan-activity; sid:100002333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crecerco.com"; classtype:trojan-activity; sid:100002334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crittersbythebay.com"; classtype:trojan-activity; sid:100002335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crm.notariavieitoyvelamazan.com"; classtype:trojan-activity; sid:100002336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crmfarko.manivelasst.com"; classtype:trojan-activity; sid:100002337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crmroche.manivelasst.com"; classtype:trojan-activity; sid:100002338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crscorretordeimoveis.com.br"; classtype:trojan-activity; sid:100002339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cse-engineer.com"; classtype:trojan-activity; sid:100002340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"csnserver.com"; classtype:trojan-activity; sid:100002341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cubescargoexpress.com"; classtype:trojan-activity; sid:100002342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"curasoles.co.za"; classtype:trojan-activity; sid:100002343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"currantmedia.com"; classtype:trojan-activity; sid:100002344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cwa.mx"; classtype:trojan-activity; sid:100002345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cyclomove.com"; classtype:trojan-activity; sid:100002346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cynkon.kairoscs.net"; classtype:trojan-activity; sid:100002347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"czsl.91756.cn"; classtype:trojan-activity; sid:100002348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d.powerofwish.com"; classtype:trojan-activity; sid:100002349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d9.99ddd.com"; classtype:trojan-activity; sid:100002350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"da.alibuf.com"; classtype:trojan-activity; sid:100002351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"danaevara.com"; classtype:trojan-activity; sid:100002352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dartoonpictures.com"; classtype:trojan-activity; sid:100002353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.cdevelop.org"; classtype:trojan-activity; sid:100002354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.over-blog-kiwi.com"; classtype:trojan-activity; sid:100002355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datapolish.com"; classtype:trojan-activity; sid:100002356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dating.khokhas.co.za"; classtype:trojan-activity; sid:100002357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datsom.vn"; classtype:trojan-activity; sid:100002358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davethompson.me.uk"; classtype:trojan-activity; sid:100002359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davidmcguinness.info"; classtype:trojan-activity; sid:100002360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dayspringdaisies.com"; classtype:trojan-activity; sid:100002361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dd.qiyuea.cn"; classtype:trojan-activity; sid:100002362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"de.gsearch.com.de"; classtype:trojan-activity; sid:100002363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"decifrar.com.br"; classtype:trojan-activity; sid:100002364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"deigratia2.elin.co.za"; classtype:trojan-activity; sid:100002365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dekovizyon.com"; classtype:trojan-activity; sid:100002366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo-cliente.mindcreative.com.br"; classtype:trojan-activity; sid:100002367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo.glassforcars.com.au"; classtype:trojan-activity; sid:100002368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo6.hiites.com"; classtype:trojan-activity; sid:100002369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dent-estet.com"; classtype:trojan-activity; sid:100002370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dental.xiaoxiao.media"; classtype:trojan-activity; sid:100002371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dentalalliance.se"; classtype:trojan-activity; sid:100002372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"desertlandtrd.com"; classtype:trojan-activity; sid:100002373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"designerliving.co.za"; classtype:trojan-activity; sid:100002374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"despertaresi.com.br"; classtype:trojan-activity; sid:100002375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"destinymc.co.za"; classtype:trojan-activity; sid:100002376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"detorre.es"; classtype:trojan-activity; sid:100002377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.sebpo.net"; classtype:trojan-activity; sid:100002378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.watch-store.eu"; classtype:trojan-activity; sid:100002379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dezcom.com"; classtype:trojan-activity; sid:100002380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfcf.91756.cn"; classtype:trojan-activity; sid:100002381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"diamantenegro.mi-fs.com"; classtype:trojan-activity; sid:100002382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dienmayminhhung.com"; classtype:trojan-activity; sid:100002383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"digilib.dianhusada.ac.id"; classtype:trojan-activity; sid:100002384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"digisails.org"; classtype:trojan-activity; sid:100002385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"disinfection-cleaning.co.za"; classtype:trojan-activity; sid:100002386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"djking.f3322.net"; classtype:trojan-activity; sid:100002387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.1003b.56a.com"; classtype:trojan-activity; sid:100002388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.198424.com"; classtype:trojan-activity; sid:100002389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.installcdn-aws.com"; classtype:trojan-activity; sid:100002390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.packetstormsecurity.net"; classtype:trojan-activity; sid:100002391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.rina-roleplay.com"; classtype:trojan-activity; sid:100002392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dnn.alibuf.com"; classtype:trojan-activity; sid:100002393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dns.alibuf.com"; classtype:trojan-activity; sid:100002394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dockerupdate.anondns.net"; classtype:trojan-activity; sid:100002395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"docman.orientalservices.in"; classtype:trojan-activity; sid:100002396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dodsonimaging.com"; classtype:trojan-activity; sid:100002397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"doitunlimited.com"; classtype:trojan-activity; sid:100002398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dokan.blueberrytec.com"; classtype:trojan-activity; sid:100002399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom.daf.free.fr"; classtype:trojan-activity; sid:100002400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"doncedyhall.com"; classtype:trojan-activity; sid:100002401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donghobinhminh.com"; classtype:trojan-activity; sid:100002402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dongphuctop.com"; classtype:trojan-activity; sid:100002403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosman.pl"; classtype:trojan-activity; sid:100002404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dovberger.com"; classtype:trojan-activity; sid:100002405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.pcclear.com"; classtype:trojan-activity; sid:100002406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.udashi.com"; classtype:trojan-activity; sid:100002407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.webbora.com"; classtype:trojan-activity; sid:100002408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down1.arpun.com"; classtype:trojan-activity; sid:100002409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.caihong.com"; classtype:trojan-activity; sid:100002410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.doumaibiji.cn"; classtype:trojan-activity; sid:100002411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.exrnybuf.cn"; classtype:trojan-activity; sid:100002412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.kaobeitu.com"; classtype:trojan-activity; sid:100002413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.pdf00.cn"; classtype:trojan-activity; sid:100002414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.rising.com.cn"; classtype:trojan-activity; sid:100002415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.skycn.com"; classtype:trojan-activity; sid:100002416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.zjsyawqj.cn"; classtype:trojan-activity; sid:100002417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dragonsknot.com"; classtype:trojan-activity; sid:100002418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drbaby.com.sa"; classtype:trojan-activity; sid:100002419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dream.pics"; classtype:trojan-activity; sid:100002420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drgroup.co.za"; classtype:trojan-activity; sid:100002421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drools-moved.46999.n3.nabble.com"; classtype:trojan-activity; sid:100002422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drsha.innovativesolutions.mobi"; classtype:trojan-activity; sid:100002423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsenterprize.co.za"; classtype:trojan-activity; sid:100002424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsspainting.com"; classtype:trojan-activity; sid:100002425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"du-wizards.com"; classtype:trojan-activity; sid:100002426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duque.guantanameratravel.com"; classtype:trojan-activity; sid:100002427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dutapp.wisolve.co.za"; classtype:trojan-activity; sid:100002428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duvalcharter.dekitout.com"; classtype:trojan-activity; sid:100002429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dw2.co.id"; classtype:trojan-activity; sid:100002430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dx.qqyewu.com"; classtype:trojan-activity; sid:100002431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dzinestudio87.co.uk"; classtype:trojan-activity; sid:100002432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e-commerce.saleensuporte.com.br"; classtype:trojan-activity; sid:100002433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e.sldov.ru"; classtype:trojan-activity; sid:100002434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eandgdesign.com.ng"; classtype:trojan-activity; sid:100002435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ebruyatkin.com"; classtype:trojan-activity; sid:100002436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"edu.saicraftsman.com"; classtype:trojan-activity; sid:100002437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"efficientegroup.com"; classtype:trojan-activity; sid:100002438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"elbauldenora.com"; classtype:trojan-activity; sid:100002439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"emaids.co.za"; classtype:trojan-activity; sid:100002440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"emaz.pk"; classtype:trojan-activity; sid:100002441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"en.baoend.com"; classtype:trojan-activity; sid:100002442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enc-tech.com"; classtype:trojan-activity; sid:100002443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"endurotanzania.co.tz"; classtype:trojan-activity; sid:100002444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ennovate.elin.co.za"; classtype:trojan-activity; sid:100002445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"equimination.ee"; classtype:trojan-activity; sid:100002446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"erp.nanotechproautocare.com"; classtype:trojan-activity; sid:100002447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"escola.probommar.org.br"; classtype:trojan-activity; sid:100002448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eservices.immigration.gov.lk"; classtype:trojan-activity; sid:100002449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"esnconsultants.com"; classtype:trojan-activity; sid:100002450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"essentia.org.br"; classtype:trojan-activity; sid:100002451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ethereality.info"; classtype:trojan-activity; sid:100002452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eubanks7.com"; classtype:trojan-activity; sid:100002453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"europeanzonexxi.com"; classtype:trojan-activity; sid:100002454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exilum.com"; classtype:trojan-activity; sid:100002455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exitoalfaomega.co"; classtype:trojan-activity; sid:100002456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"extrovertoffers.com"; classtype:trojan-activity; sid:100002457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"f1sol.com"; classtype:trojan-activity; sid:100002458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"familydentist.site"; classtype:trojan-activity; sid:100002459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"faveraprojects.com"; classtype:trojan-activity; sid:100002460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fc.co.mz"; classtype:trojan-activity; sid:100002461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"felicienne.nl"; classtype:trojan-activity; sid:100002462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"files.martellexpress.us"; classtype:trojan-activity; sid:100002463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"files6.uludagbilisim.com"; classtype:trojan-activity; sid:100002464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"final.makkahkmcc.com"; classtype:trojan-activity; sid:100002465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fineartgallerym.com"; classtype:trojan-activity; sid:100002466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fisconline.bar"; classtype:trojan-activity; sid:100002467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fisconline.casa"; classtype:trojan-activity; sid:100002468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fix-america-now.org"; classtype:trojan-activity; sid:100002469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fixauto.illumetechnology.com"; classtype:trojan-activity; sid:100002470; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flexypay.dsquaregroup.com"; classtype:trojan-activity; sid:100002471; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flintspin.com"; classtype:trojan-activity; sid:100002472; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flyingbuddhadesign.com"; classtype:trojan-activity; sid:100002473; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fmjplastering.co.uk"; classtype:trojan-activity; sid:100002474; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"follower.instantcashback.in"; classtype:trojan-activity; sid:100002475; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foothills.com.br"; classtype:trojan-activity; sid:100002476; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"footweardirect.elin.co.za"; classtype:trojan-activity; sid:100002477; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"forum.mdb.nu"; classtype:trojan-activity; sid:100002478; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fotoobjetivo.com"; classtype:trojan-activity; sid:100002479; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foundationrepairhoustontx.net"; classtype:trojan-activity; sid:100002480; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foxeps.com.br"; classtype:trojan-activity; sid:100002481; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freecnetdownload.com"; classtype:trojan-activity; sid:100002482; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freisites.com.br"; classtype:trojan-activity; sid:100002483; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ftp.n3twork30cm.ml"; classtype:trojan-activity; sid:100002484; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fullelectronica.com.ar"; classtype:trojan-activity; sid:100002485; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"funletters.net"; classtype:trojan-activity; sid:100002486; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fusionfiresolutions.com"; classtype:trojan-activity; sid:100002487; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"futbolpr.com"; classtype:trojan-activity; sid:100002488; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"futuregraphics.com.ar"; classtype:trojan-activity; sid:100002489; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"g.pinmonkey.xyz"; classtype:trojan-activity; sid:100002490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gaditastour.com"; classtype:trojan-activity; sid:100002491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gametwogame.com"; classtype:trojan-activity; sid:100002492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garciadogshow.com"; classtype:trojan-activity; sid:100002493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow.myvnc.com"; classtype:trojan-activity; sid:100002494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow4.myvnc.com"; classtype:trojan-activity; sid:100002495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gastoudergonny.nl"; classtype:trojan-activity; sid:100002496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gbbulls.co.uk"; classtype:trojan-activity; sid:100002497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gcpc.co.id.chronoscurtain.com"; classtype:trojan-activity; sid:100002498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"generaldeviales.com"; classtype:trojan-activity; sid:100002499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfmodd1.webselffiles01.com"; classtype:trojan-activity; sid:100002500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfold1.webselffiles01.com"; classtype:trojan-activity; sid:100002501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghettohub.co.za"; classtype:trojan-activity; sid:100002502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghislain.dartois.pagesperso-orange.fr"; classtype:trojan-activity; sid:100002503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giadungg7.com"; classtype:trojan-activity; sid:100002504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giddos.ga"; classtype:trojan-activity; sid:100002505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giteletropical.com"; classtype:trojan-activity; sid:100002506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"glowinmedia.co.ke"; classtype:trojan-activity; sid:100002507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmtransformationacademy.com"; classtype:trojan-activity; sid:100002508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmvadmission.org"; classtype:trojan-activity; sid:100002509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnimelf.net"; classtype:trojan-activity; sid:100002510; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnscrew.ro"; classtype:trojan-activity; sid:100002511; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gold.investforex.id"; classtype:trojan-activity; sid:100002512; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcake.co.id"; classtype:trojan-activity; sid:100002513; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com"; classtype:trojan-activity; sid:100002514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com.au"; classtype:trojan-activity; sid:100002515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"golden-memories-funerals.yourpageserver.com"; classtype:trojan-activity; sid:100002516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldenasiacapital.com"; classtype:trojan-activity; sid:100002517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldmen.in"; classtype:trojan-activity; sid:100002518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gpotecnosystems.com"; classtype:trojan-activity; sid:100002519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gracejukes.com"; classtype:trojan-activity; sid:100002520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"greataccesstoserver.com"; classtype:trojan-activity; sid:100002521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"grupoinmare.com"; classtype:trojan-activity; sid:100002522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gruposelt.000webhostapp.com"; classtype:trojan-activity; sid:100002523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gs.monerorx.com"; classtype:trojan-activity; sid:100002524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"guide-to-cell-phones.com"; classtype:trojan-activity; sid:100002525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gulfac-house.com"; classtype:trojan-activity; sid:100002526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gvpcdpgc.edu.in"; classtype:trojan-activity; sid:100002527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"h.epelcdn.com"; classtype:trojan-activity; sid:100002528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"habbotips.free.fr"; classtype:trojan-activity; sid:100002529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hagebakken.no"; classtype:trojan-activity; sid:100002530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hamptonpartyoffive.com"; classtype:trojan-activity; sid:100002531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hashmati.com"; classtype:trojan-activity; sid:100002532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hassanproduct.com"; classtype:trojan-activity; sid:100002533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hchfug.org"; classtype:trojan-activity; sid:100002534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hd11315.com"; classtype:trojan-activity; sid:100002535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hdkamera2003.hu"; classtype:trojan-activity; sid:100002536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hds.sz4h.com"; classtype:trojan-activity; sid:100002537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hellogorgeous.com.au"; classtype:trojan-activity; sid:100002538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"help.hizuko.com"; classtype:trojan-activity; sid:100002539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"helpdeskserver.epelcdn.com"; classtype:trojan-activity; sid:100002540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"herchinfitout.com.sg"; classtype:trojan-activity; sid:100002541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hhaward.org"; classtype:trojan-activity; sid:100002542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandroadcoc.com"; classtype:trojan-activity; sid:100002543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandslasvegas.atakdev.com"; classtype:trojan-activity; sid:100002544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hindi.factsriver.com"; classtype:trojan-activity; sid:100002545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hiptool.net"; classtype:trojan-activity; sid:100002546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitpe.com"; classtype:trojan-activity; sid:100002547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitstation.nl"; classtype:trojan-activity; sid:100002548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hmpmall.co.kr"; classtype:trojan-activity; sid:100002549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoagietesting10.com"; classtype:trojan-activity; sid:100002550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoayeuthuong-my.sharepoint.com"; classtype:trojan-activity; sid:100002551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"holmesservices.mobiledevsite.co"; classtype:trojan-activity; sid:100002552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"homefindersolutions.com"; classtype:trojan-activity; sid:100002553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hometownchick.com"; classtype:trojan-activity; sid:100002554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hongluosi.com"; classtype:trojan-activity; sid:100002555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hookedupboatclub.com"; classtype:trojan-activity; sid:100002556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostingparacolombia.com"; classtype:trojan-activity; sid:100002557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostzaa.com"; classtype:trojan-activity; sid:100002558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"houstonshutters.site"; classtype:trojan-activity; sid:100002559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hr2019.vrcom7.com"; classtype:trojan-activity; sid:100002560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hseda.com"; classtype:trojan-activity; sid:100002561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hsmwebapp.com"; classtype:trojan-activity; sid:100002562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"htownbars.com"; classtype:trojan-activity; sid:100002563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hubtech.co.za"; classtype:trojan-activity; sid:100002564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"huellacero.cl"; classtype:trojan-activity; sid:100002565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hunchomusichub.com"; classtype:trojan-activity; sid:100002566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hunggiang.vn"; classtype:trojan-activity; sid:100002567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"husamiyahschool.com"; classtype:trojan-activity; sid:100002568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"i.n.t.e.rloca.l.qs.j.y@jfas.top"; classtype:trojan-activity; sid:100002569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iabmixx2020.rayadigital.online"; classtype:trojan-activity; sid:100002570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iam313.com"; classtype:trojan-activity; sid:100002571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"icon.shatangmu.cn"; classtype:trojan-activity; sid:100002572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idea-secure-login.com"; classtype:trojan-activity; sid:100002573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idilsoft.com"; classtype:trojan-activity; sid:100002574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idj.no"; classtype:trojan-activity; sid:100002575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idvindia.com"; classtype:trojan-activity; sid:100002576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ieclb.com.br"; classtype:trojan-activity; sid:100002577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ikexpert.com"; classtype:trojan-activity; sid:100002578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ilrafrica.com"; classtype:trojan-activity; sid:100002579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"images.jermiau.com"; classtype:trojan-activity; sid:100002580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"imbueautoworx.co.za"; classtype:trojan-activity; sid:100002581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"in-tune2016.com"; classtype:trojan-activity; sid:100002582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incrediblepixels.com"; classtype:trojan-activity; sid:100002583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incredicole.com"; classtype:trojan-activity; sid:100002584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"indrasbikaner.com"; classtype:trojan-activity; sid:100002585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infair.vn"; classtype:trojan-activity; sid:100002586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infovator.com"; classtype:trojan-activity; sid:100002587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"initialnetworks.com"; classtype:trojan-activity; sid:100002588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inodesthetotaldesigners.com"; classtype:trojan-activity; sid:100002589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inrajahmundry.co.in"; classtype:trojan-activity; sid:100002590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"instantindialoan.com"; classtype:trojan-activity; sid:100002591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intersel-idf.org"; classtype:trojan-activity; sid:100002592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intuitiveideas.com.my"; classtype:trojan-activity; sid:100002593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inversiones.arrayanfinanciero.cl"; classtype:trojan-activity; sid:100002594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"invest.xpcorporative.com.br"; classtype:trojan-activity; sid:100002595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ipmes.ma"; classtype:trojan-activity; sid:100002596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iremart.es"; classtype:trojan-activity; sid:100002597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iris101.co.uk"; classtype:trojan-activity; sid:100002598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isaac.mikhailmotoringschool.com"; classtype:trojan-activity; sid:100002599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iscamenabe.com"; classtype:trojan-activity; sid:100002600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isiphephelocon.co.za"; classtype:trojan-activity; sid:100002601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ismf.com.ng"; classtype:trojan-activity; sid:100002602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iso-dubai.net"; classtype:trojan-activity; sid:100002603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"israrulhaq.me"; classtype:trojan-activity; sid:100002604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isrorg.com"; classtype:trojan-activity; sid:100002605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isso.ps"; classtype:trojan-activity; sid:100002606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"it123.ru"; classtype:trojan-activity; sid:100002607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"italiandirezione.casa"; classtype:trojan-activity; sid:100002608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itc-demo.softgig.co.ke"; classtype:trojan-activity; sid:100002609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamiekaylive.com"; classtype:trojan-activity; sid:100002610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamshed.pk"; classtype:trojan-activity; sid:100002611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jansen-heesch.nl"; classtype:trojan-activity; sid:100002612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jathra.co.uk"; classtype:trojan-activity; sid:100002613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jay.diamondrelationscrm.us"; classtype:trojan-activity; sid:100002614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jebs.net.au"; classtype:trojan-activity; sid:100002615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jeffdahlke.com"; classtype:trojan-activity; sid:100002616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jfas.top"; classtype:trojan-activity; sid:100002617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jhayesconsulting.com"; classtype:trojan-activity; sid:100002618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jiaoyuzixun.cn"; classtype:trojan-activity; sid:100002619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jing-da.com.tw"; classtype:trojan-activity; sid:100002620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jmtc.91756.cn"; classtype:trojan-activity; sid:100002621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jnanbharati.com"; classtype:trojan-activity; sid:100002622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jobs.thebeessolution.com"; classtype:trojan-activity; sid:100002623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"joelbonissilver.com"; classtype:trojan-activity; sid:100002624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"join.cl8movement.co.za"; classtype:trojan-activity; sid:100002625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"josegene.com"; classtype:trojan-activity; sid:100002626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jpwoodfordco.com"; classtype:trojan-activity; sid:100002627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jumpmanualjacobhiller.com"; classtype:trojan-activity; sid:100002628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jupiter.toxsl.in"; classtype:trojan-activity; sid:100002629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"justinscott.com.au"; classtype:trojan-activity; sid:100002630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kadigital.co.uk"; classtype:trojan-activity; sid:100002631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalawatihomes.com"; classtype:trojan-activity; sid:100002632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalogirosfinance.com"; classtype:trojan-activity; sid:100002633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kaptaanchapal.com"; classtype:trojan-activity; sid:100002634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"karer.by"; classtype:trojan-activity; sid:100002635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"katanvetov.co.il"; classtype:trojan-activity; sid:100002636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kensingtondriving.com"; classtype:trojan-activity; sid:100002637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ketofitnessexpert.com"; classtype:trojan-activity; sid:100002638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kevinjewelry.com.co"; classtype:trojan-activity; sid:100002639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"keywatch.yourpageserver.com"; classtype:trojan-activity; sid:100002640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kihn-delaney30gn.ru.com"; classtype:trojan-activity; sid:100002641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kingssa.co.za"; classtype:trojan-activity; sid:100002642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kjcpromo.com"; classtype:trojan-activity; sid:100002643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kleinendeli.co.za"; classtype:trojan-activity; sid:100002644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"korrectconceptservices.com"; classtype:trojan-activity; sid:100002645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"krisbadminton.com"; classtype:trojan-activity; sid:100002646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ktb.sch.id"; classtype:trojan-activity; sid:100002647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kubatoglubaklava.com.tr"; classtype:trojan-activity; sid:100002648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kullumanalitours.com"; classtype:trojan-activity; sid:100002649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kumaralok.in"; classtype:trojan-activity; sid:100002650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kwanfromhongkong.com"; classtype:trojan-activity; sid:100002651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kz.sldov.ru"; classtype:trojan-activity; sid:100002652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"l.oc.atevur.c@zytrox.tk"; classtype:trojan-activity; sid:100002653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lacasadelosalebrijes.com"; classtype:trojan-activity; sid:100002654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lameguard.ru"; classtype:trojan-activity; sid:100002655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laodongnhat.vn"; classtype:trojan-activity; sid:100002656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laravel.pointersoftwares.com.br"; classtype:trojan-activity; sid:100002657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lasermobilesounds.co.uk"; classtype:trojan-activity; sid:100002658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lauratomismith.com"; classtype:trojan-activity; sid:100002659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lautarosanmiguel.com"; classtype:trojan-activity; sid:100002660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lawforall.edu.lk"; classtype:trojan-activity; sid:100002661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lawschoolideas.xyz"; classtype:trojan-activity; sid:100002662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lceventos.net"; classtype:trojan-activity; sid:100002663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ld.mediaget.com"; classtype:trojan-activity; sid:100002664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ldgcorp.com"; classtype:trojan-activity; sid:100002665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"learning.real-academy.net"; classtype:trojan-activity; sid:100002666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leasiacherise.com"; classtype:trojan-activity; sid:100002667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leczkregoslup.acelero.pl"; classtype:trojan-activity; sid:100002668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"legend.nu"; classtype:trojan-activity; sid:100002669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leluibuffet.com.br"; classtype:trojan-activity; sid:100002670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lestesteux.ca"; classtype:trojan-activity; sid:100002671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.arihantmbainstitute.ac.in"; classtype:trojan-activity; sid:100002672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.uib.ac.id"; classtype:trojan-activity; sid:100002673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lidoraggiodisole.it"; classtype:trojan-activity; sid:100002674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lifebeam.elin.co.za"; classtype:trojan-activity; sid:100002675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lindnerelektroanlagen.de"; classtype:trojan-activity; sid:100002676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"linkintec.cn"; classtype:trojan-activity; sid:100002677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"liquidaz.casa"; classtype:trojan-activity; sid:100002678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"livetrack.in"; classtype:trojan-activity; sid:100002679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lloydsindian.co.uk"; classtype:trojan-activity; sid:100002680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lm.stagingarea.co.za"; classtype:trojan-activity; sid:100002681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lmaancha.co.il"; classtype:trojan-activity; sid:100002682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.cstdevs.com"; classtype:trojan-activity; sid:100002683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.login2.in"; classtype:trojan-activity; sid:100002684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"location-voitures.ma"; classtype:trojan-activity; sid:100002685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"login.trezor.com.stockfootagesindia.com"; classtype:trojan-activity; sid:100002686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"logotypfabriken.se"; classtype:trojan-activity; sid:100002687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotix.de"; classtype:trojan-activity; sid:100002688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotusanddragonfly.com"; classtype:trojan-activity; sid:100002689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.definerisco.com"; classtype:trojan-activity; sid:100002690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.difusodesign.com"; classtype:trojan-activity; sid:100002691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ltc.typoten.com"; classtype:trojan-activity; sid:100002692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luckybrownie.com"; classtype:trojan-activity; sid:100002693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luminouspneuma.com"; classtype:trojan-activity; sid:100002694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luxomodels.com"; classtype:trojan-activity; sid:100002695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m-technics.kz"; classtype:trojan-activity; sid:100002696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m.estudiomoros.com.ar"; classtype:trojan-activity; sid:100002697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"madicon.co.za"; classtype:trojan-activity; sid:100002698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"magianegramagiablancayamarres.com"; classtype:trojan-activity; sid:100002699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.bs-eiendomme.co.za"; classtype:trojan-activity; sid:100002700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.golimoapp.com"; classtype:trojan-activity; sid:100002701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.jeffsono.org"; classtype:trojan-activity; sid:100002702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maksi.feb.unib.ac.id"; classtype:trojan-activity; sid:100002703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malaya.tv"; classtype:trojan-activity; sid:100002704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malwarecoding.github.io"; classtype:trojan-activity; sid:100002705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managed.oss-cn-beijing.aliyuncs.com"; classtype:trojan-activity; sid:100002706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managemysalon.in"; classtype:trojan-activity; sid:100002707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manantialesdelnorte.uy"; classtype:trojan-activity; sid:100002708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manhtien.net"; classtype:trojan-activity; sid:100002709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marcapinyo.ru"; classtype:trojan-activity; sid:100002710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mario-sunjic.com"; classtype:trojan-activity; sid:100002711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariobrown.net"; classtype:trojan-activity; sid:100002712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariotessarollo.com"; classtype:trojan-activity; sid:100002713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketinfosales.com"; classtype:trojan-activity; sid:100002714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketing.enexusgroup.com.au"; classtype:trojan-activity; sid:100002715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marksidfgs.ug"; classtype:trojan-activity; sid:100002716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"masjidhabeebiyarazviya.mysunni.com"; classtype:trojan-activity; sid:100002717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mastersofclientretention.com.au"; classtype:trojan-activity; sid:100002718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"materialescantu.com"; classtype:trojan-activity; sid:100002719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"matruchhaya.co.in"; classtype:trojan-activity; sid:100002720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxtox.com.pk"; classtype:trojan-activity; sid:100002721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbgrm.com"; classtype:trojan-activity; sid:100002722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbjtimes.com"; classtype:trojan-activity; sid:100002723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbsolutions.ge"; classtype:trojan-activity; sid:100002724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mdasa.elin.co.za"; classtype:trojan-activity; sid:100002725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medevlb.org"; classtype:trojan-activity; sid:100002726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"media-server.skyinternet.com.pk"; classtype:trojan-activity; sid:100002727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medianews.ge"; classtype:trojan-activity; sid:100002728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mediawaysnews.com"; classtype:trojan-activity; sid:100002729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medistaffconsulting.com"; classtype:trojan-activity; sid:100002730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meeweb.com"; classtype:trojan-activity; sid:100002731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"megagynreformas.com.br"; classtype:trojan-activity; sid:100002732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"megamart.afnan-amc.com"; classtype:trojan-activity; sid:100002733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mehainteriors.com"; classtype:trojan-activity; sid:100002734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"merkathink.com"; classtype:trojan-activity; sid:100002735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mertlog.com"; classtype:trojan-activity; sid:100002736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"metalin-cr.com"; classtype:trojan-activity; sid:100002737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mettaanand.org"; classtype:trojan-activity; sid:100002738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meuoculosnanet.com.br"; classtype:trojan-activity; sid:100002739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mfevr.com"; classtype:trojan-activity; sid:100002740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot.myvnc.com"; classtype:trojan-activity; sid:100002741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot80.myvnc.com"; classtype:trojan-activity; sid:100002742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"micalle.com.au"; classtype:trojan-activity; sid:100002743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michaelphilip.com"; classtype:trojan-activity; sid:100002744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michimal2.000webhostapp.com"; classtype:trojan-activity; sid:100002745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microblading.mirliandias.com.br"; classtype:trojan-activity; sid:100002746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microcomm-group.com"; classtype:trojan-activity; sid:100002747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mikhailmotoringschool.com"; classtype:trojan-activity; sid:100002748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mingguanwms.com"; classtype:trojan-activity; sid:100002749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"minuevavida.org"; classtype:trojan-activity; sid:100002750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mirror.mypage.sk"; classtype:trojan-activity; sid:100002751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mis.nbcc.ac.th"; classtype:trojan-activity; sid:100002752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"misterson.com"; classtype:trojan-activity; sid:100002753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mkontakt.az"; classtype:trojan-activity; sid:100002754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mktf.mx"; classtype:trojan-activity; sid:100002755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mmdx.com"; classtype:trojan-activity; sid:100002756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mmogollon.com.mx"; classtype:trojan-activity; sid:100002757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mncarteam.com"; classtype:trojan-activity; sid:100002758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modelhouseturkey.com"; classtype:trojan-activity; sid:100002759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modernmanna.org"; classtype:trojan-activity; sid:100002760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"monetization.business"; classtype:trojan-activity; sid:100002761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moninediy.com"; classtype:trojan-activity; sid:100002762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moreirawag.ac.ug"; classtype:trojan-activity; sid:100002763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"motorcomunicacion.com"; classtype:trojan-activity; sid:100002764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"msacontabil.com.br"; classtype:trojan-activity; sid:100002765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mumgee.co.za"; classtype:trojan-activity; sid:100002766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"muzimbiti.xigubo.co.mz"; classtype:trojan-activity; sid:100002767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mvb.kz"; classtype:trojan-activity; sid:100002768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mxpiqw.am.files.1drv.com"; classtype:trojan-activity; sid:100002769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mydatebook.in"; classtype:trojan-activity; sid:100002770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mymlql.com"; classtype:trojan-activity; sid:100002771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myritz.vettickal.com"; classtype:trojan-activity; sid:100002772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mysalons.in"; classtype:trojan-activity; sid:100002773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myscape.in"; classtype:trojan-activity; sid:100002774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mysura.it"; classtype:trojan-activity; sid:100002775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"naeemacademy.com"; classtype:trojan-activity; sid:100002776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"namnyak.co.ke"; classtype:trojan-activity; sid:100002777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nap.mgsservers.com"; classtype:trojan-activity; sid:100002778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"navayurveda.in"; classtype:trojan-activity; sid:100002779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nec-i.com"; classtype:trojan-activity; sid:100002780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nelitrianggraeni.000webhostapp.com"; classtype:trojan-activity; sid:100002781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nerve.untergrund.net"; classtype:trojan-activity; sid:100002782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nettube.com.br"; classtype:trojan-activity; sid:100002783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"networkwheels.co.za"; classtype:trojan-activity; sid:100002784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newfuture.fr"; classtype:trojan-activity; sid:100002785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newinfinitysynergy.com"; classtype:trojan-activity; sid:100002786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newtreedesign.co.uk"; classtype:trojan-activity; sid:100002787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newvisionopticallab.com"; classtype:trojan-activity; sid:100002788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newxing.com"; classtype:trojan-activity; sid:100002789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nextdigitalday.ru"; classtype:trojan-activity; sid:100002790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ngdaycare.co.za"; classtype:trojan-activity; sid:100002791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nguyenkekhuyen.com"; classtype:trojan-activity; sid:100002792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nhorangtreem.com"; classtype:trojan-activity; sid:100002793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nicolas.ug"; classtype:trojan-activity; sid:100002794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nidhi.iexist.in"; classtype:trojan-activity; sid:100002795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nikanpolimer.ir"; classtype:trojan-activity; sid:100002796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilehouse.co.ug"; classtype:trojan-activity; sid:100002797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilinkeji.com"; classtype:trojan-activity; sid:100002798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nimboohomes.com"; classtype:trojan-activity; sid:100002799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"njtiledesigncenter.com"; classtype:trojan-activity; sid:100002800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nobius.org"; classtype:trojan-activity; sid:100002801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nocalnoodle.elin.co.za"; classtype:trojan-activity; sid:100002802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nomadicbees.com"; classtype:trojan-activity; sid:100002803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"northnodegroup.com.au"; classtype:trojan-activity; sid:100002804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"notamuzikaletleri.com"; classtype:trojan-activity; sid:100002805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ns1.the-widyantos.com"; classtype:trojan-activity; sid:100002806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nsb.org.uk"; classtype:trojan-activity; sid:100002807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nurmarkaz.org"; classtype:trojan-activity; sid:100002808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nxtnet.ga"; classtype:trojan-activity; sid:100002809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nyasabigbullets.com"; classtype:trojan-activity; sid:100002810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nyeh2o.com.au"; classtype:trojan-activity; sid:100002811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"obseques-conseils.com"; classtype:trojan-activity; sid:100002812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oecteam.com"; classtype:trojan-activity; sid:100002813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohsewgorgeous.co.uk"; classtype:trojan-activity; sid:100002814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oleholeh.memangbeda.website"; classtype:trojan-activity; sid:100002815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaia.org"; classtype:trojan-activity; sid:100002816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaromatic.com"; classtype:trojan-activity; sid:100002817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omega.az"; classtype:trojan-activity; sid:100002818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oms.pappai.com"; classtype:trojan-activity; sid:100002819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omscoc.pappai.com"; classtype:trojan-activity; sid:100002820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedigitalcard.granvizionnecorp.com"; classtype:trojan-activity; sid:100002821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedrive.listifyapp.co"; classtype:trojan-activity; sid:100002822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"online.creedglobal.in"; classtype:trojan-activity; sid:100002823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"open.rawntech.com"; classtype:trojan-activity; sid:100002824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"open.warehousesaas.co.uk"; classtype:trojan-activity; sid:100002825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opolis.io"; classtype:trojan-activity; sid:100002826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"optimus.com.sg"; classtype:trojan-activity; sid:100002827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"order.bizpeed.com"; classtype:trojan-activity; sid:100002828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orientgatewayltd.com"; classtype:trojan-activity; sid:100002829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orion445.com"; classtype:trojan-activity; sid:100002830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orlina.be"; classtype:trojan-activity; sid:100002831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oserve.pk"; classtype:trojan-activity; sid:100002832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ot.weenets.com"; classtype:trojan-activity; sid:100002833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ozemag.com"; classtype:trojan-activity; sid:100002834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p1.lingpao8.com"; classtype:trojan-activity; sid:100002835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p3.zbjimg.com"; classtype:trojan-activity; sid:100002836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p6.zbjimg.com"; classtype:trojan-activity; sid:100002837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pablobrothel.com.ar"; classtype:trojan-activity; sid:100002838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacificgroup.ws"; classtype:trojan-activity; sid:100002839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacwebdesigns.com"; classtype:trojan-activity; sid:100002840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pagos.krayem.com.mx"; classtype:trojan-activity; sid:100002841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"palochusvet.szm.com"; classtype:trojan-activity; sid:100002842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"panslimiterd.com"; classtype:trojan-activity; sid:100002843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parallel.rockvideos.at"; classtype:trojan-activity; sid:100002844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parejasfelices.mi-fs.com"; classtype:trojan-activity; sid:100002845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parkhussion.com"; classtype:trojan-activity; sid:100002846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pastorpaulocosta.com"; classtype:trojan-activity; sid:100002847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.51lg.com"; classtype:trojan-activity; sid:100002848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.99ddd.com"; classtype:trojan-activity; sid:100002849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch3.99ddd.com"; classtype:trojan-activity; sid:100002850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paths.elin.co.za"; classtype:trojan-activity; sid:100002851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patriotsupremehemp.com"; classtype:trojan-activity; sid:100002852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paulmercier.biz"; classtype:trojan-activity; sid:100002853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payerrealty.com"; classtype:trojan-activity; sid:100002854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payments.atifsiddiqui.me"; classtype:trojan-activity; sid:100002855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pcsoori.com"; classtype:trojan-activity; sid:100002856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pd.oceaniarp.net"; classtype:trojan-activity; sid:100002857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pemdodo.com"; classtype:trojan-activity; sid:100002858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perfumeriamontes.es"; classtype:trojan-activity; sid:100002859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"periodiche.bar"; classtype:trojan-activity; sid:100002860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpus.onlineman7-jombang.sch.id"; classtype:trojan-activity; sid:100002861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpustekim.untirta.ac.id"; classtype:trojan-activity; sid:100002862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pestoclean.co.uk"; classtype:trojan-activity; sid:100002863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"petercollie.com"; classtype:trojan-activity; sid:100002864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ph4s.ru"; classtype:trojan-activity; sid:100002865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phasdesign.com"; classtype:trojan-activity; sid:100002866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phenhuong.sanpham.online"; classtype:trojan-activity; sid:100002867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phittc.com"; classtype:trojan-activity; sid:100002868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"photo360.kubooking.com"; classtype:trojan-activity; sid:100002869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pink99.com"; classtype:trojan-activity; sid:100002870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"plasfan.ind.br"; classtype:trojan-activity; sid:100002871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"playground2.grupoaliadasca.com"; classtype:trojan-activity; sid:100002872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pmglance.startwriteup.com"; classtype:trojan-activity; sid:100002873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pokojewewladyslawowie.pl"; classtype:trojan-activity; sid:100002874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pole.com.vc"; classtype:trojan-activity; sid:100002875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pool.phxdir.com"; classtype:trojan-activity; sid:100002876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pooltablemoversdenver.net"; classtype:trojan-activity; sid:100002877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"posmicrosystems.com"; classtype:trojan-activity; sid:100002878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"poulman.panagiotopoulos-tours.gr"; classtype:trojan-activity; sid:100002879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ppdb.smk-ciptaskill.sch.id"; classtype:trojan-activity; sid:100002880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestasicash.com.ar"; classtype:trojan-activity; sid:100002881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestigehomeautomation.net"; classtype:trojan-activity; sid:100002882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"preview2.behalen.com"; classtype:trojan-activity; sid:100002883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prishaartcreations.com"; classtype:trojan-activity; sid:100002884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"production.sparshims.com"; classtype:trojan-activity; sid:100002885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"programaoperadoronline.com.br"; classtype:trojan-activity; sid:100002886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"project.exquitec.com"; classtype:trojan-activity; sid:100002887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promotoradescomplica.com.br"; classtype:trojan-activity; sid:100002888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promoversdubai.com"; classtype:trojan-activity; sid:100002889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq.elin.co.za"; classtype:trojan-activity; sid:100002890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq2.elin.co.za"; classtype:trojan-activity; sid:100002891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosoc.nl"; classtype:trojan-activity; sid:100002892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosyarmakassar.com"; classtype:trojan-activity; sid:100002893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"provence.elin.co.za"; classtype:trojan-activity; sid:100002894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prox.realunix.cc"; classtype:trojan-activity; sid:100002895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pujashoppe.in"; classtype:trojan-activity; sid:100002896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punchdialogues.com"; classtype:trojan-activity; sid:100002897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punjabdevelopersassociation.com.pk"; classtype:trojan-activity; sid:100002898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qadir.tickfa.ir"; classtype:trojan-activity; sid:100002899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qatarglobalconsulting.com"; classtype:trojan-activity; sid:100002900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qmsled.com"; classtype:trojan-activity; sid:100002901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qu.o.t.ev.v.n.r@zytrox.tk"; classtype:trojan-activity; sid:100002902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"quartier-midi.be"; classtype:trojan-activity; sid:100002903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"querocar.com"; classtype:trojan-activity; sid:100002904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rachmat-assuhaimi.my.id"; classtype:trojan-activity; sid:100002905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"radioafifense.deploys.live"; classtype:trojan-activity; sid:100002906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rainbowisp.info"; classtype:trojan-activity; sid:100002907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rajeshtailang.com"; classtype:trojan-activity; sid:100002908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rakeshkhatri.in"; classtype:trojan-activity; sid:100002909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"raodigitalmedia.com"; classtype:trojan-activity; sid:100002910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"raquelhelena.com.br"; classtype:trojan-activity; sid:100002911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rarlabarchiver.ac"; classtype:trojan-activity; sid:100002912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rasadbar.ir"; classtype:trojan-activity; sid:100002913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rashika.ascarvalho.co.za"; classtype:trojan-activity; sid:100002914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ratemyfenancialadvisor.com"; classtype:trojan-activity; sid:100002915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ravenproductionsltd.com"; classtype:trojan-activity; sid:100002916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ravo.net.au"; classtype:trojan-activity; sid:100002917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rc.ixiaoyang.cn"; classtype:trojan-activity; sid:100002918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rcmesilva.charbelsales.com.br"; classtype:trojan-activity; sid:100002919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reacredit.com.br"; classtype:trojan-activity; sid:100002920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"readwrite26.nl"; classtype:trojan-activity; sid:100002921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"readymmade.com"; classtype:trojan-activity; sid:100002922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"recyclethesurplus.com"; classtype:trojan-activity; sid:100002923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redbats.co.in"; classtype:trojan-activity; sid:100002924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redchillicrackers.com"; classtype:trojan-activity; sid:100002925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reifenquick.de"; classtype:trojan-activity; sid:100002926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"relaxindulge.co.nz"; classtype:trojan-activity; sid:100002927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"renehavis.com.ua"; classtype:trojan-activity; sid:100002928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"repatriacioncolombia.com"; classtype:trojan-activity; sid:100002929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"res.uf1.cn"; classtype:trojan-activity; sid:100002930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reseller.digimitra.in"; classtype:trojan-activity; sid:100002931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reseller.itechbrasil.com"; classtype:trojan-activity; sid:100002932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"resuco.net"; classtype:trojan-activity; sid:100002933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"revolet-sa.com"; classtype:trojan-activity; sid:100002934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rezkabum.ru"; classtype:trojan-activity; sid:100002935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rhema.com.sg"; classtype:trojan-activity; sid:100002936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richmondminerals.co.zm"; classtype:trojan-activity; sid:100002937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinaefoundation.org.za"; classtype:trojan-activity; sid:100002938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinkaisystem-ht.com"; classtype:trojan-activity; sid:100002939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"riverfox.co.za"; classtype:trojan-activity; sid:100002940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkcable.co.in"; classtype:trojan-activity; sid:100002941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkverify.securestudies.com"; classtype:trojan-activity; sid:100002942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertmcardle.com"; classtype:trojan-activity; sid:100002943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertsinclair.net"; classtype:trojan-activity; sid:100002944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"romanianpoints.com"; classtype:trojan-activity; sid:100002945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ronnietucker.co.uk"; classtype:trojan-activity; sid:100002946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roomsvc.servegate.kr"; classtype:trojan-activity; sid:100002947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roshnijewellery.com"; classtype:trojan-activity; sid:100002948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rsgym.net"; classtype:trojan-activity; sid:100002949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubazar.pro"; classtype:trojan-activity; sid:100002950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubycityvietnam.com"; classtype:trojan-activity; sid:100002951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruisgood.ru"; classtype:trojan-activity; sid:100002952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruwadalkuwait.com"; classtype:trojan-activity; sid:100002953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.51shijuan.com"; classtype:trojan-activity; sid:100002954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.hu.d.es.h.d.u.e54.78.16247@46.249.33.79"; classtype:trojan-activity; sid:100002955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.thechinesemuslim.com"; classtype:trojan-activity; sid:100002956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sacredscentsonline.com"; classtype:trojan-activity; sid:100002957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sadmahfuneralservices.co.za"; classtype:trojan-activity; sid:100002958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safcol-colors.com"; classtype:trojan-activity; sid:100002959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safehubsecurity.ca"; classtype:trojan-activity; sid:100002960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safety.nanotechproautocare.com"; classtype:trojan-activity; sid:100002961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sahathaikasetpan.com"; classtype:trojan-activity; sid:100002962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sainzim.co.za"; classtype:trojan-activity; sid:100002963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"saisoftwareinc.com"; classtype:trojan-activity; sid:100002964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"salecorner.yourpageserver.com"; classtype:trojan-activity; sid:100002965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"salonsaifa.com"; classtype:trojan-activity; sid:100002966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"samriddhijyotish.com"; classtype:trojan-activity; sid:100002967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sandovalgraphics.com"; classtype:trojan-activity; sid:100002968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"santyago.org"; classtype:trojan-activity; sid:100002969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sasystemsuk.com"; classtype:trojan-activity; sid:100002970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scarfaceindustries.com"; classtype:trojan-activity; sid:100002971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scglobal.co.th"; classtype:trojan-activity; sid:100002972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schalke04rss.de"; classtype:trojan-activity; sid:100002973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scheff.com"; classtype:trojan-activity; sid:100002974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schoolbustracker.softgig.co.ke"; classtype:trojan-activity; sid:100002975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sculetus.nl"; classtype:trojan-activity; sid:100002976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"secure-doc-reader.com"; classtype:trojan-activity; sid:100002977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"segalsmetals.elin.co.za"; classtype:trojan-activity; sid:100002978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sellmyphonela.com"; classtype:trojan-activity; sid:100002979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"selltechtoday.com"; classtype:trojan-activity; sid:100002980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"senbiaojita.com"; classtype:trojan-activity; sid:100002981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sentierodelviandante.ml"; classtype:trojan-activity; sid:100002982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serendibsourcing.com"; classtype:trojan-activity; sid:100002983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sericaasia.com"; classtype:trojan-activity; sid:100002984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd.myvnc.com"; classtype:trojan-activity; sid:100002985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd80.myvnc.com"; classtype:trojan-activity; sid:100002986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sexologistpakistan.net"; classtype:trojan-activity; sid:100002987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sgessy.com.br"; classtype:trojan-activity; sid:100002988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shaheentbfoundation.com"; classtype:trojan-activity; sid:100002989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shahikhana.cstdevs.com"; classtype:trojan-activity; sid:100002990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shahu66.com"; classtype:trojan-activity; sid:100002991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shalombaptistchapel.com"; classtype:trojan-activity; sid:100002992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharkrigs.com"; classtype:trojan-activity; sid:100002993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharpelevators.in"; classtype:trojan-activity; sid:100002994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shembefoundation.com"; classtype:trojan-activity; sid:100002995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shidditourism.com"; classtype:trojan-activity; sid:100002996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shivakunwar.com.np"; classtype:trojan-activity; sid:100002997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shoblasaathitrust.org"; classtype:trojan-activity; sid:100002998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shomalhouse.com"; classtype:trojan-activity; sid:100002999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shooka-co.com"; classtype:trojan-activity; sid:100003000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shop.goldspot.agency"; classtype:trojan-activity; sid:100003001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shopsofe.com"; classtype:trojan-activity; sid:100003002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sibernetix.fr"; classtype:trojan-activity; sid:100003003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sige.brisainformatica.com.br"; classtype:trojan-activity; sid:100003004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"signatureads.co.in"; classtype:trojan-activity; sid:100003005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siili.net"; classtype:trojan-activity; sid:100003006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simoneporzi.it"; classtype:trojan-activity; sid:100003007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simorsint.com"; classtype:trojan-activity; sid:100003008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simplithy.co.uk"; classtype:trojan-activity; sid:100003009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindicato1ucm.cl"; classtype:trojan-activity; sid:100003010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindpol.tiejuris.com.br"; classtype:trojan-activity; sid:100003011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sipahielektrik.com"; classtype:trojan-activity; sid:100003012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sistelligent.com"; classtype:trojan-activity; sid:100003013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyflyfares.com"; classtype:trojan-activity; sid:100003014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyscan.com"; classtype:trojan-activity; sid:100003015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"slot0.gamoruz.com"; classtype:trojan-activity; sid:100003016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smarthouseforum.ru"; classtype:trojan-activity; sid:100003017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smartzedu.com"; classtype:trojan-activity; sid:100003018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smokesolutionindia.com"; classtype:trojan-activity; sid:100003019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smritiphotography.in"; classtype:trojan-activity; sid:100003020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sobariko.com"; classtype:trojan-activity; sid:100003021; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sobethuacademy.com"; classtype:trojan-activity; sid:100003022; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.110route.com"; classtype:trojan-activity; sid:100003023; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.officelabo.net"; classtype:trojan-activity; sid:100003024; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sogecoenergy.com"; classtype:trojan-activity; sid:100003025; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sohs.conceptechs.info"; classtype:trojan-activity; sid:100003026; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"solar.amazingtribe.lk"; classtype:trojan-activity; sid:100003027; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somcorbera.cat"; classtype:trojan-activity; sid:100003028; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somir.com.mx"; classtype:trojan-activity; sid:100003029; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soralapps.com"; classtype:trojan-activity; sid:100003030; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sota-france.fr"; classtype:trojan-activity; sid:100003031; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"space.proactint.org"; classtype:trojan-activity; sid:100003032; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spaceframe.mobi.space-frame.co.za"; classtype:trojan-activity; sid:100003033; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"special-key.cf"; classtype:trojan-activity; sid:100003034; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spent.com.pl"; classtype:trojan-activity; sid:100003035; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spetsesyachtcharter.gr"; classtype:trojan-activity; sid:100003036; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spititourism.com"; classtype:trojan-activity; sid:100003037; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spittinfire.com"; classtype:trojan-activity; sid:100003038; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"springbedspetroleum.com"; classtype:trojan-activity; sid:100003039; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"src1.minibai.com"; classtype:trojan-activity; sid:100003040; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sreenivasapaintingworks.com"; classtype:trojan-activity; sid:100003041; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sriglobalit.com"; classtype:trojan-activity; sid:100003042; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"srilankamovies.com"; classtype:trojan-activity; sid:100003043; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"srvmanos.no-ip.info"; classtype:trojan-activity; sid:100003044; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ss.monita.co.id"; classtype:trojan-activity; sid:100003045; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"st.devcodin.com"; classtype:trojan-activity; sid:100003046; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"staging.apparelpunch.com"; classtype:trojan-activity; sid:100003047; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"starcountry.net"; classtype:trojan-activity; sid:100003048; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"static.3001.net"; classtype:trojan-activity; sid:100003049; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stiau.iuc.ac"; classtype:trojan-activity; sid:100003050; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sticker.jewsjuice.com"; classtype:trojan-activity; sid:100003051; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stiepancasetia.ac.id"; classtype:trojan-activity; sid:100003052; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stlukesohag.com"; classtype:trojan-activity; sid:100003053; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"store.ericalgarin.com"; classtype:trojan-activity; sid:100003054; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stott-thompson.co.uk"; classtype:trojan-activity; sid:100003055; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"streetdemo.yourpageserver.com"; classtype:trojan-activity; sid:100003056; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"suboldesign.com"; classtype:trojan-activity; sid:100003057; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sumerians.org"; classtype:trojan-activity; sid:100003058; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunaryem.com.tr"; classtype:trojan-activity; sid:100003059; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunmarkholidays.com"; classtype:trojan-activity; sid:100003060; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support-4-free.com"; classtype:trojan-activity; sid:100003061; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support.clz.kr"; classtype:trojan-activity; sid:100003062; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supportit.online"; classtype:trojan-activity; sid:100003063; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sw.yourpageserver.com"; classtype:trojan-activity; sid:100003064; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweaty.dk"; classtype:trojan-activity; sid:100003065; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweet-diet.com"; classtype:trojan-activity; sid:100003066; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swiftlogisticseg.com"; classtype:trojan-activity; sid:100003067; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swwbia.com"; classtype:trojan-activity; sid:100003068; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"syracusecoffee.com"; classtype:trojan-activity; sid:100003069; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sytraders.co"; classtype:trojan-activity; sid:100003070; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"t.honker.info"; classtype:trojan-activity; sid:100003071; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tadoo.ca"; classtype:trojan-activity; sid:100003072; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tafsantoursandtravels.com"; classtype:trojan-activity; sid:100003073; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tajushariya.com"; classtype:trojan-activity; sid:100003074; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tallyinvoicecustomization.com"; classtype:trojan-activity; sid:100003075; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taltus.co.uk"; classtype:trojan-activity; sid:100003076; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tapalkoedacoffee.com"; classtype:trojan-activity; sid:100003077; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tarravalleyfoods.com.au"; classtype:trojan-activity; sid:100003078; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taurus.ug"; classtype:trojan-activity; sid:100003079; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tc.snpsresidential.com"; classtype:trojan-activity; sid:100003080; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tcy.198424.com"; classtype:trojan-activity; sid:100003081; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tdsp.yngw518.com"; classtype:trojan-activity; sid:100003082; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"techgms.com"; classtype:trojan-activity; sid:100003083; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teduae.com"; classtype:trojan-activity; sid:100003084; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teleargentina.com"; classtype:trojan-activity; sid:100003085; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"telescopelms.com"; classtype:trojan-activity; sid:100003086; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"temptmag.com"; classtype:trojan-activity; sid:100003087; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tencoconsulting.com"; classtype:trojan-activity; sid:100003088; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teneth.co.za"; classtype:trojan-activity; sid:100003089; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tentandoserfitness.000webhostapp.com"; classtype:trojan-activity; sid:100003090; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tessrobins.com"; classtype:trojan-activity; sid:100003091; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.adventser.com"; classtype:trojan-activity; sid:100003092; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.letraele.es"; classtype:trojan-activity; sid:100003093; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.lubrico.in"; classtype:trojan-activity; sid:100003094; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.protocsconnectes.eu"; classtype:trojan-activity; sid:100003095; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.typoten.com"; classtype:trojan-activity; sid:100003096; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.wanepghana.org"; classtype:trojan-activity; sid:100003097; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.asistencia247.com"; classtype:trojan-activity; sid:100003098; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.milenial.id"; classtype:trojan-activity; sid:100003099; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.tenplusone.my"; classtype:trojan-activity; sid:100003100; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.basis-web.com"; classtype:trojan-activity; sid:100003101; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.marrenconstruction.ie"; classtype:trojan-activity; sid:100003102; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.clickitsolutionsmw.com"; classtype:trojan-activity; sid:100003103; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.thinkingcorp.in"; classtype:trojan-activity; sid:100003104; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testnew.yourpageserver.com"; classtype:trojan-activity; sid:100003105; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teteaffiche.stephanebillon.com"; classtype:trojan-activity; sid:100003106; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tewoerd.eu"; classtype:trojan-activity; sid:100003107; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"textile.softberg.ro"; classtype:trojan-activity; sid:100003108; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tharringtonsponsorship.com"; classtype:trojan-activity; sid:100003109; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecleaningladiespdx.com"; classtype:trojan-activity; sid:100003110; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecreativecafe.co.uk"; classtype:trojan-activity; sid:100003111; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thedesertship.com"; classtype:trojan-activity; sid:100003112; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thefamouscurrybazaar.co.uk"; classtype:trojan-activity; sid:100003113; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thefuturelife.in"; classtype:trojan-activity; sid:100003114; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thehighlightinterior.com"; classtype:trojan-activity; sid:100003115; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thekassia.co.uk"; classtype:trojan-activity; sid:100003116; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"themansionkasauli.com"; classtype:trojan-activity; sid:100003117; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theprofinn.com"; classtype:trojan-activity; sid:100003118; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thesummitpc.net"; classtype:trojan-activity; sid:100003119; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theurbantutors.com"; classtype:trojan-activity; sid:100003120; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thosewebbs.com"; classtype:trojan-activity; sid:100003121; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thriveink.com"; classtype:trojan-activity; sid:100003122; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tianangdep.com"; classtype:trojan-activity; sid:100003123; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickfoods.tickme.lk"; classtype:trojan-activity; sid:100003124; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tidymasters.com.au"; classtype:trojan-activity; sid:100003125; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"timegonebuy.com"; classtype:trojan-activity; sid:100003126; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tksb.net"; classtype:trojan-activity; sid:100003127; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tlcc.com.gt"; classtype:trojan-activity; sid:100003128; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"todoapp.cstdevs.com"; classtype:trojan-activity; sid:100003129; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonydong.com"; classtype:trojan-activity; sid:100003130; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonyzone.com"; classtype:trojan-activity; sid:100003131; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tooba.tenplusone.my"; classtype:trojan-activity; sid:100003132; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tools.reimclub.com"; classtype:trojan-activity; sid:100003133; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topcell9.com"; classtype:trojan-activity; sid:100003134; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toplevel.com.br"; classtype:trojan-activity; sid:100003135; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topmask.co.za"; classtype:trojan-activity; sid:100003136; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"torresquinterocorp.com"; classtype:trojan-activity; sid:100003137; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"towme.services"; classtype:trojan-activity; sid:100003138; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toyotacollege.ac.th"; classtype:trojan-activity; sid:100003139; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpke.hu"; classtype:trojan-activity; sid:100003140; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"translaterjemah.com"; classtype:trojan-activity; sid:100003141; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"travelwithmanta.co.za"; classtype:trojan-activity; sid:100003142; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trendyshoes.co.za"; classtype:trojan-activity; sid:100003143; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trezors.io.mahlongwa.com"; classtype:trojan-activity; sid:100003144; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trimestre.bar"; classtype:trojan-activity; sid:100003145; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"troki.com.co"; classtype:trojan-activity; sid:100003146; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tropics.codeleek.net"; classtype:trojan-activity; sid:100003147; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trudelfavreau.com"; classtype:trojan-activity; sid:100003148; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tsd.jxwan.com"; classtype:trojan-activity; sid:100003149; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tulli.info"; classtype:trojan-activity; sid:100003150; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tupperware.michaelroberge.ca"; classtype:trojan-activity; sid:100003151; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"turanggaresources.com"; classtype:trojan-activity; sid:100003152; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uat.indianfilmzone.com"; classtype:trojan-activity; sid:100003153; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ublretailerdemo.cstdevs.com"; classtype:trojan-activity; sid:100003154; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uc-56.ru"; classtype:trojan-activity; sid:100003155; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uisusa.uisusa.com"; classtype:trojan-activity; sid:100003156; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ultimate-24.de"; classtype:trojan-activity; sid:100003157; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"umwelt-kirchhof.de"; classtype:trojan-activity; sid:100003158; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unicorpbrunei.com"; classtype:trojan-activity; sid:100003159; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uniengrisb.com"; classtype:trojan-activity; sid:100003160; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"union.jctrip.cn"; classtype:trojan-activity; sid:100003161; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unyazitelecom.com"; classtype:trojan-activity; sid:100003162; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"up.llw0.com"; classtype:trojan-activity; sid:100003163; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"upcbpta.com"; classtype:trojan-activity; sid:100003164; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"used-jeans.fr"; classtype:trojan-activity; sid:100003165; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"useformoney.000webhostapp.com"; classtype:trojan-activity; sid:100003166; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uss.ac.th"; classtype:trojan-activity; sid:100003167; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uzzepay.com.br"; classtype:trojan-activity; sid:100003168; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vanzare.cabanabrazi2.ro"; classtype:trojan-activity; sid:100003169; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vbcargo.hu"; classtype:trojan-activity; sid:100003170; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vcah.co.uk"; classtype:trojan-activity; sid:100003171; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vectarts.com"; classtype:trojan-activity; sid:100003172; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vegadelcasero.cl"; classtype:trojan-activity; sid:100003173; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"velma-harber30ku.com"; classtype:trojan-activity; sid:100003174; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vendas.lidiacarmeli.com.br"; classtype:trojan-activity; sid:100003175; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"veterinariadrpopui.com"; classtype:trojan-activity; sid:100003176; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vfocus.net"; classtype:trojan-activity; sid:100003177; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vienen.gblix.srv.br"; classtype:trojan-activity; sid:100003178; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vilaart.rs"; classtype:trojan-activity; sid:100003179; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villamarand.com"; classtype:trojan-activity; sid:100003180; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villatera.com"; classtype:trojan-activity; sid:100003181; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"violinstop.com"; classtype:trojan-activity; sid:100003182; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"virtuleverage.com"; classtype:trojan-activity; sid:100003183; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visions.alnisamart.com"; classtype:trojan-activity; sid:100003184; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visualhome.cl"; classtype:trojan-activity; sid:100003185; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vivationdesign.com"; classtype:trojan-activity; sid:100003186; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"viveirodoiscorregos.com.br"; classtype:trojan-activity; sid:100003187; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vksales.com"; classtype:trojan-activity; sid:100003188; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vocalterra.com"; classtype:trojan-activity; sid:100003189; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vokasi.ub.ac.id"; classtype:trojan-activity; sid:100003190; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vologroup.com.br"; classtype:trojan-activity; sid:100003191; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"voteyouramerica.dekitout.com"; classtype:trojan-activity; sid:100003192; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vpts.co.za"; classtype:trojan-activity; sid:100003193; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vstsample.com"; classtype:trojan-activity; sid:100003194; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vtube.fadlymotivator.com"; classtype:trojan-activity; sid:100003195; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vvsskmodinationalschool.com"; classtype:trojan-activity; sid:100003196; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu"; classtype:trojan-activity; sid:100003197; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepliberia.org"; classtype:trojan-activity; sid:100003198; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepniger.org"; classtype:trojan-activity; sid:100003199; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weareactum.com"; classtype:trojan-activity; sid:100003200; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.eng.ubu.ac.th"; classtype:trojan-activity; sid:100003201; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geomegasoft.net"; classtype:trojan-activity; sid:100003202; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.newinnovationtechnology.com"; classtype:trojan-activity; sid:100003203; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.smarts-works.com"; classtype:trojan-activity; sid:100003204; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.thebeessolution.com"; classtype:trojan-activity; sid:100003205; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webgis.perumdasolo.com"; classtype:trojan-activity; sid:100003206; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webpresario.com"; classtype:trojan-activity; sid:100003207; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weinsteincounseling.com"; classtype:trojan-activity; sid:100003208; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wfinance.com.br"; classtype:trojan-activity; sid:100003209; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whcms.yourpageserver.com"; classtype:trojan-activity; sid:100003210; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteresponse.com"; classtype:trojan-activity; sid:100003211; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wi522012.ferozo.com"; classtype:trojan-activity; sid:100003212; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wikalen.co.za"; classtype:trojan-activity; sid:100003213; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildnights.co.uk"; classtype:trojan-activity; sid:100003214; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildtrust.mediadevstaging.com"; classtype:trojan-activity; sid:100003215; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"willow-nettica.com"; classtype:trojan-activity; sid:100003216; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wimbamusica.com"; classtype:trojan-activity; sid:100003217; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"windcomtechnologies.com"; classtype:trojan-activity; sid:100003218; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wishesconcierge.com"; classtype:trojan-activity; sid:100003219; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woezon.agency"; classtype:trojan-activity; sid:100003220; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wolfgang-brodte.de"; classtype:trojan-activity; sid:100003221; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woodsytech.com"; classtype:trojan-activity; sid:100003222; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wordpress.saleensuporte.com.br"; classtype:trojan-activity; sid:100003223; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wozata.000webhostapp.com"; classtype:trojan-activity; sid:100003224; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wp.readhere.in"; classtype:trojan-activity; sid:100003225; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wpdemo.101clients.com.au"; classtype:trojan-activity; sid:100003226; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"writtendeer.com"; classtype:trojan-activity; sid:100003227; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ws5588.f3322.net"; classtype:trojan-activity; sid:100003228; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wyklej.pl"; classtype:trojan-activity; sid:100003229; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"x2vn.com"; classtype:trojan-activity; sid:100003230; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xia.beihaixue.com"; classtype:trojan-activity; sid:100003231; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xixaoclothing.com"; classtype:trojan-activity; sid:100003232; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xk.996is.com"; classtype:trojan-activity; sid:100003233; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--polimerbizmimarlk-rvc.com"; classtype:trojan-activity; sid:100003234; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ybom.urbanolab.com"; classtype:trojan-activity; sid:100003235; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yeichner.com"; classtype:trojan-activity; sid:100003236; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yeq.i.u.j.ia.n.3@zytrox.tk"; classtype:trojan-activity; sid:100003237; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ylfpremium.com"; classtype:trojan-activity; sid:100003238; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yoast.yourpageserver.com"; classtype:trojan-activity; sid:100003239; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yummyyogaudaipur.com"; classtype:trojan-activity; sid:100003240; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yzkzixun.com"; classtype:trojan-activity; sid:100003241; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ziyker4gaming@zytrox.tk"; classtype:trojan-activity; sid:100003242; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zmedcoach.com"; classtype:trojan-activity; sid:100003243; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zytrox.tk"; classtype:trojan-activity; sid:100003244; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zz.690tx.com"; classtype:trojan-activity; sid:100003245; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100003246; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/86.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100003247; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; endswith; nocase; http.host; content:"amumufree.weebly.com"; classtype:trojan-activity; sid:100003248; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/proxyi.exe"; endswith; nocase; http.host; content:"analogx.com"; classtype:trojan-activity; sid:100003249; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003250; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvdfv/anjj/downloads/jami.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003251; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/heyhoeee/heyhoename1/downloads/1234.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003252; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/4.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003253; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/6.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003254; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labesoftware/update/downloads/boost-fps.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003255; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labesoftware/update/downloads/install_plugin_x64_x86.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003256; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labesoftware/update/downloads/vpn_free.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003257; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/clr.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003258; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/dianthus.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003259; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/n.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003260; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/newred.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003261; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/omar.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003262; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/serv.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003263; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/test.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003264; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updachrome.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003265; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatedata.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003266; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatev.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003267; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/work.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003268; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/component.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003269; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003270; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/regsvc.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003271; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skygaming/updates/downloads/update.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003272; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/001.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003273; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1488.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003274; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1_cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003275; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003276; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1fc2d.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003277; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/26a5.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003278; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003279; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/abjects.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003280; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/attached.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003281; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/b7f2c.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003282; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/battletext.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003283; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003284; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003285; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003286; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_makros.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003287; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_silent.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003288; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_sup.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003289; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003290; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003291; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003292; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildss.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003293; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientnik.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003294; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientrevers.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003295; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dcrat.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003296; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003297; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003298; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003299; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hans.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003300; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hulu.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003301; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfive.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003302; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfour.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003303; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelone.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003304; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelthree.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003305; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/inteltwo.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003306; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003307; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/kleiman.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003308; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003309; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/notepadplus.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003310; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003311; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003312; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003313; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003314; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/putty.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003315; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/rockethcd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003316; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/scvhost900.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003317; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/sessionwin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003318; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/siliculose.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003319; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/statemobi.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003320; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003321; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003322; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stgedo.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003323; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/svcperf.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003324; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003325; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurjok.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003326; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurusbabac.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003327; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/telekiller.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003328; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateanddr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003329; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateandr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003330; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/vhajeja.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003331; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/word.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003332; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/www.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003333; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/xlsd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003334; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003335; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003336; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmatrix/data/hack1226.exe"; endswith; nocase; http.host; content:"cd.textfiles.com"; classtype:trojan-activity; sid:100003337; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/712408764354920490/829413679866839120/echelon_protected.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003338; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003339; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/816070119281131570/816070273254162442/all.txt"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003340; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/826848185246023750/loaddd.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003341; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/826848348342059008/zeppelin.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003342; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/826848405258633277/build.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003343; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/826198252025675816/826537386485612574/china.png"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003344; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003345; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003346; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/829721030112182363/829724335526510622/dcratbuild.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003347; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razor/rzr-winner_intro.zip"; endswith; nocase; http.host; content:"chiptune.com"; classtype:trojan-activity; sid:100003348; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100003349; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100003350; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meteoradminz/hidden-tear/zip/master"; endswith; nocase; http.host; content:"codeload.github.com"; classtype:trojan-activity; sid:100003351; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; endswith; nocase; http.host; content:"colfincas.com"; classtype:trojan-activity; sid:100003352; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ktcghnmcwws43wzscphukbfnwtuaxidx&revid=0b8z0b7_i5sirk2xrtehmstg0vxvit3b4n3lmbdrdrjrodndrpq"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100003353; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1qze6qzzh1uf7iaj4rqixttznx6u1--gc&revid=0b45wwmcofx7fuvnmdhpkt1d0k3rhzldyoffnuc83auzkslvrpq"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100003354; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; endswith; nocase; http.host; content:"drive.google.com.it-barcelona.com"; classtype:trojan-activity; sid:100003355; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003356; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=11idvvx22jx_1lw-hxnpmlwuvjgdyp63g"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003357; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=12khl-unz2np4q54b2jgpwlsh6cuz0pss"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003358; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003359; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003360; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=16yyvhney9_-nygeipjqgnlcmwfoyiaxo"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003361; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=17pl-4i0otjbyxwrtrdagxxebirdh2wl8"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003362; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003363; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003364; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1br5iufkkmmfeipqo3ecviqykbcdgcnio"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003365; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1bwtwpqmeqdvctbcqcc2gil5xzjf28c0z"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003366; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003367; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003368; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1d0ij6qkgrf6irywv6ftk1m7p5l3weh3a"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003369; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1gprlk2mcrl6law-zk5r0pjogaqrxwepd"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003370; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003371; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003372; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1jdqcxydqvz3bjodp66ieiocbjcz8foi6"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003373; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1l5urks5wzib2zcb16bfsk76bjrdsejms"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003374; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ldxaekbcbzb-zfdix-ucj4rilobnbswx"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003375; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ljz-kmuibyiehba6blw37guu_yr799y0"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003376; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1lsv4sko083sywwjndgqnsh_6sgqodqtu"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003377; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003378; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003379; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003380; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1oek6vmzbv15nyho_uqcbk4_vaq1ezowv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003381; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ph-lri07dohowhmuczrrvjwrtsvmnu9s"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003382; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003383; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1r1flwyfwtyziyr47y5sk3q821r6_tgsl"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003384; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1r9f9irwhutxozsbp2h9erd_a7fa2pwko"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003385; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1s221a6wpx6i7nfrztnhh9priojtybuxq"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003386; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1sutnyikgc4qw-tbvnnvzm8uz9thch0vz"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003387; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003388; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1taubixyqiqdgfbhmc2rv_aitvkbqhzwz"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003389; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1tpd_qbnl_mtmhfsv4a-qtfsnuiimyoy6"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003390; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003391; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vjq92eqivh01yxmal20whl2es3ld6nxb"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003392; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1voqnsh0cmxl5hty4zpc18pgnkud5rtvy"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003393; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vy1nx5zefluh5ewihr-6pcndlyex7xcm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003394; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1wpqa2nnnktbhzs4j0r-erosvgyaagi_a"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003395; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003396; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003397; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003398; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003399; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ywkgalidldb32pio6ywmbyvdk7oar3yy"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003400; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003401; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003402; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/1zilg/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100003403; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/qcgfmfvh/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100003404; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/emclick.zip"; endswith; nocase; http.host; content:"e-mudhra.com"; classtype:trojan-activity; sid:100003405; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe"; endswith; nocase; http.host; content:"evertkok.nl"; classtype:trojan-activity; sid:100003406; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe"; endswith; nocase; http.host; content:"evertkok.nl"; classtype:trojan-activity; sid:100003407; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100003408; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100003409; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100003410; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003411; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003412; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003413; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003414; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; endswith; nocase; http.host; content:"file.elecfans.com"; classtype:trojan-activity; sid:100003415; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100003416; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100003417; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; endswith; nocase; http.host; content:"gist.githubusercontent.com"; classtype:trojan-activity; sid:100003418; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; endswith; nocase; http.host; content:"hqdecig.com"; classtype:trojan-activity; sid:100003419; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/suy/"; endswith; nocase; http.host; content:"hsecaravans.co.uk"; classtype:trojan-activity; sid:100003420; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19/items/startup_20210219/startup.txt"; endswith; nocase; http.host; content:"ia801802.us.archive.org"; classtype:trojan-activity; sid:100003421; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/online-timer-kvhxz/ilxl/"; endswith; nocase; http.host; content:"ie-best.net"; classtype:trojan-activity; sid:100003422; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100003423; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebook/cs17.exe"; endswith; nocase; http.host; content:"jcedu.org"; classtype:trojan-activity; sid:100003424; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100003425; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100003426; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100003427; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; endswith; nocase; http.host; content:"karmakoincodes.weebly.com"; classtype:trojan-activity; sid:100003428; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ds/index.html"; endswith; nocase; http.host; content:"kautilyaclasses.com"; classtype:trojan-activity; sid:100003429; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dg/etrac/nf4emwz/"; endswith; nocase; http.host; content:"kotakwarna.co.id"; classtype:trojan-activity; sid:100003430; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe"; endswith; nocase; http.host; content:"ksh.hu"; classtype:trojan-activity; sid:100003431; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/affiliate/kuaizip_setup_10029.exe"; endswith; nocase; http.host; content:"kuaizip.com"; classtype:trojan-activity; sid:100003432; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linuxforensicscode.zip"; endswith; nocase; http.host; content:"linuxforensicsbook.com.s3.amazonaws.com"; classtype:trojan-activity; sid:100003433; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl8.exe"; endswith; nocase; http.host; content:"lojavirtual.top"; classtype:trojan-activity; sid:100003434; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl8v2.exe"; endswith; nocase; http.host; content:"lojavirtual.top"; classtype:trojan-activity; sid:100003435; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k/big5/1giof6/"; endswith; nocase; http.host; content:"minpic.de"; classtype:trojan-activity; sid:100003436; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-contentbak/t9m/"; endswith; nocase; http.host; content:"morrobaydrugandgift.com"; classtype:trojan-activity; sid:100003437; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; endswith; nocase; http.host; content:"my.cloudme.com"; classtype:trojan-activity; sid:100003438; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/aacenc.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100003439; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/doxillionsetup.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100003440; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/4/1/6/6/4166984/keygen.exe"; endswith; nocase; http.host; content:"newyarlfm.weebly.com"; classtype:trojan-activity; sid:100003441; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; endswith; nocase; http.host; content:"nhipcauytevietnhat.com"; classtype:trojan-activity; sid:100003442; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; endswith; nocase; http.host; content:"note.youdao.com"; classtype:trojan-activity; sid:100003443; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; endswith; nocase; http.host; content:"oldschoolvalue.s3.amazonaws.com"; classtype:trojan-activity; sid:100003444; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20cid=ba02d68febf523dc&resid=ba02d68febf523dc!1431&authkey=afbifi7o9ywbjpm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003445; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20cid=ba02d68febf523dc&resid=ba02d68febf523dc%211431&authkey=afbifi7o9ywbjpm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003446; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003447; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003448; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003449; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003450; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003451; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003452; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003453; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003454; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003455; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003456; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003457; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003458; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003459; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003460; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003461; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003462; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003463; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003464; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003465; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003466; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003467; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003468; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003469; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003470; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003471; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003472; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003473; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d!184&authkey=ackbiiarirejcam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003474; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d%21184&authkey=ackbiiarirejcam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003475; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003476; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003477; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003478; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003479; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0!1667&authkey=an8otd7jzc7xgho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003480; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0%211667&authkey=an8otd7jzc7xgho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003481; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003482; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003483; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003484; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003485; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003486; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003487; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003488; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=15d9646f4dbf9553&resid=15d9646f4dbf9553%21110&authkey=ag0eg1lha_lwgi0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003489; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003490; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003491; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003492; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003493; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003494; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003495; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003496; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003497; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003498; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003499; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003500; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003501; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003502; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003503; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003504; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003505; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003506; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba!112&authkey=afjxmbcllibdbvo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003507; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba!114&authkey=adecqvkvvvadznc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003508; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba%21112&authkey=afjxmbcllibdbvo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003509; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba%21114&authkey=adecqvkvvvadznc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003510; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=216ef243e34992b8&resid=216ef243e34992b8!330&authkey=apiugomnim7heom"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003511; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=216ef243e34992b8&resid=216ef243e34992b8%21330&authkey=apiugomnim7heom"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003512; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=23423a594eafc2de&resid=23423a594eafc2de%21130&authkey=aeh1dm0c-5hp44a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003513; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003514; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003515; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003516; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003517; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003518; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003519; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003520; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003521; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003522; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b!287&authkey=advpfy_0ry8upmi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003523; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b!288&authkey=aembucxemjjo3bk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003524; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b%21287&authkey=advpfy_0ry8upmi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003525; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b%21288&authkey=aembucxemjjo3bk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003526; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003527; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003528; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003529; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003530; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003531; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003532; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003533; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003534; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003535; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003536; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003537; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003538; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3004cdd743a543f5&resid=3004cdd743a543f5%21170&authkey=ao8vz-4rkwuiyn8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003539; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003540; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003541; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003542; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003543; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003544; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003545; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1!223&authkey=aajr842bzum0yg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003546; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003547; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003548; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003549; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003550; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003551; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003552; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003553; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003554; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003555; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003556; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003557; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003558; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003559; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003560; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003561; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003562; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003563; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003564; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3ee68228c34c236d&resid=3ee68228c34c236d%21129&authkey=apll6hu3-xetzxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003565; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003566; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003567; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003568; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003569; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003570; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003571; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003572; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003573; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003574; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003575; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21141&authkey=aazwaw2xjms24o0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003576; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21145&authkey=aaenjqj018fjmc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003577; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003578; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003579; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003580; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003581; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003582; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003583; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003584; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003585; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003586; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003587; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003588; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003589; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003590; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003591; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003592; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003593; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003594; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003595; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003596; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003597; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003598; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003599; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003600; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003601; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003602; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003603; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003604; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003605; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003606; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003607; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003608; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003609; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003610; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003611; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003612; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003613; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003614; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003615; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003616; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003617; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003618; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003619; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003620; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003621; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003622; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003623; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003624; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003625; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003626; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003627; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003628; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003629; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003630; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003631; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003632; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003633; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003634; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003635; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003636; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003637; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003638; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003639; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003640; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003641; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003642; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003643; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003644; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003645; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003646; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003647; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003648; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003649; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003650; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003651; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003652; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003653; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003654; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003655; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003656; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003657; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003658; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003659; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003660; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003661; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003662; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003663; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003664; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003665; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003666; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003667; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003668; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003669; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003670; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003671; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003672; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003673; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003674; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003675; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003676; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003677; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003678; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003679; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003680; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003681; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003682; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003683; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003684; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003685; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003686; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003687; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003688; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003689; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003690; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003691; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003692; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003693; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003694; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003695; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003696; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003697; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003698; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003699; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003700; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003701; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003702; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003703; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003704; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003705; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003706; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003707; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003708; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003709; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003710; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003711; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003712; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003713; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003714; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003715; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003716; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003717; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003718; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003719; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003720; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003721; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003722; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003723; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003724; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003725; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003726; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003727; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003728; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003729; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003730; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003731; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003732; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003733; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003734; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003735; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003736; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003737; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003738; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003739; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=855b20b0e8399717&resid=855b20b0e8399717%21110&authkey=afhxx21ztsd7hbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003740; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003741; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003742; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003743; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003744; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003745; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003746; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003747; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003748; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003749; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003750; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003751; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003752; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003753; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003754; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003755; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!112&authkey=af43qpcgl0t2f5o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003756; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003757; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003758; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003759; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003760; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003761; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003762; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003763; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003764; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003765; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003766; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003767; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003768; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003769; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003770; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003771; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003772; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003773; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003774; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003775; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003776; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003777; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003778; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003779; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003780; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003781; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003782; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003783; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003784; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003785; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003786; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003787; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003788; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003789; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003790; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21256&authkey=aapnly5qifymcvw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003791; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003792; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003793; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003794; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003795; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003796; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003797; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003798; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003799; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003800; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818!129&authkey=aesewk3cf5vbrxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003801; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818%21129&authkey=aesewk3cf5vbrxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003802; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003803; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5!2423&authkey=aoiqjwenlzfiqe0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003804; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212417&authkey=aa2zjoxjz1c83ns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003805; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212418&authkey=akjeumqon_fyj9c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003806; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212423&authkey=aoiqjwenlzfiqe0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003807; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003808; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003809; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003810; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003811; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003812; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003813; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003814; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003815; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003816; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003817; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003818; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003819; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003820; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003821; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003822; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003823; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003824; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003825; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003826; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003827; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003828; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003829; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003830; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003831; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003832; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003833; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ba02d68febf523dc&resid=ba02d68febf523dc%211431&authkey=afbifi7o9ywbjpm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003834; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1047&authkey=aod6jbxyicq2v4g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003835; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211047&authkey=aod6jbxyicq2v4g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003836; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003837; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003838; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003839; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003840; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003841; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003842; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c29fdbf45b3d2671&resid=c29fdbf45b3d2671%21608&authkey=aafwhzmybg1czta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003843; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003844; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003845; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003846; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003847; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003848; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003849; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003850; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003851; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003852; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003853; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003854; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003855; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003856; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003857; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003858; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003859; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003860; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003861; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003862; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003863; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003864; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003865; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003866; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003867; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003868; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003869; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003870; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!357&authkey=alw3vqqxz6myrle"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003871; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!362&authkey=alycl9izrvfl7oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003872; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21354&authkey=aa_ukeour7rex1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003873; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21355&authkey=aajjwf_sm4xdqdk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003874; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21357&authkey=alw3vqqxz6myrle"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003875; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21362&authkey=alycl9izrvfl7oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003876; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003877; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003878; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003879; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003880; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003881; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003882; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003883; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003884; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003885; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003886; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003887; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003888; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003889; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003890; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003891; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d4d413b6e7cf7088&resid=d4d413b6e7cf7088%211271&authkey=akz65bxpgvdxjb8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003892; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003893; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003894; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003895; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003896; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003897; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003898; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003899; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003900; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003901; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003902; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003903; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003904; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003905; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003906; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003907; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003908; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003909; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003910; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003911; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003912; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003913; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2!107&authkey=af-bicrg1c6vgck"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003914; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2%21107&authkey=af-bicrg1c6vgck"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003915; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003916; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003917; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003918; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003919; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003920; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003921; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003922; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003923; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003924; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003925; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003926; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003927; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003928; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003929; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003930; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003931; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003932; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003933; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003934; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003935; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003936; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003937; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003938; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003939; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003940; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003941; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003942; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003943; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003944; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003945; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003946; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003947; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003948; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003949; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003950; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003951; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003952; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003953; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003954; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003955; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003956; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003957; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003958; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003959; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003960; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003961; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003962; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003963; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003964; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21848&authkey=ag1_e421v-t5r9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003965; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003966; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003967; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003968; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003969; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003970; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003971; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003972; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003973; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003974; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003975; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003976; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/77jhk0iw"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100003977; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/89hkc7wb"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100003978; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/yqvsvlvq"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100003979; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/llc/mwcacs65xienqdp/"; endswith; nocase; http.host; content:"pierreconsulting.info"; classtype:trojan-activity; sid:100003980; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skoda22.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100003981; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100003982; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; endswith; nocase; http.host; content:"qjbutterflyevents.co.za"; classtype:trojan-activity; sid:100003983; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100003984; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100003985; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100003986; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100003987; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100003988; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100003989; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myqseeaccount/one/main/one.htm"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100003990; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100003991; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100003992; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100003993; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tennc/webshell/master/other/small_shell.txt"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100003994; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; endswith; nocase; http.host; content:"res.yeshen.com"; classtype:trojan-activity; sid:100003995; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/q05z91"; endswith; nocase; http.host; content:"sendspace.com"; classtype:trojan-activity; sid:100003996; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ey4lpx8rx.zip"; endswith; nocase; http.host; content:"shribharatvatika.com"; classtype:trojan-activity; sid:100003997; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; endswith; nocase; http.host; content:"sites.google.com"; classtype:trojan-activity; sid:100003998; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100003999; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004000; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004001; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004002; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004003; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004004; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004005; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004006; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004007; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004008; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-nurse-ss8d9/z/"; endswith; nocase; http.host; content:"technologydistilled.com"; classtype:trojan-activity; sid:100004009; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crisanar/defis/jek_crackme1.7.zip"; endswith; nocase; http.host; content:"users.skynet.be"; classtype:trojan-activity; sid:100004010; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/amowvegfrt9ja/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100004011; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100004012; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100004013; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100004014; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004015; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb%5efr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004016; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb^fr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004017; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004018; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/151_155/tidex_-_short_stuff.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004019; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syria-files/attach/222/222051_instruction.zip"; endswith; nocase; http.host; content:"wikileaks.org"; classtype:trojan-activity; sid:100004020; rev:1;) -alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/common/yz.vbs"; endswith; nocase; http.host; content:"yp.hnggzyjy.cn"; classtype:trojan-activity; sid:100004021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.139.242"; classtype:trojan-activity; sid:100001515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.212.209"; classtype:trojan-activity; sid:100001516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.253.149"; classtype:trojan-activity; sid:100001517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.71.243"; classtype:trojan-activity; sid:100001518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.98.242"; classtype:trojan-activity; sid:100001519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.144.66"; classtype:trojan-activity; sid:100001520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.225.28"; classtype:trojan-activity; sid:100001521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.227.95"; classtype:trojan-activity; sid:100001522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.234.98"; classtype:trojan-activity; sid:100001523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.191.58"; classtype:trojan-activity; sid:100001524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.135.3"; classtype:trojan-activity; sid:100001525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.132.71"; classtype:trojan-activity; sid:100001526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.160.112"; classtype:trojan-activity; sid:100001527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.176.72"; classtype:trojan-activity; sid:100001528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.83.244"; classtype:trojan-activity; sid:100001529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.20.66"; classtype:trojan-activity; sid:100001530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.249.0"; classtype:trojan-activity; sid:100001531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.83.170"; classtype:trojan-activity; sid:100001532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.85.168"; classtype:trojan-activity; sid:100001533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.221.239.223"; classtype:trojan-activity; sid:100001534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.221.242.95"; classtype:trojan-activity; sid:100001535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.76.80"; classtype:trojan-activity; sid:100001536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.223.242.164"; classtype:trojan-activity; sid:100001537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.129.198"; classtype:trojan-activity; sid:100001538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.154.13"; classtype:trojan-activity; sid:100001539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.212.124"; classtype:trojan-activity; sid:100001540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.58.5"; classtype:trojan-activity; sid:100001541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.40.79.170"; classtype:trojan-activity; sid:100001542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.36.97"; classtype:trojan-activity; sid:100001543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.0.98.131"; classtype:trojan-activity; sid:100001544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.11.51.57"; classtype:trojan-activity; sid:100001545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.13.23.180"; classtype:trojan-activity; sid:100001546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.124.130"; classtype:trojan-activity; sid:100001547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.146.199"; classtype:trojan-activity; sid:100001548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.16.68"; classtype:trojan-activity; sid:100001549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.179.83"; classtype:trojan-activity; sid:100001550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.184.59"; classtype:trojan-activity; sid:100001551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.191.243"; classtype:trojan-activity; sid:100001552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.194.67"; classtype:trojan-activity; sid:100001553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.216.132"; classtype:trojan-activity; sid:100001554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.219.28"; classtype:trojan-activity; sid:100001555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.24.115"; classtype:trojan-activity; sid:100001556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.30.65"; classtype:trojan-activity; sid:100001557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.65.233"; classtype:trojan-activity; sid:100001558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.79.66"; classtype:trojan-activity; sid:100001559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.94.16"; classtype:trojan-activity; sid:100001560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.179.201.26"; classtype:trojan-activity; sid:100001561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.195.84.250"; classtype:trojan-activity; sid:100001562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.138"; classtype:trojan-activity; sid:100001563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.28.7.159"; classtype:trojan-activity; sid:100001564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.30.119.23"; classtype:trojan-activity; sid:100001565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32.208.157.193"; classtype:trojan-activity; sid:100001566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32792.prolocksmithwinterpark.com"; classtype:trojan-activity; sid:100001567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"34.122.44.188"; classtype:trojan-activity; sid:100001568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"34.126.93.163"; classtype:trojan-activity; sid:100001569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"35.184.169.169"; classtype:trojan-activity; sid:100001570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.108.231.218"; classtype:trojan-activity; sid:100001571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.248.83.98"; classtype:trojan-activity; sid:100001572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.250.203.246"; classtype:trojan-activity; sid:100001573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.157.225"; classtype:trojan-activity; sid:100001574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.18.18"; classtype:trojan-activity; sid:100001575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.51.244"; classtype:trojan-activity; sid:100001576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.255.90.219"; classtype:trojan-activity; sid:100001577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.32.28.18"; classtype:trojan-activity; sid:100001578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.160.167"; classtype:trojan-activity; sid:100001579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.34.150.236"; classtype:trojan-activity; sid:100001580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.65.216.145"; classtype:trojan-activity; sid:100001581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.105.159"; classtype:trojan-activity; sid:100001582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.133.125"; classtype:trojan-activity; sid:100001583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.139.36"; classtype:trojan-activity; sid:100001584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.89.18.133"; classtype:trojan-activity; sid:100001585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.91.89.187"; classtype:trojan-activity; sid:100001586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360.lcy2zzx.pw"; classtype:trojan-activity; sid:100001587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360down7.miiyun.cn"; classtype:trojan-activity; sid:100001588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.222.98.51"; classtype:trojan-activity; sid:100001589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.233.60.68"; classtype:trojan-activity; sid:100001590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.179.221"; classtype:trojan-activity; sid:100001591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.180.172"; classtype:trojan-activity; sid:100001592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.44.238.35"; classtype:trojan-activity; sid:100001593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.116.243"; classtype:trojan-activity; sid:100001594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.14.36"; classtype:trojan-activity; sid:100001595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.245.254"; classtype:trojan-activity; sid:100001596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.98.136"; classtype:trojan-activity; sid:100001597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.114.137.102"; classtype:trojan-activity; sid:100001598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.117.31.162"; classtype:trojan-activity; sid:100001599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.162.104.119"; classtype:trojan-activity; sid:100001600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.162.98.216"; classtype:trojan-activity; sid:100001601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.164.112.139"; classtype:trojan-activity; sid:100001602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.196.34"; classtype:trojan-activity; sid:100001603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.104.83"; classtype:trojan-activity; sid:100001604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.125.186"; classtype:trojan-activity; sid:100001605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.146.60"; classtype:trojan-activity; sid:100001606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.206.228"; classtype:trojan-activity; sid:100001607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.171.125"; classtype:trojan-activity; sid:100001608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.249.255"; classtype:trojan-activity; sid:100001609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.60.61"; classtype:trojan-activity; sid:100001610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.167.202"; classtype:trojan-activity; sid:100001611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.67.64"; classtype:trojan-activity; sid:100001612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.10.198"; classtype:trojan-activity; sid:100001613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.163.231"; classtype:trojan-activity; sid:100001614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.168.234"; classtype:trojan-activity; sid:100001615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.203.225"; classtype:trojan-activity; sid:100001616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.215.212"; classtype:trojan-activity; sid:100001617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.194.65"; classtype:trojan-activity; sid:100001618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.78.251"; classtype:trojan-activity; sid:100001619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.113.201"; classtype:trojan-activity; sid:100001620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.114.45"; classtype:trojan-activity; sid:100001621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.150.203"; classtype:trojan-activity; sid:100001622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.123.189"; classtype:trojan-activity; sid:100001623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.166.31"; classtype:trojan-activity; sid:100001624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.218.46"; classtype:trojan-activity; sid:100001625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.91.244"; classtype:trojan-activity; sid:100001626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.93.171"; classtype:trojan-activity; sid:100001627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.127.214"; classtype:trojan-activity; sid:100001628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.18.140"; classtype:trojan-activity; sid:100001629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.191.137"; classtype:trojan-activity; sid:100001630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.205.255"; classtype:trojan-activity; sid:100001631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.24.54"; classtype:trojan-activity; sid:100001632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.36.151"; classtype:trojan-activity; sid:100001633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.37.182"; classtype:trojan-activity; sid:100001634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.251.0"; classtype:trojan-activity; sid:100001635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.27.15"; classtype:trojan-activity; sid:100001636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.29.231"; classtype:trojan-activity; sid:100001637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.70.88"; classtype:trojan-activity; sid:100001638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.83.185.108"; classtype:trojan-activity; sid:100001639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.83.94.11"; classtype:trojan-activity; sid:100001640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.115.152"; classtype:trojan-activity; sid:100001641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.85.54.4"; classtype:trojan-activity; sid:100001642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.211.20"; classtype:trojan-activity; sid:100001643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.234.187"; classtype:trojan-activity; sid:100001644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.78.244"; classtype:trojan-activity; sid:100001645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.93.109"; classtype:trojan-activity; sid:100001646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.96.227"; classtype:trojan-activity; sid:100001647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.143.176"; classtype:trojan-activity; sid:100001648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.233.131"; classtype:trojan-activity; sid:100001649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.67.238"; classtype:trojan-activity; sid:100001650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.72.9"; classtype:trojan-activity; sid:100001651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.145.11"; classtype:trojan-activity; sid:100001652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.36"; classtype:trojan-activity; sid:100001653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.63.23"; classtype:trojan-activity; sid:100001654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.90.86.212"; classtype:trojan-activity; sid:100001655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"40.88.2.151"; classtype:trojan-activity; sid:100001656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.139.209.46"; classtype:trojan-activity; sid:100001657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.165.130.43"; classtype:trojan-activity; sid:100001658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.193.192.100"; classtype:trojan-activity; sid:100001659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.219.185.171"; classtype:trojan-activity; sid:100001660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.226.60.115"; classtype:trojan-activity; sid:100001661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.72.203.82"; classtype:trojan-activity; sid:100001662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.76.157.2"; classtype:trojan-activity; sid:100001663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.147"; classtype:trojan-activity; sid:100001664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.152"; classtype:trojan-activity; sid:100001665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.38"; classtype:trojan-activity; sid:100001666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.59"; classtype:trojan-activity; sid:100001667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.103"; classtype:trojan-activity; sid:100001668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.197"; classtype:trojan-activity; sid:100001669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.48"; classtype:trojan-activity; sid:100001670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.202.101.181"; classtype:trojan-activity; sid:100001671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.202.101.199"; classtype:trojan-activity; sid:100001672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.171.165"; classtype:trojan-activity; sid:100001673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.176.27"; classtype:trojan-activity; sid:100001674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.254.220"; classtype:trojan-activity; sid:100001675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.4.110"; classtype:trojan-activity; sid:100001676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.222.189"; classtype:trojan-activity; sid:100001677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.225.253"; classtype:trojan-activity; sid:100001678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.40.143"; classtype:trojan-activity; sid:100001679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.143.162"; classtype:trojan-activity; sid:100001680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.233.97.141"; classtype:trojan-activity; sid:100001681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.84.85"; classtype:trojan-activity; sid:100001682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.161.72"; classtype:trojan-activity; sid:100001683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.212.157"; classtype:trojan-activity; sid:100001684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.237.114.80"; classtype:trojan-activity; sid:100001685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.238.141.250"; classtype:trojan-activity; sid:100001686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.61.99.155"; classtype:trojan-activity; sid:100001687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.82.217.241"; classtype:trojan-activity; sid:100001688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.230.207.204"; classtype:trojan-activity; sid:100001689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.241.106.183"; classtype:trojan-activity; sid:100001690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.252.8.94"; classtype:trojan-activity; sid:100001691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.203.192"; classtype:trojan-activity; sid:100001692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.135.134.228"; classtype:trojan-activity; sid:100001693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.178"; classtype:trojan-activity; sid:100001694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.182"; classtype:trojan-activity; sid:100001695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.204"; classtype:trojan-activity; sid:100001696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.224.165"; classtype:trojan-activity; sid:100001697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.141.84.184"; classtype:trojan-activity; sid:100001698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.118"; classtype:trojan-activity; sid:100001699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.135"; classtype:trojan-activity; sid:100001700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.213"; classtype:trojan-activity; sid:100001701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.27"; classtype:trojan-activity; sid:100001702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.47"; classtype:trojan-activity; sid:100001703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.94"; classtype:trojan-activity; sid:100001704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.15.143.191"; classtype:trojan-activity; sid:100001705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.248"; classtype:trojan-activity; sid:100001706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.109.205"; classtype:trojan-activity; sid:100001707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.110.146"; classtype:trojan-activity; sid:100001708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.130"; classtype:trojan-activity; sid:100001709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.22.209.58"; classtype:trojan-activity; sid:100001710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.229.53.148"; classtype:trojan-activity; sid:100001711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.27.253.137"; classtype:trojan-activity; sid:100001712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.51.104.59"; classtype:trojan-activity; sid:100001713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.77.9.151"; classtype:trojan-activity; sid:100001714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.85.90.131"; classtype:trojan-activity; sid:100001715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.9.148.37"; classtype:trojan-activity; sid:100001716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.92.108.35"; classtype:trojan-activity; sid:100001717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.95.169.143"; classtype:trojan-activity; sid:100001718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.95.169.147"; classtype:trojan-activity; sid:100001719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.95.169.153"; classtype:trojan-activity; sid:100001720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.172.75.231"; classtype:trojan-activity; sid:100001721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.182.173.247"; classtype:trojan-activity; sid:100001722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.20.63.218"; classtype:trojan-activity; sid:100001723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.214.27.4"; classtype:trojan-activity; sid:100001724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.214.35.50"; classtype:trojan-activity; sid:100001725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.236.65.83"; classtype:trojan-activity; sid:100001726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.24.130.254"; classtype:trojan-activity; sid:100001727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.241.120.165"; classtype:trojan-activity; sid:100001728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.243.179.115"; classtype:trojan-activity; sid:100001729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.249.33.79"; classtype:trojan-activity; sid:100001730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.25.242.211"; classtype:trojan-activity; sid:100001731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.118.86"; classtype:trojan-activity; sid:100001732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.86.128"; classtype:trojan-activity; sid:100001733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.97.76.242"; classtype:trojan-activity; sid:100001734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.136.96.53"; classtype:trojan-activity; sid:100001735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.145.152.26"; classtype:trojan-activity; sid:100001736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.157.97.71"; classtype:trojan-activity; sid:100001737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.16.131.51"; classtype:trojan-activity; sid:100001738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.21.202.98"; classtype:trojan-activity; sid:100001739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.46.231.38"; classtype:trojan-activity; sid:100001740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.162.113"; classtype:trojan-activity; sid:100001741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.87.36"; classtype:trojan-activity; sid:100001742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.143.43.93"; classtype:trojan-activity; sid:100001743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.156.35.166"; classtype:trojan-activity; sid:100001744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.158.201.200"; classtype:trojan-activity; sid:100001745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.158.201.218"; classtype:trojan-activity; sid:100001746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.20.121"; classtype:trojan-activity; sid:100001747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.21.3"; classtype:trojan-activity; sid:100001748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.174.182.99"; classtype:trojan-activity; sid:100001749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.170.49"; classtype:trojan-activity; sid:100001750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.178.183"; classtype:trojan-activity; sid:100001751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.179.129"; classtype:trojan-activity; sid:100001752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.14.122.233"; classtype:trojan-activity; sid:100001753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.188.62.111"; classtype:trojan-activity; sid:100001754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.95.226.154"; classtype:trojan-activity; sid:100001755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.115.174.103"; classtype:trojan-activity; sid:100001756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.115.174.106"; classtype:trojan-activity; sid:100001757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.121.91.255"; classtype:trojan-activity; sid:100001758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.247.83.66"; classtype:trojan-activity; sid:100001759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.252.47.29"; classtype:trojan-activity; sid:100001760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"51.89.77.2"; classtype:trojan-activity; sid:100001761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.114.136"; classtype:trojan-activity; sid:100001762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.180.122"; classtype:trojan-activity; sid:100001763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.114.246.26"; classtype:trojan-activity; sid:100001764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.162.92"; classtype:trojan-activity; sid:100001765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.174.4"; classtype:trojan-activity; sid:100001766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.125.191.4"; classtype:trojan-activity; sid:100001767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.126.247.118"; classtype:trojan-activity; sid:100001768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.141.122.109"; classtype:trojan-activity; sid:100001769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.166.120"; classtype:trojan-activity; sid:100001770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.200.124"; classtype:trojan-activity; sid:100001771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.218.67.253"; classtype:trojan-activity; sid:100001772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.22.212.107"; classtype:trojan-activity; sid:100001773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.226.129.29"; classtype:trojan-activity; sid:100001774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.230.89.42"; classtype:trojan-activity; sid:100001775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.237.125.4"; classtype:trojan-activity; sid:100001776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.238.42.192"; classtype:trojan-activity; sid:100001777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.240.147.97"; classtype:trojan-activity; sid:100001778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.241.78.55"; classtype:trojan-activity; sid:100001779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.242.91.219"; classtype:trojan-activity; sid:100001780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.22.24"; classtype:trojan-activity; sid:100001781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.75.128"; classtype:trojan-activity; sid:100001782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.75.146"; classtype:trojan-activity; sid:100001783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.77.141"; classtype:trojan-activity; sid:100001784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.80.36"; classtype:trojan-activity; sid:100001785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.253.15.184"; classtype:trojan-activity; sid:100001786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.51.219.200"; classtype:trojan-activity; sid:100001787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.153"; classtype:trojan-activity; sid:100001788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.39"; classtype:trojan-activity; sid:100001789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.0.211.161"; classtype:trojan-activity; sid:100001790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.102.168.189"; classtype:trojan-activity; sid:100001791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.202.3"; classtype:trojan-activity; sid:100001792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.214.4"; classtype:trojan-activity; sid:100001793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.173.135.51"; classtype:trojan-activity; sid:100001794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.175.63.177"; classtype:trojan-activity; sid:100001795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.23.114.97"; classtype:trojan-activity; sid:100001796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.26.181.228"; classtype:trojan-activity; sid:100001797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.30.12.254"; classtype:trojan-activity; sid:100001798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.50.23.23"; classtype:trojan-activity; sid:100001799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.89.242.116"; classtype:trojan-activity; sid:100001800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.217.215"; classtype:trojan-activity; sid:100001801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.218.82"; classtype:trojan-activity; sid:100001802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.21.140"; classtype:trojan-activity; sid:100001803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.21.172"; classtype:trojan-activity; sid:100001804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.94.182.212"; classtype:trojan-activity; sid:100001805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.95.175.49"; classtype:trojan-activity; sid:100001806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.170.146"; classtype:trojan-activity; sid:100001807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.13.61.12"; classtype:trojan-activity; sid:100001808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.122.57"; classtype:trojan-activity; sid:100001809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.216.23"; classtype:trojan-activity; sid:100001810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.233.94"; classtype:trojan-activity; sid:100001811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.6.112"; classtype:trojan-activity; sid:100001812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.80.216"; classtype:trojan-activity; sid:100001813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.100.83"; classtype:trojan-activity; sid:100001814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.111.39"; classtype:trojan-activity; sid:100001815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.206.246"; classtype:trojan-activity; sid:100001816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.218.31"; classtype:trojan-activity; sid:100001817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.220.167"; classtype:trojan-activity; sid:100001818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.254.178"; classtype:trojan-activity; sid:100001819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.83.55"; classtype:trojan-activity; sid:100001820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.214.53.159"; classtype:trojan-activity; sid:100001821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.214.85.149"; classtype:trojan-activity; sid:100001822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.177.196"; classtype:trojan-activity; sid:100001823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.86.208"; classtype:trojan-activity; sid:100001824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.4.72"; classtype:trojan-activity; sid:100001825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.51.127"; classtype:trojan-activity; sid:100001826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.60.174"; classtype:trojan-activity; sid:100001827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.8.81"; classtype:trojan-activity; sid:100001828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.10.121"; classtype:trojan-activity; sid:100001829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.8.43"; classtype:trojan-activity; sid:100001830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.146.108.150"; classtype:trojan-activity; sid:100001831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.163.131.67"; classtype:trojan-activity; sid:100001832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.91.194"; classtype:trojan-activity; sid:100001833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.247.224.66"; classtype:trojan-activity; sid:100001834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.150.101"; classtype:trojan-activity; sid:100001835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.101.143"; classtype:trojan-activity; sid:100001836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.186.186"; classtype:trojan-activity; sid:100001837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.241.252"; classtype:trojan-activity; sid:100001838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.57.40"; classtype:trojan-activity; sid:100001839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.9.166"; classtype:trojan-activity; sid:100001840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.97.68"; classtype:trojan-activity; sid:100001841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.98.43"; classtype:trojan-activity; sid:100001842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.99.161"; classtype:trojan-activity; sid:100001843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.117.152"; classtype:trojan-activity; sid:100001844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.103.56"; classtype:trojan-activity; sid:100001845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.180.67"; classtype:trojan-activity; sid:100001846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.181.7"; classtype:trojan-activity; sid:100001847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.57.96.116"; classtype:trojan-activity; sid:100001848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.170.60"; classtype:trojan-activity; sid:100001849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.73.220"; classtype:trojan-activity; sid:100001850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.61.218.23"; classtype:trojan-activity; sid:100001851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.65.172.121"; classtype:trojan-activity; sid:100001852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.0.22"; classtype:trojan-activity; sid:100001853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.104.46"; classtype:trojan-activity; sid:100001854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.110.59"; classtype:trojan-activity; sid:100001855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.195"; classtype:trojan-activity; sid:100001856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.255.60"; classtype:trojan-activity; sid:100001857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.45.130"; classtype:trojan-activity; sid:100001858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.98.144.75"; classtype:trojan-activity; sid:100001859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.1.98.131"; classtype:trojan-activity; sid:100001860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.141.73.58"; classtype:trojan-activity; sid:100001861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.131.205"; classtype:trojan-activity; sid:100001862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.143.46"; classtype:trojan-activity; sid:100001863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.31.126.33"; classtype:trojan-activity; sid:100001864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.149.66"; classtype:trojan-activity; sid:100001865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.43.207.148"; classtype:trojan-activity; sid:100001866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.90.165.236"; classtype:trojan-activity; sid:100001867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"63.245.122.93"; classtype:trojan-activity; sid:100001868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"64.233.154.99"; classtype:trojan-activity; sid:100001869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.125.128.196"; classtype:trojan-activity; sid:100001870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.26.155.131"; classtype:trojan-activity; sid:100001871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.35.61.255"; classtype:trojan-activity; sid:100001872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.108.199.144"; classtype:trojan-activity; sid:100001873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.57.55.210"; classtype:trojan-activity; sid:100001874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.74.7.197"; classtype:trojan-activity; sid:100001875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.97.181.196"; classtype:trojan-activity; sid:100001876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.245.151.203"; classtype:trojan-activity; sid:100001877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.8.138.101"; classtype:trojan-activity; sid:100001878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.83.49.234"; classtype:trojan-activity; sid:100001879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.84.138.165"; classtype:trojan-activity; sid:100001880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.148.103.248"; classtype:trojan-activity; sid:100001881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.174.182.226"; classtype:trojan-activity; sid:100001882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.175.107.153"; classtype:trojan-activity; sid:100001883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.188.144.143"; classtype:trojan-activity; sid:100001884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.204.88.29"; classtype:trojan-activity; sid:100001885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.119.241"; classtype:trojan-activity; sid:100001886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.78.33.33"; classtype:trojan-activity; sid:100001887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.115.37.205"; classtype:trojan-activity; sid:100001888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.120.237.255"; classtype:trojan-activity; sid:100001889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.123.245.151"; classtype:trojan-activity; sid:100001890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.124.231.110"; classtype:trojan-activity; sid:100001891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.127.214.47"; classtype:trojan-activity; sid:100001892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.146.232.34"; classtype:trojan-activity; sid:100001893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.165.173.49"; classtype:trojan-activity; sid:100001894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.196.158.227"; classtype:trojan-activity; sid:100001895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.222.157.166"; classtype:trojan-activity; sid:100001896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.229.0.133"; classtype:trojan-activity; sid:100001897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.63.73.234"; classtype:trojan-activity; sid:100001898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.115.194"; classtype:trojan-activity; sid:100001899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.227.186"; classtype:trojan-activity; sid:100001900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.76.240.206"; classtype:trojan-activity; sid:100001901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.115.31.30"; classtype:trojan-activity; sid:100001902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.118.240.88"; classtype:trojan-activity; sid:100001903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.167.10.180"; classtype:trojan-activity; sid:100001904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.236.190.250"; classtype:trojan-activity; sid:100001905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.25.5.105"; classtype:trojan-activity; sid:100001906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.93.129.118"; classtype:trojan-activity; sid:100001907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.127.148.69"; classtype:trojan-activity; sid:100001908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.146.190.91"; classtype:trojan-activity; sid:100001909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.204.63.239"; classtype:trojan-activity; sid:100001910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.34.191.213"; classtype:trojan-activity; sid:100001911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.40.234.166"; classtype:trojan-activity; sid:100001912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.106.142"; classtype:trojan-activity; sid:100001913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.2.122"; classtype:trojan-activity; sid:100001914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.235.106"; classtype:trojan-activity; sid:100001915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.47.133.58"; classtype:trojan-activity; sid:100001916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.71.60.69"; classtype:trojan-activity; sid:100001917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.85.106.211"; classtype:trojan-activity; sid:100001918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.17.22.30"; classtype:trojan-activity; sid:100001919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.180.98"; classtype:trojan-activity; sid:100001920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.200.62"; classtype:trojan-activity; sid:100001921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.202.249.109"; classtype:trojan-activity; sid:100001922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.214.69.226"; classtype:trojan-activity; sid:100001923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.229.230.118"; classtype:trojan-activity; sid:100001924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.31.40.122"; classtype:trojan-activity; sid:100001925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.112.123.203"; classtype:trojan-activity; sid:100001926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.204.216.103"; classtype:trojan-activity; sid:100001927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.31.139.77"; classtype:trojan-activity; sid:100001928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.70.164.42"; classtype:trojan-activity; sid:100001929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.101.1.159"; classtype:trojan-activity; sid:100001930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.108.224.112"; classtype:trojan-activity; sid:100001931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.195.115.176"; classtype:trojan-activity; sid:100001932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.199.84.77"; classtype:trojan-activity; sid:100001933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.64.139.223"; classtype:trojan-activity; sid:100001934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.75.165.81"; classtype:trojan-activity; sid:100001935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.127.141.52"; classtype:trojan-activity; sid:100001936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.83.102.27"; classtype:trojan-activity; sid:100001937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.99.213.61"; classtype:trojan-activity; sid:100001938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.170.11.82"; classtype:trojan-activity; sid:100001939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.178.22.145"; classtype:trojan-activity; sid:100001940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.217.92.231"; classtype:trojan-activity; sid:100001941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.250.199.133"; classtype:trojan-activity; sid:100001942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.254.129.227"; classtype:trojan-activity; sid:100001943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.84.134.33"; classtype:trojan-activity; sid:100001944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.89.107.69"; classtype:trojan-activity; sid:100001945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.95.12.137"; classtype:trojan-activity; sid:100001946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.237.25.210"; classtype:trojan-activity; sid:100001947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.50.153"; classtype:trojan-activity; sid:100001948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.89.203.238"; classtype:trojan-activity; sid:100001949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77st.net"; classtype:trojan-activity; sid:100001950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.138.98.134"; classtype:trojan-activity; sid:100001951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.145.224.45"; classtype:trojan-activity; sid:100001952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.41.200"; classtype:trojan-activity; sid:100001953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.106.235"; classtype:trojan-activity; sid:100001954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.168.64"; classtype:trojan-activity; sid:100001955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.188.141"; classtype:trojan-activity; sid:100001956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.104.157"; classtype:trojan-activity; sid:100001957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.176.163"; classtype:trojan-activity; sid:100001958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.27.157"; classtype:trojan-activity; sid:100001959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.23.172.81"; classtype:trojan-activity; sid:100001960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.8.225.77"; classtype:trojan-activity; sid:100001961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.11.195.121"; classtype:trojan-activity; sid:100001962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.147.123.48"; classtype:trojan-activity; sid:100001963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.175.42.244"; classtype:trojan-activity; sid:100001964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.21.84.63"; classtype:trojan-activity; sid:100001965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.7.170.58"; classtype:trojan-activity; sid:100001966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.79.58.94"; classtype:trojan-activity; sid:100001967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.8.70.162"; classtype:trojan-activity; sid:100001968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.9.88.185"; classtype:trojan-activity; sid:100001969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.107.89.207"; classtype:trojan-activity; sid:100001970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.19.101.218"; classtype:trojan-activity; sid:100001971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.211.181.77"; classtype:trojan-activity; sid:100001972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.99.128.61"; classtype:trojan-activity; sid:100001973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.136.146.213"; classtype:trojan-activity; sid:100001974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.165.44.109"; classtype:trojan-activity; sid:100001975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.191.40.58"; classtype:trojan-activity; sid:100001976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.198.7.22"; classtype:trojan-activity; sid:100001977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.141.184"; classtype:trojan-activity; sid:100001978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.215.199.29"; classtype:trojan-activity; sid:100001979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.187.113"; classtype:trojan-activity; sid:100001980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.195.216"; classtype:trojan-activity; sid:100001981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.229.230.103"; classtype:trojan-activity; sid:100001982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.244.219.41"; classtype:trojan-activity; sid:100001983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.246.225.203"; classtype:trojan-activity; sid:100001984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.30.177.68"; classtype:trojan-activity; sid:100001985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.92.36.96"; classtype:trojan-activity; sid:100001986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.103.108.72"; classtype:trojan-activity; sid:100001987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.135.196.130"; classtype:trojan-activity; sid:100001988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.85.112"; classtype:trojan-activity; sid:100001989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.207.61.194"; classtype:trojan-activity; sid:100001990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.209.250.155"; classtype:trojan-activity; sid:100001991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.211.156.38"; classtype:trojan-activity; sid:100001992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.59.31.181"; classtype:trojan-activity; sid:100001993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.110.252"; classtype:trojan-activity; sid:100001994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.53.77"; classtype:trojan-activity; sid:100001995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.138.72"; classtype:trojan-activity; sid:100001996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.139.92"; classtype:trojan-activity; sid:100001997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.154.214"; classtype:trojan-activity; sid:100001998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.187.109"; classtype:trojan-activity; sid:100001999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.100.54"; classtype:trojan-activity; sid:100002000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.102.84"; classtype:trojan-activity; sid:100002001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.106.65"; classtype:trojan-activity; sid:100002002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.108.172"; classtype:trojan-activity; sid:100002003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.131.158"; classtype:trojan-activity; sid:100002004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.134.66"; classtype:trojan-activity; sid:100002005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.19.42"; classtype:trojan-activity; sid:100002006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.197.254"; classtype:trojan-activity; sid:100002007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.215.149"; classtype:trojan-activity; sid:100002008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.232.68"; classtype:trojan-activity; sid:100002009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.234.195"; classtype:trojan-activity; sid:100002010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.246.96"; classtype:trojan-activity; sid:100002011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.28.57"; classtype:trojan-activity; sid:100002012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.4.57"; classtype:trojan-activity; sid:100002013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.55.84"; classtype:trojan-activity; sid:100002014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.73.245"; classtype:trojan-activity; sid:100002015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.98.51"; classtype:trojan-activity; sid:100002016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.165.237.163"; classtype:trojan-activity; sid:100002017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.147.99"; classtype:trojan-activity; sid:100002018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.218.42"; classtype:trojan-activity; sid:100002019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.242.253.154"; classtype:trojan-activity; sid:100002020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.252.9.37"; classtype:trojan-activity; sid:100002021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.210.219.213"; classtype:trojan-activity; sid:100002022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.50.118"; classtype:trojan-activity; sid:100002023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.95.204"; classtype:trojan-activity; sid:100002024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.238.24.35"; classtype:trojan-activity; sid:100002025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.247.83.74"; classtype:trojan-activity; sid:100002026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.254.39.129"; classtype:trojan-activity; sid:100002027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.33.111.227"; classtype:trojan-activity; sid:100002028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.40.127.242"; classtype:trojan-activity; sid:100002029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.42.20.217"; classtype:trojan-activity; sid:100002030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; classtype:trojan-activity; sid:100002031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.11.216"; classtype:trojan-activity; sid:100002032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.123.251"; classtype:trojan-activity; sid:100002033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.135.187"; classtype:trojan-activity; sid:100002034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.180.33"; classtype:trojan-activity; sid:100002035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.208.25"; classtype:trojan-activity; sid:100002036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.224.141"; classtype:trojan-activity; sid:100002037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.241.2"; classtype:trojan-activity; sid:100002038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.214.149.236"; classtype:trojan-activity; sid:100002039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.241.39.182"; classtype:trojan-activity; sid:100002040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.250.147.134"; classtype:trojan-activity; sid:100002041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.64.181.50"; classtype:trojan-activity; sid:100002042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.74.215.180"; classtype:trojan-activity; sid:100002043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.130.227"; classtype:trojan-activity; sid:100002044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"86.35.43.220"; classtype:trojan-activity; sid:100002045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"86.98.23.78"; classtype:trojan-activity; sid:100002046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.117.11.46"; classtype:trojan-activity; sid:100002047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.172.19.130"; classtype:trojan-activity; sid:100002048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.251.71.78"; classtype:trojan-activity; sid:100002049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87du.vip"; classtype:trojan-activity; sid:100002050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.119.171.253"; classtype:trojan-activity; sid:100002051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.129.208.43"; classtype:trojan-activity; sid:100002052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.208.71"; classtype:trojan-activity; sid:100002053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.219.179"; classtype:trojan-activity; sid:100002054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.218.17.149"; classtype:trojan-activity; sid:100002055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.225.222.128"; classtype:trojan-activity; sid:100002056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.247.96.19"; classtype:trojan-activity; sid:100002057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.51.139"; classtype:trojan-activity; sid:100002058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.249.13.164"; classtype:trojan-activity; sid:100002059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.249.244.180"; classtype:trojan-activity; sid:100002060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.204.12"; classtype:trojan-activity; sid:100002061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.226.26"; classtype:trojan-activity; sid:100002062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.240.245"; classtype:trojan-activity; sid:100002063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.254.90"; classtype:trojan-activity; sid:100002064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.122.183.130"; classtype:trojan-activity; sid:100002065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.136.197.170"; classtype:trojan-activity; sid:100002066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.22.152.244"; classtype:trojan-activity; sid:100002067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.237.84.19"; classtype:trojan-activity; sid:100002068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.248.112.202"; classtype:trojan-activity; sid:100002069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.29.213.33"; classtype:trojan-activity; sid:100002070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.85.166"; classtype:trojan-activity; sid:100002071; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.87.5"; classtype:trojan-activity; sid:100002072; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8poieq.bn.files.1drv.com"; classtype:trojan-activity; sid:100002073; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"90.152.144.139"; classtype:trojan-activity; sid:100002074; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.132.197.39"; classtype:trojan-activity; sid:100002075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.177.139.132"; classtype:trojan-activity; sid:100002076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.187.103.32"; classtype:trojan-activity; sid:100002077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.212.150.241"; classtype:trojan-activity; sid:100002078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.217.104.185"; classtype:trojan-activity; sid:100002079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.233.112.188"; classtype:trojan-activity; sid:100002080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.234.60.94"; classtype:trojan-activity; sid:100002081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.244.169.139"; classtype:trojan-activity; sid:100002082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.92.16.244"; classtype:trojan-activity; sid:100002083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.114.191.82"; classtype:trojan-activity; sid:100002084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.241.78.114"; classtype:trojan-activity; sid:100002085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.27.246.202"; classtype:trojan-activity; sid:100002086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.54.237.237"; classtype:trojan-activity; sid:100002087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.83.62.139"; classtype:trojan-activity; sid:100002088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.85.18.138"; classtype:trojan-activity; sid:100002089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.157.63.221"; classtype:trojan-activity; sid:100002090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.159.169.190"; classtype:trojan-activity; sid:100002091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.173.235.110"; classtype:trojan-activity; sid:100002092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.21.224.154"; classtype:trojan-activity; sid:100002093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.39.115.176"; classtype:trojan-activity; sid:100002094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.39.79.41"; classtype:trojan-activity; sid:100002095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.137.16"; classtype:trojan-activity; sid:100002096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.182.249"; classtype:trojan-activity; sid:100002097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.206.56"; classtype:trojan-activity; sid:100002098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.57.43.233"; classtype:trojan-activity; sid:100002099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.73.99.102"; classtype:trojan-activity; sid:100002100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.136.69.199"; classtype:trojan-activity; sid:100002101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.143.53.34"; classtype:trojan-activity; sid:100002102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.17.170"; classtype:trojan-activity; sid:100002103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.82.190"; classtype:trojan-activity; sid:100002104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.200.16.22"; classtype:trojan-activity; sid:100002105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.224.83.208"; classtype:trojan-activity; sid:100002106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.53.120.109"; classtype:trojan-activity; sid:100002107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.85.0.3"; classtype:trojan-activity; sid:100002108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.132.129.250"; classtype:trojan-activity; sid:100002109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.133.158.20"; classtype:trojan-activity; sid:100002110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.158.19.130"; classtype:trojan-activity; sid:100002111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.113.227"; classtype:trojan-activity; sid:100002112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.201.34"; classtype:trojan-activity; sid:100002113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.60.146.134"; classtype:trojan-activity; sid:100002114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.66.196.63"; classtype:trojan-activity; sid:100002115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.9.111.51"; classtype:trojan-activity; sid:100002116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.9.120.40"; classtype:trojan-activity; sid:100002117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.239.73.246"; classtype:trojan-activity; sid:100002118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.47.147.169"; classtype:trojan-activity; sid:100002119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.68.140.254"; classtype:trojan-activity; sid:100002120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.96.199.75"; classtype:trojan-activity; sid:100002121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.0.210.218"; classtype:trojan-activity; sid:100002122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.113.239.207"; classtype:trojan-activity; sid:100002123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.116.72.119"; classtype:trojan-activity; sid:100002124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.128.147.115"; classtype:trojan-activity; sid:100002125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.178.242.44"; classtype:trojan-activity; sid:100002126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.30.24.54"; classtype:trojan-activity; sid:100002127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.150.245.203"; classtype:trojan-activity; sid:100002128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.33.195.164"; classtype:trojan-activity; sid:100002129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"a.stro.lo.gy.t.em.r@zytrox.tk"; classtype:trojan-activity; sid:100002130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aatreefelling.co.za"; classtype:trojan-activity; sid:100002131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abcd.bg"; classtype:trojan-activity; sid:100002132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abissnet.net"; classtype:trojan-activity; sid:100002133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aboveandbelow.com.au"; classtype:trojan-activity; sid:100002134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absoftechworld.com"; classtype:trojan-activity; sid:100002135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abyssos.eu"; classtype:trojan-activity; sid:100002136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"academyshademani.com"; classtype:trojan-activity; sid:100002137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acbick.com"; classtype:trojan-activity; sid:100002138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"accesslinksgroup.com"; classtype:trojan-activity; sid:100002139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acellr.co.uk"; classtype:trojan-activity; sid:100002140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acteon.com.ar"; classtype:trojan-activity; sid:100002141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"addahealingmusic.com"; classtype:trojan-activity; sid:100002142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.com"; classtype:trojan-activity; sid:100002143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.memengers.com"; classtype:trojan-activity; sid:100002144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.erapor.smk-alasror.net"; classtype:trojan-activity; sid:100002145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.grandoceanvilla.com"; classtype:trojan-activity; sid:100002146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admission.kmctartskuttippuram.org"; classtype:trojan-activity; sid:100002147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adventureexplorer.in"; classtype:trojan-activity; sid:100002148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aeropilates.cl"; classtype:trojan-activity; sid:100002149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afnan-amc.com"; classtype:trojan-activity; sid:100002150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afrimedspecialist.com"; classtype:trojan-activity; sid:100002151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agemn.co.za"; classtype:trojan-activity; sid:100002152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenciadigitalwdys.com"; classtype:trojan-activity; sid:100002153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenda.gmelloinformatica.com.br"; classtype:trojan-activity; sid:100002154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agentt.ac.ug"; classtype:trojan-activity; sid:100002155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agile8studio.com"; classtype:trojan-activity; sid:100002156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aiecons.com"; classtype:trojan-activity; sid:100002157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aiqtest.com"; classtype:trojan-activity; sid:100002158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajpharmaholding.com"; classtype:trojan-activity; sid:100002159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"akdvidyalaya.com"; classtype:trojan-activity; sid:100002160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"al-wahd.com"; classtype:trojan-activity; sid:100002161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alasdemariposas.org"; classtype:trojan-activity; sid:100002162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alberts.diamondrelationscrm.us"; classtype:trojan-activity; sid:100002163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alemelektronik.com"; classtype:trojan-activity; sid:100002164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alena1971.es"; classtype:trojan-activity; sid:100002165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alexdubai.com.aldiabsteel.com"; classtype:trojan-activity; sid:100002166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alka.institute"; classtype:trojan-activity; sid:100002167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"allforcreative.com.au"; classtype:trojan-activity; sid:100002168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alltheway.travel"; classtype:trojan-activity; sid:100002169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alpaylar.com.tr"; classtype:trojan-activity; sid:100002170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alumni.hildred.ibbott@46.249.33.79"; classtype:trojan-activity; sid:100002171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"am-concepts.ca"; classtype:trojan-activity; sid:100002172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarresdeamorymaestroshechiceros.com"; classtype:trojan-activity; sid:100002173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarteargentina.com.ar"; classtype:trojan-activity; sid:100002174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amos524.org"; classtype:trojan-activity; sid:100002175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ams.alvinasschools.org.ng"; classtype:trojan-activity; sid:100002176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anadelgbt.org"; classtype:trojan-activity; sid:100002177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anantam.net.in"; classtype:trojan-activity; sid:100002178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreelapeyre.com"; classtype:trojan-activity; sid:100002179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andremaraisbeleggings.co.za"; classtype:trojan-activity; sid:100002180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ac.ug"; classtype:trojan-activity; sid:100002181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ug"; classtype:trojan-activity; sid:100002182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreshconcejal.solucioneslink.com"; classtype:trojan-activity; sid:100002183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelsdetour.com"; classtype:trojan-activity; sid:100002184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anurontv.com"; classtype:trojan-activity; sid:100002185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anysbergbiltong.co.za"; classtype:trojan-activity; sid:100002186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apartamentoscitta.com"; classtype:trojan-activity; sid:100002187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api-ms.cobainaja.id"; classtype:trojan-activity; sid:100002188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.cstdevs.com"; classtype:trojan-activity; sid:100002189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apoolcondo.com"; classtype:trojan-activity; sid:100002190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.adsensearticle.com"; classtype:trojan-activity; sid:100002191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.explicitsurveys.co.uk"; classtype:trojan-activity; sid:100002192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.prerana.info"; classtype:trojan-activity; sid:100002193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apps.saintsoporte.com"; classtype:trojan-activity; sid:100002194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aps-scribe.com"; classtype:trojan-activity; sid:100002195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aps-sv.com"; classtype:trojan-activity; sid:100002196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"artedibujoyarquitectura.com"; classtype:trojan-activity; sid:100002197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"arwenyapi.com"; classtype:trojan-activity; sid:100002198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ask-regard.call-save.biz"; classtype:trojan-activity; sid:100002199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atfile.com"; classtype:trojan-activity; sid:100002200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"athenacapsg.com"; classtype:trojan-activity; sid:100002201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atlasconcreteworks.com"; classtype:trojan-activity; sid:100002202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"attach.66rpg.com"; classtype:trojan-activity; sid:100002203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atteuqpotentialunlimited.com"; classtype:trojan-activity; sid:100002204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"augustair.com"; classtype:trojan-activity; sid:100002205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aulist.com"; classtype:trojan-activity; sid:100002206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"australianpga.com.au"; classtype:trojan-activity; sid:100002207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"automaticrefreshments.com"; classtype:trojan-activity; sid:100002208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"avadhanagames.com"; classtype:trojan-activity; sid:100002209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aventuramotorhome.com"; classtype:trojan-activity; sid:100002210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"awumad01.top"; classtype:trojan-activity; sid:100002211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"awuqze02.top"; classtype:trojan-activity; sid:100002212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ayahuascasp.com.br"; classtype:trojan-activity; sid:100002213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ayamallah.com"; classtype:trojan-activity; sid:100002214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azmeasurement.com"; classtype:trojan-activity; sid:100002215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azraktours.com"; classtype:trojan-activity; sid:100002216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"b.r.uce.lee.b.es.t@zytrox.tk"; classtype:trojan-activity; sid:100002217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"b2b.toptanakaryakit.com.tr"; classtype:trojan-activity; sid:100002218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"backgrounds.pk"; classtype:trojan-activity; sid:100002219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"badeggdesign.com"; classtype:trojan-activity; sid:100002220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bakamla.go.id"; classtype:trojan-activity; sid:100002221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"balealgodon.mx"; classtype:trojan-activity; sid:100002222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bangkok-orchids.com"; classtype:trojan-activity; sid:100002223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bangladeshunbound.com"; classtype:trojan-activity; sid:100002224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bary.sz4h.com"; classtype:trojan-activity; sid:100002225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bash.givemexyz.in"; classtype:trojan-activity; sid:100002226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; classtype:trojan-activity; sid:100002227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bavhome.com"; classtype:trojan-activity; sid:100002228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bbia.co.uk"; classtype:trojan-activity; sid:100002229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcmt.elin.co.za"; classtype:trojan-activity; sid:100002230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcrg.co.za"; classtype:trojan-activity; sid:100002231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bdnextrend.xyz"; classtype:trojan-activity; sid:100002232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beanx88.xyz"; classtype:trojan-activity; sid:100002233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bearcatpumps.com.cn"; classtype:trojan-activity; sid:100002234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beautincollagen.rs"; classtype:trojan-activity; sid:100002235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beautymomentsgt.de"; classtype:trojan-activity; sid:100002236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bekape.co.id"; classtype:trojan-activity; sid:100002237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beor360.com"; classtype:trojan-activity; sid:100002238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bespokeweddings.ie"; classtype:trojan-activity; sid:100002239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bestcarenepal.com"; classtype:trojan-activity; sid:100002240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betone.co.kr"; classtype:trojan-activity; sid:100002241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beveragesmiami.solucioneslink.com"; classtype:trojan-activity; sid:100002242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bhavaniengineering.com"; classtype:trojan-activity; sid:100002243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bigmikesupplies.co.za"; classtype:trojan-activity; sid:100002244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilbosaquet.ug"; classtype:trojan-activity; sid:100002245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilhen.co.za"; classtype:trojan-activity; sid:100002246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"billing.rahitechnosoft.com"; classtype:trojan-activity; sid:100002247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"binoy.stalphonsamissionva.org"; classtype:trojan-activity; sid:100002248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"biometrico.gpotecnosystems.com"; classtype:trojan-activity; sid:100002249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bioskey.com"; classtype:trojan-activity; sid:100002250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birdi.elin.co.za"; classtype:trojan-activity; sid:100002251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birminghamlink.org"; classtype:trojan-activity; sid:100002252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bizztradingbot.nl"; classtype:trojan-activity; sid:100002253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bl4n3.zadns.co.za"; classtype:trojan-activity; sid:100002254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.callensaxen.com"; classtype:trojan-activity; sid:100002255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.difusodesign.com"; classtype:trojan-activity; sid:100002256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.oyinblogs.com"; classtype:trojan-activity; sid:100002257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.takbelit.com"; classtype:trojan-activity; sid:100002258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bmlifestyle.co.uk"; classtype:trojan-activity; sid:100002259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"boatpecas.com.br"; classtype:trojan-activity; sid:100002260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bodenstein.co.za"; classtype:trojan-activity; sid:100002261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bodylanguage.santulan.co.in"; classtype:trojan-activity; sid:100002262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"booksearch.com"; classtype:trojan-activity; sid:100002263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bophelocare.co.za"; classtype:trojan-activity; sid:100002264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bounces.mi-fs.com"; classtype:trojan-activity; sid:100002265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"boutiqueofferte.com"; classtype:trojan-activity; sid:100002266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bpo.correct.go.th"; classtype:trojan-activity; sid:100002267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bradleyinstitute.co.za"; classtype:trojan-activity; sid:100002268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brandtrust.com.pk"; classtype:trojan-activity; sid:100002269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"braunfinancial.com.au"; classtype:trojan-activity; sid:100002270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brendanquine.com"; classtype:trojan-activity; sid:100002271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brideofmessiah.com"; classtype:trojan-activity; sid:100002272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightaffiliatesales.org"; classtype:trojan-activity; sid:100002273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightmega.com"; classtype:trojan-activity; sid:100002274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightstarshop.com"; classtype:trojan-activity; sid:100002275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"browardinsurancemiami.solucioneslink.com"; classtype:trojan-activity; sid:100002276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bt2.elin.co.za"; classtype:trojan-activity; sid:100002277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"btdapi.robotake.com"; classtype:trojan-activity; sid:100002278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buigiaphat.com.vn"; classtype:trojan-activity; sid:100002279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bullseyemedia.in"; classtype:trojan-activity; sid:100002280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"busandvanrentalmalaysia.com"; classtype:trojan-activity; sid:100002281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buscascolegios.diit.cl"; classtype:trojan-activity; sid:100002282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"business.softberg.ro"; classtype:trojan-activity; sid:100002283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"business2.softberg.ro"; classtype:trojan-activity; sid:100002284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c.ompact.i.o.np.d.yu@zytrox.tk"; classtype:trojan-activity; sid:100002285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c.oooooooooo.ga"; classtype:trojan-activity; sid:100002286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c0140529.ferozo.com"; classtype:trojan-activity; sid:100002287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"caballo.com.au"; classtype:trojan-activity; sid:100002288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cacaoprojects.com"; classtype:trojan-activity; sid:100002289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"calgaryautorepairservice.com"; classtype:trojan-activity; sid:100002290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"callbury.in"; classtype:trojan-activity; sid:100002291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"camminachetipassa.it"; classtype:trojan-activity; sid:100002292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"canadianwork.cc"; classtype:trojan-activity; sid:100002293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capitalgroup-kw.com"; classtype:trojan-activity; sid:100002294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capoeiraventrelivre.com"; classtype:trojan-activity; sid:100002295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cashyinvestment.org"; classtype:trojan-activity; sid:100002296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"casiomaneflirt.cf"; classtype:trojan-activity; sid:100002297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"catchpoolshetlands.co.uk"; classtype:trojan-activity; sid:100002298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cazyacustomfurniture.com"; classtype:trojan-activity; sid:100002299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cbn.hypervoizd.com"; classtype:trojan-activity; sid:100002300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ccauthority.net"; classtype:trojan-activity; sid:100002301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cdaonline.com.ar"; classtype:trojan-activity; sid:100002302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cec.asso.ac-amiens.fr"; classtype:trojan-activity; sid:100002303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cellas.sk"; classtype:trojan-activity; sid:100002304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cendekiabinaaksara.com"; classtype:trojan-activity; sid:100002305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cfs5.tistory.com"; classtype:trojan-activity; sid:100002306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ch.rmu.ac.th"; classtype:trojan-activity; sid:100002307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"changematterscounselling.com"; classtype:trojan-activity; sid:100002308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chardhamdodham.com"; classtype:trojan-activity; sid:100002309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chezalice.co.za"; classtype:trojan-activity; sid:100002310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"childselect.com"; classtype:trojan-activity; sid:100002311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile.myvnc.com"; classtype:trojan-activity; sid:100002312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile80.myvnc.com"; classtype:trojan-activity; sid:100002313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cible-energy.com"; classtype:trojan-activity; sid:100002314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cifeer.net"; classtype:trojan-activity; sid:100002315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citiconstructioncorp.com"; classtype:trojan-activity; sid:100002316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citihits.lk"; classtype:trojan-activity; sid:100002317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citssolutions.co.za"; classtype:trojan-activity; sid:100002318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cityglobalgospel.com"; classtype:trojan-activity; sid:100002319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"civi.istmejia.com"; classtype:trojan-activity; sid:100002320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cleanbydesignllc.com"; classtype:trojan-activity; sid:100002321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cloud.fc.co.mz"; classtype:trojan-activity; sid:100002322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cnc.tacobelllover.tk"; classtype:trojan-activity; sid:100002323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"codsambal.com"; classtype:trojan-activity; sid:100002324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colorpak.pl"; classtype:trojan-activity; sid:100002325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"columbia.aula-web.net"; classtype:trojan-activity; sid:100002326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"community.reimclub.com"; classtype:trojan-activity; sid:100002327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"competancy.indigoconsult.net"; classtype:trojan-activity; sid:100002328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"conceptimagine.ro"; classtype:trojan-activity; sid:100002329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"config.cqhbkjzx.com"; classtype:trojan-activity; sid:100002330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"connectcapital.com.br"; classtype:trojan-activity; sid:100002331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"constructoralyon.com"; classtype:trojan-activity; sid:100002332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"consulateins.solucioneslink.com"; classtype:trojan-activity; sid:100002333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"contributeindustry.com"; classtype:trojan-activity; sid:100002334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"copelandscapes.com"; classtype:trojan-activity; sid:100002335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"corwin-tommie06f.ru.com"; classtype:trojan-activity; sid:100002336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"coulsongraphics.com"; classtype:trojan-activity; sid:100002337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"count.mail.163.com.impactmedfoundation.com"; classtype:trojan-activity; sid:100002338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"covid19.cyberschool.or.id"; classtype:trojan-activity; sid:100002339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"covid19vaccinations.hopto.org"; classtype:trojan-activity; sid:100002340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cr-sq.com"; classtype:trojan-activity; sid:100002341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"craftech.nxtnet.ga"; classtype:trojan-activity; sid:100002342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crearechile.cl"; classtype:trojan-activity; sid:100002343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"creationskateboards.com"; classtype:trojan-activity; sid:100002344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crecerco.com"; classtype:trojan-activity; sid:100002345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crittersbythebay.com"; classtype:trojan-activity; sid:100002346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crm.notariavieitoyvelamazan.com"; classtype:trojan-activity; sid:100002347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crmfarko.manivelasst.com"; classtype:trojan-activity; sid:100002348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crmroche.manivelasst.com"; classtype:trojan-activity; sid:100002349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crscorretordeimoveis.com.br"; classtype:trojan-activity; sid:100002350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cse-engineer.com"; classtype:trojan-activity; sid:100002351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"csnserver.com"; classtype:trojan-activity; sid:100002352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cubescargoexpress.com"; classtype:trojan-activity; sid:100002353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"curasoles.co.za"; classtype:trojan-activity; sid:100002354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"currantmedia.com"; classtype:trojan-activity; sid:100002355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cwa.mx"; classtype:trojan-activity; sid:100002356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cyclomove.com"; classtype:trojan-activity; sid:100002357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cynkon.kairoscs.net"; classtype:trojan-activity; sid:100002358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"czsl.91756.cn"; classtype:trojan-activity; sid:100002359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d.powerofwish.com"; classtype:trojan-activity; sid:100002360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d9.99ddd.com"; classtype:trojan-activity; sid:100002361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"da.alibuf.com"; classtype:trojan-activity; sid:100002362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"danaevara.com"; classtype:trojan-activity; sid:100002363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dartoonpictures.com"; classtype:trojan-activity; sid:100002364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.cdevelop.org"; classtype:trojan-activity; sid:100002365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.over-blog-kiwi.com"; classtype:trojan-activity; sid:100002366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datapolish.com"; classtype:trojan-activity; sid:100002367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dating.khokhas.co.za"; classtype:trojan-activity; sid:100002368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datsom.vn"; classtype:trojan-activity; sid:100002369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davethompson.me.uk"; classtype:trojan-activity; sid:100002370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davidmcguinness.info"; classtype:trojan-activity; sid:100002371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dayspringdaisies.com"; classtype:trojan-activity; sid:100002372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dd.qiyuea.cn"; classtype:trojan-activity; sid:100002373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"de.gsearch.com.de"; classtype:trojan-activity; sid:100002374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"decifrar.com.br"; classtype:trojan-activity; sid:100002375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"deigratia2.elin.co.za"; classtype:trojan-activity; sid:100002376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dekovizyon.com"; classtype:trojan-activity; sid:100002377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo-cliente.mindcreative.com.br"; classtype:trojan-activity; sid:100002378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo.glassforcars.com.au"; classtype:trojan-activity; sid:100002379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo6.hiites.com"; classtype:trojan-activity; sid:100002380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dent-estet.com"; classtype:trojan-activity; sid:100002381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dental.xiaoxiao.media"; classtype:trojan-activity; sid:100002382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dentalalliance.se"; classtype:trojan-activity; sid:100002383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"desertlandtrd.com"; classtype:trojan-activity; sid:100002384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"designerliving.co.za"; classtype:trojan-activity; sid:100002385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"despertaresi.com.br"; classtype:trojan-activity; sid:100002386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"destinymc.co.za"; classtype:trojan-activity; sid:100002387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"detorre.es"; classtype:trojan-activity; sid:100002388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.sebpo.net"; classtype:trojan-activity; sid:100002389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.watch-store.eu"; classtype:trojan-activity; sid:100002390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dezcom.com"; classtype:trojan-activity; sid:100002391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfcf.91756.cn"; classtype:trojan-activity; sid:100002392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"diamantenegro.mi-fs.com"; classtype:trojan-activity; sid:100002393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dienmayminhhung.com"; classtype:trojan-activity; sid:100002394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"digilib.dianhusada.ac.id"; classtype:trojan-activity; sid:100002395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"digisails.org"; classtype:trojan-activity; sid:100002396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"disinfection-cleaning.co.za"; classtype:trojan-activity; sid:100002397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"djking.f3322.net"; classtype:trojan-activity; sid:100002398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.1003b.56a.com"; classtype:trojan-activity; sid:100002399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.198424.com"; classtype:trojan-activity; sid:100002400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.installcdn-aws.com"; classtype:trojan-activity; sid:100002401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.packetstormsecurity.net"; classtype:trojan-activity; sid:100002402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.pandasecur.com"; classtype:trojan-activity; sid:100002403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.rina-roleplay.com"; classtype:trojan-activity; sid:100002404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dnn.alibuf.com"; classtype:trojan-activity; sid:100002405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dns.alibuf.com"; classtype:trojan-activity; sid:100002406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dockerupdate.anondns.net"; classtype:trojan-activity; sid:100002407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"docman.orientalservices.in"; classtype:trojan-activity; sid:100002408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dodsonimaging.com"; classtype:trojan-activity; sid:100002409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"doitunlimited.com"; classtype:trojan-activity; sid:100002410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dokan.blueberrytec.com"; classtype:trojan-activity; sid:100002411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom.daf.free.fr"; classtype:trojan-activity; sid:100002412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"doncedyhall.com"; classtype:trojan-activity; sid:100002413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donghobinhminh.com"; classtype:trojan-activity; sid:100002414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dongphuctop.com"; classtype:trojan-activity; sid:100002415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosman.pl"; classtype:trojan-activity; sid:100002416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dovberger.com"; classtype:trojan-activity; sid:100002417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.pcclear.com"; classtype:trojan-activity; sid:100002418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.udashi.com"; classtype:trojan-activity; sid:100002419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.webbora.com"; classtype:trojan-activity; sid:100002420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down1.arpun.com"; classtype:trojan-activity; sid:100002421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.caihong.com"; classtype:trojan-activity; sid:100002422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.doumaibiji.cn"; classtype:trojan-activity; sid:100002423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.exrnybuf.cn"; classtype:trojan-activity; sid:100002424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.kaobeitu.com"; classtype:trojan-activity; sid:100002425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.pdf00.cn"; classtype:trojan-activity; sid:100002426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.rising.com.cn"; classtype:trojan-activity; sid:100002427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.skycn.com"; classtype:trojan-activity; sid:100002428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.zjsyawqj.cn"; classtype:trojan-activity; sid:100002429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dragonsknot.com"; classtype:trojan-activity; sid:100002430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drbaby.com.sa"; classtype:trojan-activity; sid:100002431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dream.pics"; classtype:trojan-activity; sid:100002432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drgroup.co.za"; classtype:trojan-activity; sid:100002433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drools-moved.46999.n3.nabble.com"; classtype:trojan-activity; sid:100002434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drsha.innovativesolutions.mobi"; classtype:trojan-activity; sid:100002435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsenterprize.co.za"; classtype:trojan-activity; sid:100002436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsspainting.com"; classtype:trojan-activity; sid:100002437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"du-wizards.com"; classtype:trojan-activity; sid:100002438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duque.guantanameratravel.com"; classtype:trojan-activity; sid:100002439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dutapp.wisolve.co.za"; classtype:trojan-activity; sid:100002440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duvalcharter.dekitout.com"; classtype:trojan-activity; sid:100002441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dw2.co.id"; classtype:trojan-activity; sid:100002442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dx.qqyewu.com"; classtype:trojan-activity; sid:100002443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dzinestudio87.co.uk"; classtype:trojan-activity; sid:100002444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e-commerce.saleensuporte.com.br"; classtype:trojan-activity; sid:100002445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e.sldov.ru"; classtype:trojan-activity; sid:100002446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eandgdesign.com.ng"; classtype:trojan-activity; sid:100002447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ebruyatkin.com"; classtype:trojan-activity; sid:100002448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"edu.saicraftsman.com"; classtype:trojan-activity; sid:100002449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"efficientegroup.com"; classtype:trojan-activity; sid:100002450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"elbauldenora.com"; classtype:trojan-activity; sid:100002451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"emaids.co.za"; classtype:trojan-activity; sid:100002452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"emaz.pk"; classtype:trojan-activity; sid:100002453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"en.baoend.com"; classtype:trojan-activity; sid:100002454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enc-tech.com"; classtype:trojan-activity; sid:100002455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"endurotanzania.co.tz"; classtype:trojan-activity; sid:100002456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ennovate.elin.co.za"; classtype:trojan-activity; sid:100002457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"equimination.ee"; classtype:trojan-activity; sid:100002458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"erp.nanotechproautocare.com"; classtype:trojan-activity; sid:100002459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"esaja09.top"; classtype:trojan-activity; sid:100002460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"escola.probommar.org.br"; classtype:trojan-activity; sid:100002461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eservices.immigration.gov.lk"; classtype:trojan-activity; sid:100002462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"esnconsultants.com"; classtype:trojan-activity; sid:100002463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"essentia.org.br"; classtype:trojan-activity; sid:100002464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eubanks7.com"; classtype:trojan-activity; sid:100002465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"europeanzonexxi.com"; classtype:trojan-activity; sid:100002466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exilum.com"; classtype:trojan-activity; sid:100002467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exitoalfaomega.co"; classtype:trojan-activity; sid:100002468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"extrovertoffers.com"; classtype:trojan-activity; sid:100002469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"f1sol.com"; classtype:trojan-activity; sid:100002470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"familydentist.site"; classtype:trojan-activity; sid:100002471; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"faveraprojects.com"; classtype:trojan-activity; sid:100002472; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fc.co.mz"; classtype:trojan-activity; sid:100002473; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"felicienne.nl"; classtype:trojan-activity; sid:100002474; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"files.martellexpress.us"; classtype:trojan-activity; sid:100002475; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"files6.uludagbilisim.com"; classtype:trojan-activity; sid:100002476; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"final.makkahkmcc.com"; classtype:trojan-activity; sid:100002477; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fineartgallerym.com"; classtype:trojan-activity; sid:100002478; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fisconline.bar"; classtype:trojan-activity; sid:100002479; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fisconline.casa"; classtype:trojan-activity; sid:100002480; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fix-america-now.org"; classtype:trojan-activity; sid:100002481; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fkd.derpcity.ru"; classtype:trojan-activity; sid:100002482; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flexypay.dsquaregroup.com"; classtype:trojan-activity; sid:100002483; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flintspin.com"; classtype:trojan-activity; sid:100002484; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flyingbuddhadesign.com"; classtype:trojan-activity; sid:100002485; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fmjplastering.co.uk"; classtype:trojan-activity; sid:100002486; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"follower.instantcashback.in"; classtype:trojan-activity; sid:100002487; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foothills.com.br"; classtype:trojan-activity; sid:100002488; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"footweardirect.elin.co.za"; classtype:trojan-activity; sid:100002489; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"forum.mdb.nu"; classtype:trojan-activity; sid:100002490; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fotoobjetivo.com"; classtype:trojan-activity; sid:100002491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foundationrepairhoustontx.net"; classtype:trojan-activity; sid:100002492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foxeps.com.br"; classtype:trojan-activity; sid:100002493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freecnetdownload.com"; classtype:trojan-activity; sid:100002494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freisites.com.br"; classtype:trojan-activity; sid:100002495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ftp.n3twork30cm.ml"; classtype:trojan-activity; sid:100002496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fullelectronica.com.ar"; classtype:trojan-activity; sid:100002497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"funletters.net"; classtype:trojan-activity; sid:100002498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fusionfiresolutions.com"; classtype:trojan-activity; sid:100002499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"futbolpr.com"; classtype:trojan-activity; sid:100002500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"futuregraphics.com.ar"; classtype:trojan-activity; sid:100002501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"g.pinmonkey.xyz"; classtype:trojan-activity; sid:100002502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gametwogame.com"; classtype:trojan-activity; sid:100002503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garciadogshow.com"; classtype:trojan-activity; sid:100002504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow.myvnc.com"; classtype:trojan-activity; sid:100002505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow4.myvnc.com"; classtype:trojan-activity; sid:100002506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gastoudergonny.nl"; classtype:trojan-activity; sid:100002507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gbbulls.co.uk"; classtype:trojan-activity; sid:100002508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gcpc.co.id.chronoscurtain.com"; classtype:trojan-activity; sid:100002509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"generaldeviales.com"; classtype:trojan-activity; sid:100002510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfmodd1.webselffiles01.com"; classtype:trojan-activity; sid:100002511; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfold1.webselffiles01.com"; classtype:trojan-activity; sid:100002512; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghettohub.co.za"; classtype:trojan-activity; sid:100002513; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghislain.dartois.pagesperso-orange.fr"; classtype:trojan-activity; sid:100002514; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giadungg7.com"; classtype:trojan-activity; sid:100002515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giddos.ga"; classtype:trojan-activity; sid:100002516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giteletropical.com"; classtype:trojan-activity; sid:100002517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"glowinmedia.co.ke"; classtype:trojan-activity; sid:100002518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmtransformationacademy.com"; classtype:trojan-activity; sid:100002519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmvadmission.org"; classtype:trojan-activity; sid:100002520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnimelf.net"; classtype:trojan-activity; sid:100002521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnscrew.ro"; classtype:trojan-activity; sid:100002522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gold.investforex.id"; classtype:trojan-activity; sid:100002523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcake.co.id"; classtype:trojan-activity; sid:100002524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com"; classtype:trojan-activity; sid:100002525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com.au"; classtype:trojan-activity; sid:100002526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"golden-memories-funerals.yourpageserver.com"; classtype:trojan-activity; sid:100002527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldenasiacapital.com"; classtype:trojan-activity; sid:100002528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldmen.in"; classtype:trojan-activity; sid:100002529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gpotecnosystems.com"; classtype:trojan-activity; sid:100002530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gracejukes.com"; classtype:trojan-activity; sid:100002531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"grupoinmare.com"; classtype:trojan-activity; sid:100002532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gruposelt.000webhostapp.com"; classtype:trojan-activity; sid:100002533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gs.monerorx.com"; classtype:trojan-activity; sid:100002534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"guide-to-cell-phones.com"; classtype:trojan-activity; sid:100002535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gulfac-house.com"; classtype:trojan-activity; sid:100002536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gvpcdpgc.edu.in"; classtype:trojan-activity; sid:100002537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"h.epelcdn.com"; classtype:trojan-activity; sid:100002538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"habbotips.free.fr"; classtype:trojan-activity; sid:100002539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hagebakken.no"; classtype:trojan-activity; sid:100002540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hamptonpartyoffive.com"; classtype:trojan-activity; sid:100002541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hashmati.com"; classtype:trojan-activity; sid:100002542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hassanproduct.com"; classtype:trojan-activity; sid:100002543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hchfug.org"; classtype:trojan-activity; sid:100002544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hd11315.com"; classtype:trojan-activity; sid:100002545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hdkamera2003.hu"; classtype:trojan-activity; sid:100002546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hds.sz4h.com"; classtype:trojan-activity; sid:100002547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hellogorgeous.com.au"; classtype:trojan-activity; sid:100002548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"help.hizuko.com"; classtype:trojan-activity; sid:100002549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"helpdeskserver.epelcdn.com"; classtype:trojan-activity; sid:100002550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"herchinfitout.com.sg"; classtype:trojan-activity; sid:100002551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hhaward.org"; classtype:trojan-activity; sid:100002552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandroadcoc.com"; classtype:trojan-activity; sid:100002553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandslasvegas.atakdev.com"; classtype:trojan-activity; sid:100002554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hindi.factsriver.com"; classtype:trojan-activity; sid:100002555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hiptool.net"; classtype:trojan-activity; sid:100002556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitpe.com"; classtype:trojan-activity; sid:100002557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitstation.nl"; classtype:trojan-activity; sid:100002558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hmpmall.co.kr"; classtype:trojan-activity; sid:100002559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoagietesting10.com"; classtype:trojan-activity; sid:100002560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoayeuthuong-my.sharepoint.com"; classtype:trojan-activity; sid:100002561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"homefindersolutions.com"; classtype:trojan-activity; sid:100002562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hometownchick.com"; classtype:trojan-activity; sid:100002563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hookedupboatclub.com"; classtype:trojan-activity; sid:100002564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostingparacolombia.com"; classtype:trojan-activity; sid:100002565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostzaa.com"; classtype:trojan-activity; sid:100002566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hr2019.vrcom7.com"; classtype:trojan-activity; sid:100002567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hseda.com"; classtype:trojan-activity; sid:100002568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"htownbars.com"; classtype:trojan-activity; sid:100002569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hubtech.co.za"; classtype:trojan-activity; sid:100002570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"huellacero.cl"; classtype:trojan-activity; sid:100002571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hunchomusichub.com"; classtype:trojan-activity; sid:100002572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hunggiang.vn"; classtype:trojan-activity; sid:100002573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"husamiyahschool.com"; classtype:trojan-activity; sid:100002574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"i.n.t.e.rloca.l.qs.j.y@jfas.top"; classtype:trojan-activity; sid:100002575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iabmixx2020.rayadigital.online"; classtype:trojan-activity; sid:100002576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iam313.com"; classtype:trojan-activity; sid:100002577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"icon.shatangmu.cn"; classtype:trojan-activity; sid:100002578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idea-secure-login.com"; classtype:trojan-activity; sid:100002579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idilsoft.com"; classtype:trojan-activity; sid:100002580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idj.no"; classtype:trojan-activity; sid:100002581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idvindia.com"; classtype:trojan-activity; sid:100002582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ieclb.com.br"; classtype:trojan-activity; sid:100002583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ikexpert.com"; classtype:trojan-activity; sid:100002584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ilrafrica.com"; classtype:trojan-activity; sid:100002585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"images.jermiau.com"; classtype:trojan-activity; sid:100002586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"imbueautoworx.co.za"; classtype:trojan-activity; sid:100002587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"in-tune2016.com"; classtype:trojan-activity; sid:100002588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incrediblepixels.com"; classtype:trojan-activity; sid:100002589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incredicole.com"; classtype:trojan-activity; sid:100002590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"indrasbikaner.com"; classtype:trojan-activity; sid:100002591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infair.vn"; classtype:trojan-activity; sid:100002592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infovator.com"; classtype:trojan-activity; sid:100002593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"initialnetworks.com"; classtype:trojan-activity; sid:100002594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inodesthetotaldesigners.com"; classtype:trojan-activity; sid:100002595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inrajahmundry.co.in"; classtype:trojan-activity; sid:100002596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"instantindialoan.com"; classtype:trojan-activity; sid:100002597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intersel-idf.org"; classtype:trojan-activity; sid:100002598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intuitiveideas.com.my"; classtype:trojan-activity; sid:100002599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inversiones.arrayanfinanciero.cl"; classtype:trojan-activity; sid:100002600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"invest.xpcorporative.com.br"; classtype:trojan-activity; sid:100002601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ipmes.ma"; classtype:trojan-activity; sid:100002602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iremart.es"; classtype:trojan-activity; sid:100002603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iris101.co.uk"; classtype:trojan-activity; sid:100002604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isaac.mikhailmotoringschool.com"; classtype:trojan-activity; sid:100002605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iscamenabe.com"; classtype:trojan-activity; sid:100002606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isiphephelocon.co.za"; classtype:trojan-activity; sid:100002607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ismf.com.ng"; classtype:trojan-activity; sid:100002608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iso-dubai.net"; classtype:trojan-activity; sid:100002609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"israrulhaq.me"; classtype:trojan-activity; sid:100002610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isrorg.com"; classtype:trojan-activity; sid:100002611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isso.ps"; classtype:trojan-activity; sid:100002612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"it123.ru"; classtype:trojan-activity; sid:100002613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"italiandirezione.casa"; classtype:trojan-activity; sid:100002614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itc-demo.softgig.co.ke"; classtype:trojan-activity; sid:100002615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itsrlytry.000webhostapp.com"; classtype:trojan-activity; sid:100002616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jaishomo.info"; classtype:trojan-activity; sid:100002617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamiekaylive.com"; classtype:trojan-activity; sid:100002618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamshed.pk"; classtype:trojan-activity; sid:100002619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jansen-heesch.nl"; classtype:trojan-activity; sid:100002620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jathra.co.uk"; classtype:trojan-activity; sid:100002621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jay.diamondrelationscrm.us"; classtype:trojan-activity; sid:100002622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jebs.net.au"; classtype:trojan-activity; sid:100002623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jeffdahlke.com"; classtype:trojan-activity; sid:100002624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jfas.top"; classtype:trojan-activity; sid:100002625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jhayesconsulting.com"; classtype:trojan-activity; sid:100002626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jiaoyuzixun.cn"; classtype:trojan-activity; sid:100002627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jing-da.com.tw"; classtype:trojan-activity; sid:100002628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jmtc.91756.cn"; classtype:trojan-activity; sid:100002629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jnanbharati.com"; classtype:trojan-activity; sid:100002630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jobs.thebeessolution.com"; classtype:trojan-activity; sid:100002631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"joelbonissilver.com"; classtype:trojan-activity; sid:100002632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"join.cl8movement.co.za"; classtype:trojan-activity; sid:100002633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"josegene.com"; classtype:trojan-activity; sid:100002634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jpwoodfordco.com"; classtype:trojan-activity; sid:100002635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jumpmanualjacobhiller.com"; classtype:trojan-activity; sid:100002636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jupiter.toxsl.in"; classtype:trojan-activity; sid:100002637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"justinscott.com.au"; classtype:trojan-activity; sid:100002638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kadigital.co.uk"; classtype:trojan-activity; sid:100002639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalawatihomes.com"; classtype:trojan-activity; sid:100002640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalogirosfinance.com"; classtype:trojan-activity; sid:100002641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kaptaanchapal.com"; classtype:trojan-activity; sid:100002642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"karer.by"; classtype:trojan-activity; sid:100002643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"katanvetov.co.il"; classtype:trojan-activity; sid:100002644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"katelynn9506a.ru.com"; classtype:trojan-activity; sid:100002645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kensingtondriving.com"; classtype:trojan-activity; sid:100002646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ketofitnessexpert.com"; classtype:trojan-activity; sid:100002647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kevinjewelry.com.co"; classtype:trojan-activity; sid:100002648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"keywatch.yourpageserver.com"; classtype:trojan-activity; sid:100002649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kingssa.co.za"; classtype:trojan-activity; sid:100002650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kjcpromo.com"; classtype:trojan-activity; sid:100002651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kleinendeli.co.za"; classtype:trojan-activity; sid:100002652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"korrectconceptservices.com"; classtype:trojan-activity; sid:100002653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"krisbadminton.com"; classtype:trojan-activity; sid:100002654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ktb.sch.id"; classtype:trojan-activity; sid:100002655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kubatoglubaklava.com.tr"; classtype:trojan-activity; sid:100002656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kumaralok.in"; classtype:trojan-activity; sid:100002657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kwanfromhongkong.com"; classtype:trojan-activity; sid:100002658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kz.sldov.ru"; classtype:trojan-activity; sid:100002659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"l.oc.atevur.c@zytrox.tk"; classtype:trojan-activity; sid:100002660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lacasadelosalebrijes.com"; classtype:trojan-activity; sid:100002661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lameguard.ru"; classtype:trojan-activity; sid:100002662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laodongnhat.vn"; classtype:trojan-activity; sid:100002663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laravel.pointersoftwares.com.br"; classtype:trojan-activity; sid:100002664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lasermobilesounds.co.uk"; classtype:trojan-activity; sid:100002665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lauratomismith.com"; classtype:trojan-activity; sid:100002666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lautarosanmiguel.com"; classtype:trojan-activity; sid:100002667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lawforall.edu.lk"; classtype:trojan-activity; sid:100002668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lawschoolideas.xyz"; classtype:trojan-activity; sid:100002669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lceventos.net"; classtype:trojan-activity; sid:100002670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ld.mediaget.com"; classtype:trojan-activity; sid:100002671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ldgcorp.com"; classtype:trojan-activity; sid:100002672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"learning.real-academy.net"; classtype:trojan-activity; sid:100002673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leasiacherise.com"; classtype:trojan-activity; sid:100002674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leczkregoslup.acelero.pl"; classtype:trojan-activity; sid:100002675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"legend.nu"; classtype:trojan-activity; sid:100002676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leluibuffet.com.br"; classtype:trojan-activity; sid:100002677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lestesteux.ca"; classtype:trojan-activity; sid:100002678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.arihantmbainstitute.ac.in"; classtype:trojan-activity; sid:100002679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.uib.ac.id"; classtype:trojan-activity; sid:100002680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lidoraggiodisole.it"; classtype:trojan-activity; sid:100002681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lifebeam.elin.co.za"; classtype:trojan-activity; sid:100002682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lindnerelektroanlagen.de"; classtype:trojan-activity; sid:100002683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"linkintec.cn"; classtype:trojan-activity; sid:100002684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"liquidaz.casa"; classtype:trojan-activity; sid:100002685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"livetrack.in"; classtype:trojan-activity; sid:100002686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lloydsindian.co.uk"; classtype:trojan-activity; sid:100002687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lm.stagingarea.co.za"; classtype:trojan-activity; sid:100002688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lmaancha.co.il"; classtype:trojan-activity; sid:100002689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.cstdevs.com"; classtype:trojan-activity; sid:100002690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.login2.in"; classtype:trojan-activity; sid:100002691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"location-voitures.ma"; classtype:trojan-activity; sid:100002692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"login.trezor.com.stockfootagesindia.com"; classtype:trojan-activity; sid:100002693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"logotypfabriken.se"; classtype:trojan-activity; sid:100002694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotix.de"; classtype:trojan-activity; sid:100002695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotusanddragonfly.com"; classtype:trojan-activity; sid:100002696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.definerisco.com"; classtype:trojan-activity; sid:100002697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.difusodesign.com"; classtype:trojan-activity; sid:100002698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ltc.typoten.com"; classtype:trojan-activity; sid:100002699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luckybrownie.com"; classtype:trojan-activity; sid:100002700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luminouspneuma.com"; classtype:trojan-activity; sid:100002701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luxomodels.com"; classtype:trojan-activity; sid:100002702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m-technics.kz"; classtype:trojan-activity; sid:100002703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m.estudiomoros.com.ar"; classtype:trojan-activity; sid:100002704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"madicon.co.za"; classtype:trojan-activity; sid:100002705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"magianegramagiablancayamarres.com"; classtype:trojan-activity; sid:100002706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.bs-eiendomme.co.za"; classtype:trojan-activity; sid:100002707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.golimoapp.com"; classtype:trojan-activity; sid:100002708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.jeffsono.org"; classtype:trojan-activity; sid:100002709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maksi.feb.unib.ac.id"; classtype:trojan-activity; sid:100002710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malaya.tv"; classtype:trojan-activity; sid:100002711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malwarecoding.github.io"; classtype:trojan-activity; sid:100002712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managemysalon.in"; classtype:trojan-activity; sid:100002713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manantialesdelnorte.uy"; classtype:trojan-activity; sid:100002714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manhtien.net"; classtype:trojan-activity; sid:100002715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marcapinyo.ru"; classtype:trojan-activity; sid:100002716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mario-sunjic.com"; classtype:trojan-activity; sid:100002717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariobrown.net"; classtype:trojan-activity; sid:100002718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariotessarollo.com"; classtype:trojan-activity; sid:100002719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketinfosales.com"; classtype:trojan-activity; sid:100002720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketing.enexusgroup.com.au"; classtype:trojan-activity; sid:100002721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marksidfgs.ug"; classtype:trojan-activity; sid:100002722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"masjidhabeebiyarazviya.mysunni.com"; classtype:trojan-activity; sid:100002723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mastersofclientretention.com.au"; classtype:trojan-activity; sid:100002724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"materialescantu.com"; classtype:trojan-activity; sid:100002725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"matruchhaya.co.in"; classtype:trojan-activity; sid:100002726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxtox.com.pk"; classtype:trojan-activity; sid:100002727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbgrm.com"; classtype:trojan-activity; sid:100002728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbjtimes.com"; classtype:trojan-activity; sid:100002729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbsolutions.ge"; classtype:trojan-activity; sid:100002730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mdasa.elin.co.za"; classtype:trojan-activity; sid:100002731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medevlb.org"; classtype:trojan-activity; sid:100002732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"media-server.skyinternet.com.pk"; classtype:trojan-activity; sid:100002733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medianews.ge"; classtype:trojan-activity; sid:100002734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mediawaysnews.com"; classtype:trojan-activity; sid:100002735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medistaffconsulting.com"; classtype:trojan-activity; sid:100002736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meeweb.com"; classtype:trojan-activity; sid:100002737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"megagynreformas.com.br"; classtype:trojan-activity; sid:100002738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"megamart.afnan-amc.com"; classtype:trojan-activity; sid:100002739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mehainteriors.com"; classtype:trojan-activity; sid:100002740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"merkathink.com"; classtype:trojan-activity; sid:100002741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mertlog.com"; classtype:trojan-activity; sid:100002742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"metalin-cr.com"; classtype:trojan-activity; sid:100002743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mettaanand.org"; classtype:trojan-activity; sid:100002744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meuoculosnanet.com.br"; classtype:trojan-activity; sid:100002745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mfevr.com"; classtype:trojan-activity; sid:100002746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot.myvnc.com"; classtype:trojan-activity; sid:100002747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot80.myvnc.com"; classtype:trojan-activity; sid:100002748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"micalle.com.au"; classtype:trojan-activity; sid:100002749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michaelphilip.com"; classtype:trojan-activity; sid:100002750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michimal2.000webhostapp.com"; classtype:trojan-activity; sid:100002751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microblading.mirliandias.com.br"; classtype:trojan-activity; sid:100002752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microcomm-group.com"; classtype:trojan-activity; sid:100002753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mikhailmotoringschool.com"; classtype:trojan-activity; sid:100002754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mills-skyla30ec.com"; classtype:trojan-activity; sid:100002755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mingguanwms.com"; classtype:trojan-activity; sid:100002756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"minuevavida.org"; classtype:trojan-activity; sid:100002757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mirror.mypage.sk"; classtype:trojan-activity; sid:100002758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mis.nbcc.ac.th"; classtype:trojan-activity; sid:100002759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"misterson.com"; classtype:trojan-activity; sid:100002760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mkontakt.az"; classtype:trojan-activity; sid:100002761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mktf.mx"; classtype:trojan-activity; sid:100002762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mmdx.com"; classtype:trojan-activity; sid:100002763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mmogollon.com.mx"; classtype:trojan-activity; sid:100002764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mncarteam.com"; classtype:trojan-activity; sid:100002765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modelhouseturkey.com"; classtype:trojan-activity; sid:100002766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modernmanna.org"; classtype:trojan-activity; sid:100002767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"monetization.business"; classtype:trojan-activity; sid:100002768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moninediy.com"; classtype:trojan-activity; sid:100002769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moreirawag.ac.ug"; classtype:trojan-activity; sid:100002770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"motorcomunicacion.com"; classtype:trojan-activity; sid:100002771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moumitas.com"; classtype:trojan-activity; sid:100002772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"msacontabil.com.br"; classtype:trojan-activity; sid:100002773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mumgee.co.za"; classtype:trojan-activity; sid:100002774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"muzimbiti.xigubo.co.mz"; classtype:trojan-activity; sid:100002775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mvb.kz"; classtype:trojan-activity; sid:100002776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mxpiqw.am.files.1drv.com"; classtype:trojan-activity; sid:100002777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mydatebook.in"; classtype:trojan-activity; sid:100002778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mymlql.com"; classtype:trojan-activity; sid:100002779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myritz.vettickal.com"; classtype:trojan-activity; sid:100002780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mysalons.in"; classtype:trojan-activity; sid:100002781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myscape.in"; classtype:trojan-activity; sid:100002782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mysura.it"; classtype:trojan-activity; sid:100002783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"naeemacademy.com"; classtype:trojan-activity; sid:100002784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"namnyak.co.ke"; classtype:trojan-activity; sid:100002785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nap.mgsservers.com"; classtype:trojan-activity; sid:100002786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"navayurveda.in"; classtype:trojan-activity; sid:100002787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nec-i.com"; classtype:trojan-activity; sid:100002788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nelitrianggraeni.000webhostapp.com"; classtype:trojan-activity; sid:100002789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nerve.untergrund.net"; classtype:trojan-activity; sid:100002790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nettube.com.br"; classtype:trojan-activity; sid:100002791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"networkwheels.co.za"; classtype:trojan-activity; sid:100002792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newfuture.fr"; classtype:trojan-activity; sid:100002793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newinfinitysynergy.com"; classtype:trojan-activity; sid:100002794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newtreedesign.co.uk"; classtype:trojan-activity; sid:100002795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newvisionopticallab.com"; classtype:trojan-activity; sid:100002796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newxing.com"; classtype:trojan-activity; sid:100002797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nextdigitalday.ru"; classtype:trojan-activity; sid:100002798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ngdaycare.co.za"; classtype:trojan-activity; sid:100002799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nguyenkekhuyen.com"; classtype:trojan-activity; sid:100002800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nhorangtreem.com"; classtype:trojan-activity; sid:100002801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nicolas.ug"; classtype:trojan-activity; sid:100002802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nidhi.iexist.in"; classtype:trojan-activity; sid:100002803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nikanpolimer.ir"; classtype:trojan-activity; sid:100002804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilehouse.co.ug"; classtype:trojan-activity; sid:100002805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilinkeji.com"; classtype:trojan-activity; sid:100002806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nimboohomes.com"; classtype:trojan-activity; sid:100002807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"njtiledesigncenter.com"; classtype:trojan-activity; sid:100002808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nobius.org"; classtype:trojan-activity; sid:100002809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nocalnoodle.elin.co.za"; classtype:trojan-activity; sid:100002810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nomadicbees.com"; classtype:trojan-activity; sid:100002811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"northnodegroup.com.au"; classtype:trojan-activity; sid:100002812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"notamuzikaletleri.com"; classtype:trojan-activity; sid:100002813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ns1.the-widyantos.com"; classtype:trojan-activity; sid:100002814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nsb.org.uk"; classtype:trojan-activity; sid:100002815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nurmarkaz.org"; classtype:trojan-activity; sid:100002816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nxtnet.ga"; classtype:trojan-activity; sid:100002817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nyasabigbullets.com"; classtype:trojan-activity; sid:100002818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nyeh2o.com.au"; classtype:trojan-activity; sid:100002819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"obseques-conseils.com"; classtype:trojan-activity; sid:100002820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oecteam.com"; classtype:trojan-activity; sid:100002821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohe.ie"; classtype:trojan-activity; sid:100002822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohsewgorgeous.co.uk"; classtype:trojan-activity; sid:100002823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oleholeh.memangbeda.website"; classtype:trojan-activity; sid:100002824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaia.org"; classtype:trojan-activity; sid:100002825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaromatic.com"; classtype:trojan-activity; sid:100002826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omega.az"; classtype:trojan-activity; sid:100002827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oms.pappai.com"; classtype:trojan-activity; sid:100002828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omscoc.pappai.com"; classtype:trojan-activity; sid:100002829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedigitalcard.granvizionnecorp.com"; classtype:trojan-activity; sid:100002830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedrive.listifyapp.co"; classtype:trojan-activity; sid:100002831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"online.creedglobal.in"; classtype:trojan-activity; sid:100002832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"open.warehousesaas.co.uk"; classtype:trojan-activity; sid:100002833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opolis.io"; classtype:trojan-activity; sid:100002834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"optimus.com.sg"; classtype:trojan-activity; sid:100002835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"order.bizpeed.com"; classtype:trojan-activity; sid:100002836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orientgatewayltd.com"; classtype:trojan-activity; sid:100002837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orion445.com"; classtype:trojan-activity; sid:100002838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orlina.be"; classtype:trojan-activity; sid:100002839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oserve.pk"; classtype:trojan-activity; sid:100002840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ot.weenets.com"; classtype:trojan-activity; sid:100002841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ozemag.com"; classtype:trojan-activity; sid:100002842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p1.lingpao8.com"; classtype:trojan-activity; sid:100002843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p3.zbjimg.com"; classtype:trojan-activity; sid:100002844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p6.zbjimg.com"; classtype:trojan-activity; sid:100002845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pablobrothel.com.ar"; classtype:trojan-activity; sid:100002846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacificgroup.ws"; classtype:trojan-activity; sid:100002847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacwebdesigns.com"; classtype:trojan-activity; sid:100002848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pagos.krayem.com.mx"; classtype:trojan-activity; sid:100002849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"palochusvet.szm.com"; classtype:trojan-activity; sid:100002850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"panslimiterd.com"; classtype:trojan-activity; sid:100002851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parallel.rockvideos.at"; classtype:trojan-activity; sid:100002852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parejasfelices.mi-fs.com"; classtype:trojan-activity; sid:100002853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parkhussion.com"; classtype:trojan-activity; sid:100002854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pastorpaulocosta.com"; classtype:trojan-activity; sid:100002855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.51lg.com"; classtype:trojan-activity; sid:100002856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.99ddd.com"; classtype:trojan-activity; sid:100002857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch3.99ddd.com"; classtype:trojan-activity; sid:100002858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paths.elin.co.za"; classtype:trojan-activity; sid:100002859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patriotsupremehemp.com"; classtype:trojan-activity; sid:100002860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paulmercier.biz"; classtype:trojan-activity; sid:100002861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payerrealty.com"; classtype:trojan-activity; sid:100002862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payments.atifsiddiqui.me"; classtype:trojan-activity; sid:100002863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pcsoori.com"; classtype:trojan-activity; sid:100002864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pd.oceaniarp.net"; classtype:trojan-activity; sid:100002865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pemdodo.com"; classtype:trojan-activity; sid:100002866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perfumeriamontes.es"; classtype:trojan-activity; sid:100002867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"periodiche.bar"; classtype:trojan-activity; sid:100002868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpus.onlineman7-jombang.sch.id"; classtype:trojan-activity; sid:100002869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpustekim.untirta.ac.id"; classtype:trojan-activity; sid:100002870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pestoclean.co.uk"; classtype:trojan-activity; sid:100002871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"petercollie.com"; classtype:trojan-activity; sid:100002872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ph4s.ru"; classtype:trojan-activity; sid:100002873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phasdesign.com"; classtype:trojan-activity; sid:100002874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phenhuong.sanpham.online"; classtype:trojan-activity; sid:100002875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phittc.com"; classtype:trojan-activity; sid:100002876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"photo360.kubooking.com"; classtype:trojan-activity; sid:100002877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pink99.com"; classtype:trojan-activity; sid:100002878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"plasfan.ind.br"; classtype:trojan-activity; sid:100002879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"playground2.grupoaliadasca.com"; classtype:trojan-activity; sid:100002880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pmglance.startwriteup.com"; classtype:trojan-activity; sid:100002881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pokojewewladyslawowie.pl"; classtype:trojan-activity; sid:100002882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pole.com.vc"; classtype:trojan-activity; sid:100002883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pool.phxdir.com"; classtype:trojan-activity; sid:100002884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pooltablemoversdenver.net"; classtype:trojan-activity; sid:100002885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"posmicrosystems.com"; classtype:trojan-activity; sid:100002886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"poulman.panagiotopoulos-tours.gr"; classtype:trojan-activity; sid:100002887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ppdb.smk-ciptaskill.sch.id"; classtype:trojan-activity; sid:100002888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestasicash.com.ar"; classtype:trojan-activity; sid:100002889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestigehomeautomation.net"; classtype:trojan-activity; sid:100002890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"preview2.behalen.com"; classtype:trojan-activity; sid:100002891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prishaartcreations.com"; classtype:trojan-activity; sid:100002892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"production.sparshims.com"; classtype:trojan-activity; sid:100002893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"programaoperadoronline.com.br"; classtype:trojan-activity; sid:100002894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"project.exquitec.com"; classtype:trojan-activity; sid:100002895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promotoradescomplica.com.br"; classtype:trojan-activity; sid:100002896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promoversdubai.com"; classtype:trojan-activity; sid:100002897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq.elin.co.za"; classtype:trojan-activity; sid:100002898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq2.elin.co.za"; classtype:trojan-activity; sid:100002899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosoc.nl"; classtype:trojan-activity; sid:100002900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosyarmakassar.com"; classtype:trojan-activity; sid:100002901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"provence.elin.co.za"; classtype:trojan-activity; sid:100002902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prox.realunix.cc"; classtype:trojan-activity; sid:100002903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pujashoppe.in"; classtype:trojan-activity; sid:100002904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punchdialogues.com"; classtype:trojan-activity; sid:100002905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punjabdevelopersassociation.com.pk"; classtype:trojan-activity; sid:100002906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pvcprinting.co.uk"; classtype:trojan-activity; sid:100002907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qadir.tickfa.ir"; classtype:trojan-activity; sid:100002908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qatarglobalconsulting.com"; classtype:trojan-activity; sid:100002909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qmsled.com"; classtype:trojan-activity; sid:100002910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qu.o.t.ev.v.n.r@zytrox.tk"; classtype:trojan-activity; sid:100002911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"quartier-midi.be"; classtype:trojan-activity; sid:100002912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"querocar.com"; classtype:trojan-activity; sid:100002913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rachmat-assuhaimi.my.id"; classtype:trojan-activity; sid:100002914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"radioafifense.deploys.live"; classtype:trojan-activity; sid:100002915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rainbowisp.info"; classtype:trojan-activity; sid:100002916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rajeshtailang.com"; classtype:trojan-activity; sid:100002917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rakeshkhatri.in"; classtype:trojan-activity; sid:100002918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"raodigitalmedia.com"; classtype:trojan-activity; sid:100002919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"raquelhelena.com.br"; classtype:trojan-activity; sid:100002920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rarlabarchiver.ac"; classtype:trojan-activity; sid:100002921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rasadbar.ir"; classtype:trojan-activity; sid:100002922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rashika.ascarvalho.co.za"; classtype:trojan-activity; sid:100002923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ratemyfenancialadvisor.com"; classtype:trojan-activity; sid:100002924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ravenproductionsltd.com"; classtype:trojan-activity; sid:100002925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ravo.net.au"; classtype:trojan-activity; sid:100002926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rc.ixiaoyang.cn"; classtype:trojan-activity; sid:100002927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rcmesilva.charbelsales.com.br"; classtype:trojan-activity; sid:100002928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reacredit.com.br"; classtype:trojan-activity; sid:100002929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"readwrite26.nl"; classtype:trojan-activity; sid:100002930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"readymmade.com"; classtype:trojan-activity; sid:100002931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"recyclethesurplus.com"; classtype:trojan-activity; sid:100002932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redbats.co.in"; classtype:trojan-activity; sid:100002933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redboxmultimedia.com"; classtype:trojan-activity; sid:100002934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redchillicrackers.com"; classtype:trojan-activity; sid:100002935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reifenquick.de"; classtype:trojan-activity; sid:100002936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"renehavis.com.ua"; classtype:trojan-activity; sid:100002937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"repatriacioncolombia.com"; classtype:trojan-activity; sid:100002938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"res.uf1.cn"; classtype:trojan-activity; sid:100002939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reseller.digimitra.in"; classtype:trojan-activity; sid:100002940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reseller.itechbrasil.com"; classtype:trojan-activity; sid:100002941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"resuco.net"; classtype:trojan-activity; sid:100002942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rezkabum.ru"; classtype:trojan-activity; sid:100002943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rhema.com.sg"; classtype:trojan-activity; sid:100002944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richmondminerals.co.zm"; classtype:trojan-activity; sid:100002945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinaefoundation.org.za"; classtype:trojan-activity; sid:100002946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinkaisystem-ht.com"; classtype:trojan-activity; sid:100002947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"riverfox.co.za"; classtype:trojan-activity; sid:100002948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkcable.co.in"; classtype:trojan-activity; sid:100002949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkverify.securestudies.com"; classtype:trojan-activity; sid:100002950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertmcardle.com"; classtype:trojan-activity; sid:100002951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertsinclair.net"; classtype:trojan-activity; sid:100002952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"romanianpoints.com"; classtype:trojan-activity; sid:100002953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ronnietucker.co.uk"; classtype:trojan-activity; sid:100002954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roomsvc.servegate.kr"; classtype:trojan-activity; sid:100002955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roshnijewellery.com"; classtype:trojan-activity; sid:100002956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rotronics.com.ph"; classtype:trojan-activity; sid:100002957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rsgym.net"; classtype:trojan-activity; sid:100002958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubazar.pro"; classtype:trojan-activity; sid:100002959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubycityvietnam.com"; classtype:trojan-activity; sid:100002960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruisgood.ru"; classtype:trojan-activity; sid:100002961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruwadalkuwait.com"; classtype:trojan-activity; sid:100002962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.51shijuan.com"; classtype:trojan-activity; sid:100002963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.hu.d.es.h.d.u.e54.78.16247@46.249.33.79"; classtype:trojan-activity; sid:100002964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.thechinesemuslim.com"; classtype:trojan-activity; sid:100002965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sacredscentsonline.com"; classtype:trojan-activity; sid:100002966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sadmahfuneralservices.co.za"; classtype:trojan-activity; sid:100002967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safcol-colors.com"; classtype:trojan-activity; sid:100002968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safehubsecurity.ca"; classtype:trojan-activity; sid:100002969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safety.nanotechproautocare.com"; classtype:trojan-activity; sid:100002970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sahathaikasetpan.com"; classtype:trojan-activity; sid:100002971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sainzim.co.za"; classtype:trojan-activity; sid:100002972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"saisoftwareinc.com"; classtype:trojan-activity; sid:100002973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"salecorner.yourpageserver.com"; classtype:trojan-activity; sid:100002974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"salonsaifa.com"; classtype:trojan-activity; sid:100002975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"samriddhijyotish.com"; classtype:trojan-activity; sid:100002976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sandovalgraphics.com"; classtype:trojan-activity; sid:100002977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"santyago.org"; classtype:trojan-activity; sid:100002978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sasystemsuk.com"; classtype:trojan-activity; sid:100002979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scarfaceindustries.com"; classtype:trojan-activity; sid:100002980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scglobal.co.th"; classtype:trojan-activity; sid:100002981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schalke04rss.de"; classtype:trojan-activity; sid:100002982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scheff.com"; classtype:trojan-activity; sid:100002983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schoolbustracker.softgig.co.ke"; classtype:trojan-activity; sid:100002984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sculetus.nl"; classtype:trojan-activity; sid:100002985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"secure-doc-reader.com"; classtype:trojan-activity; sid:100002986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"secure.activedirect.xyz"; classtype:trojan-activity; sid:100002987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"segalsmetals.elin.co.za"; classtype:trojan-activity; sid:100002988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sellmyphonela.com"; classtype:trojan-activity; sid:100002989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"selltechtoday.com"; classtype:trojan-activity; sid:100002990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"senbiaojita.com"; classtype:trojan-activity; sid:100002991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sentierodelviandante.ml"; classtype:trojan-activity; sid:100002992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serendibsourcing.com"; classtype:trojan-activity; sid:100002993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sericaasia.com"; classtype:trojan-activity; sid:100002994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd.myvnc.com"; classtype:trojan-activity; sid:100002995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd80.myvnc.com"; classtype:trojan-activity; sid:100002996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serviciovirtual.com.ar"; classtype:trojan-activity; sid:100002997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sexologistpakistan.net"; classtype:trojan-activity; sid:100002998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sgb.ac.ke"; classtype:trojan-activity; sid:100002999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sgessy.com.br"; classtype:trojan-activity; sid:100003000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shaheentbfoundation.com"; classtype:trojan-activity; sid:100003001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shahikhana.cstdevs.com"; classtype:trojan-activity; sid:100003002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shahu66.com"; classtype:trojan-activity; sid:100003003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shalombaptistchapel.com"; classtype:trojan-activity; sid:100003004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharkrigs.com"; classtype:trojan-activity; sid:100003005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharpelevators.in"; classtype:trojan-activity; sid:100003006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shembefoundation.com"; classtype:trojan-activity; sid:100003007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shidditourism.com"; classtype:trojan-activity; sid:100003008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shivakunwar.com.np"; classtype:trojan-activity; sid:100003009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shoblasaathitrust.org"; classtype:trojan-activity; sid:100003010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shomalhouse.com"; classtype:trojan-activity; sid:100003011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shooka-co.com"; classtype:trojan-activity; sid:100003012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shop.goldspot.agency"; classtype:trojan-activity; sid:100003013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shopsofe.com"; classtype:trojan-activity; sid:100003014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sibernetix.fr"; classtype:trojan-activity; sid:100003015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sige.brisainformatica.com.br"; classtype:trojan-activity; sid:100003016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"signatureads.co.in"; classtype:trojan-activity; sid:100003017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siili.net"; classtype:trojan-activity; sid:100003018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simoneporzi.it"; classtype:trojan-activity; sid:100003019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simorsint.com"; classtype:trojan-activity; sid:100003020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simplithy.co.uk"; classtype:trojan-activity; sid:100003021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindicato1ucm.cl"; classtype:trojan-activity; sid:100003022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindpol.tiejuris.com.br"; classtype:trojan-activity; sid:100003023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sipahielektrik.com"; classtype:trojan-activity; sid:100003024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sistelligent.com"; classtype:trojan-activity; sid:100003025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyflyfares.com"; classtype:trojan-activity; sid:100003026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyscan.com"; classtype:trojan-activity; sid:100003027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"slot0.gamoruz.com"; classtype:trojan-activity; sid:100003028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smarthouseforum.ru"; classtype:trojan-activity; sid:100003029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smartzedu.com"; classtype:trojan-activity; sid:100003030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smokesolutionindia.com"; classtype:trojan-activity; sid:100003031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smritiphotography.in"; classtype:trojan-activity; sid:100003032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sobariko.com"; classtype:trojan-activity; sid:100003033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sobethuacademy.com"; classtype:trojan-activity; sid:100003034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.110route.com"; classtype:trojan-activity; sid:100003035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.officelabo.net"; classtype:trojan-activity; sid:100003036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sohs.conceptechs.info"; classtype:trojan-activity; sid:100003037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"solar.amazingtribe.lk"; classtype:trojan-activity; sid:100003038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somcorbera.cat"; classtype:trojan-activity; sid:100003039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somir.com.mx"; classtype:trojan-activity; sid:100003040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soralapps.com"; classtype:trojan-activity; sid:100003041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sota-france.fr"; classtype:trojan-activity; sid:100003042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"space.proactint.org"; classtype:trojan-activity; sid:100003043; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spaceframe.mobi.space-frame.co.za"; classtype:trojan-activity; sid:100003044; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"special-key.cf"; classtype:trojan-activity; sid:100003045; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spent.com.pl"; classtype:trojan-activity; sid:100003046; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spetsesyachtcharter.gr"; classtype:trojan-activity; sid:100003047; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spititourism.com"; classtype:trojan-activity; sid:100003048; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spittinfire.com"; classtype:trojan-activity; sid:100003049; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"src1.minibai.com"; classtype:trojan-activity; sid:100003050; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sreenivasapaintingworks.com"; classtype:trojan-activity; sid:100003051; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sriglobalit.com"; classtype:trojan-activity; sid:100003052; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"srilankamovies.com"; classtype:trojan-activity; sid:100003053; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"srvmanos.no-ip.info"; classtype:trojan-activity; sid:100003054; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ss.monita.co.id"; classtype:trojan-activity; sid:100003055; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"st.devcodin.com"; classtype:trojan-activity; sid:100003056; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"staging.apparelpunch.com"; classtype:trojan-activity; sid:100003057; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"starcountry.net"; classtype:trojan-activity; sid:100003058; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"static.3001.net"; classtype:trojan-activity; sid:100003059; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stdynbnbnewagedevixz.dns.army"; classtype:trojan-activity; sid:100003060; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stdynmxwllminoragest.dns.army"; classtype:trojan-activity; sid:100003061; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stdyunitedkesokokgst.dns.army"; classtype:trojan-activity; sid:100003062; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stdyworkfinetraingst.dns.army"; classtype:trojan-activity; sid:100003063; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stdyzgchgcloudgostxs.dns.army"; classtype:trojan-activity; sid:100003064; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stiau.iuc.ac"; classtype:trojan-activity; sid:100003065; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sticker.jewsjuice.com"; classtype:trojan-activity; sid:100003066; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stiepancasetia.ac.id"; classtype:trojan-activity; sid:100003067; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stlukesohag.com"; classtype:trojan-activity; sid:100003068; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"store.ericalgarin.com"; classtype:trojan-activity; sid:100003069; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stott-thompson.co.uk"; classtype:trojan-activity; sid:100003070; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stratexec.co.za"; classtype:trojan-activity; sid:100003071; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"streetdemo.yourpageserver.com"; classtype:trojan-activity; sid:100003072; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"suboldesign.com"; classtype:trojan-activity; sid:100003073; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sumerians.org"; classtype:trojan-activity; sid:100003074; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunaryem.com.tr"; classtype:trojan-activity; sid:100003075; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunbrero.com.au"; classtype:trojan-activity; sid:100003076; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunmarkholidays.com"; classtype:trojan-activity; sid:100003077; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support-4-free.com"; classtype:trojan-activity; sid:100003078; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support.clz.kr"; classtype:trojan-activity; sid:100003079; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supportit.online"; classtype:trojan-activity; sid:100003080; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sw.yourpageserver.com"; classtype:trojan-activity; sid:100003081; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweaty.dk"; classtype:trojan-activity; sid:100003082; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweet-diet.com"; classtype:trojan-activity; sid:100003083; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swiftlogisticseg.com"; classtype:trojan-activity; sid:100003084; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swwbia.com"; classtype:trojan-activity; sid:100003085; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"syracusecoffee.com"; classtype:trojan-activity; sid:100003086; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sytraders.co"; classtype:trojan-activity; sid:100003087; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"t.honker.info"; classtype:trojan-activity; sid:100003088; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tadoo.ca"; classtype:trojan-activity; sid:100003089; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tafsantoursandtravels.com"; classtype:trojan-activity; sid:100003090; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tajushariya.com"; classtype:trojan-activity; sid:100003091; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tallyinvoicecustomization.com"; classtype:trojan-activity; sid:100003092; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taltus.co.uk"; classtype:trojan-activity; sid:100003093; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tapalkoedacoffee.com"; classtype:trojan-activity; sid:100003094; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tarravalleyfoods.com.au"; classtype:trojan-activity; sid:100003095; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taurus.ug"; classtype:trojan-activity; sid:100003096; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tc.snpsresidential.com"; classtype:trojan-activity; sid:100003097; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tcy.198424.com"; classtype:trojan-activity; sid:100003098; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tdsp.yngw518.com"; classtype:trojan-activity; sid:100003099; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"techgms.com"; classtype:trojan-activity; sid:100003100; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teduae.com"; classtype:trojan-activity; sid:100003101; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teleargentina.com"; classtype:trojan-activity; sid:100003102; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"telescopelms.com"; classtype:trojan-activity; sid:100003103; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"temptmag.com"; classtype:trojan-activity; sid:100003104; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tencoconsulting.com"; classtype:trojan-activity; sid:100003105; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teneth.co.za"; classtype:trojan-activity; sid:100003106; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tentandoserfitness.000webhostapp.com"; classtype:trojan-activity; sid:100003107; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tessrobins.com"; classtype:trojan-activity; sid:100003108; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.adventser.com"; classtype:trojan-activity; sid:100003109; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.letraele.es"; classtype:trojan-activity; sid:100003110; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.lubrico.in"; classtype:trojan-activity; sid:100003111; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.protocsconnectes.eu"; classtype:trojan-activity; sid:100003112; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.typoten.com"; classtype:trojan-activity; sid:100003113; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.wanepghana.org"; classtype:trojan-activity; sid:100003114; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.asistencia247.com"; classtype:trojan-activity; sid:100003115; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.milenial.id"; classtype:trojan-activity; sid:100003116; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.tenplusone.my"; classtype:trojan-activity; sid:100003117; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.basis-web.com"; classtype:trojan-activity; sid:100003118; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.marrenconstruction.ie"; classtype:trojan-activity; sid:100003119; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.clickitsolutionsmw.com"; classtype:trojan-activity; sid:100003120; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.thinkingcorp.in"; classtype:trojan-activity; sid:100003121; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testnew.yourpageserver.com"; classtype:trojan-activity; sid:100003122; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teteaffiche.stephanebillon.com"; classtype:trojan-activity; sid:100003123; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tewoerd.eu"; classtype:trojan-activity; sid:100003124; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"textile.softberg.ro"; classtype:trojan-activity; sid:100003125; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tharringtonsponsorship.com"; classtype:trojan-activity; sid:100003126; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecleaningladiespdx.com"; classtype:trojan-activity; sid:100003127; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecreativecafe.co.uk"; classtype:trojan-activity; sid:100003128; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thedesertship.com"; classtype:trojan-activity; sid:100003129; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thefamouscurrybazaar.co.uk"; classtype:trojan-activity; sid:100003130; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thefuturelife.in"; classtype:trojan-activity; sid:100003131; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thehighlightinterior.com"; classtype:trojan-activity; sid:100003132; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thekassia.co.uk"; classtype:trojan-activity; sid:100003133; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"themansionkasauli.com"; classtype:trojan-activity; sid:100003134; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theprofinn.com"; classtype:trojan-activity; sid:100003135; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thesummitpc.net"; classtype:trojan-activity; sid:100003136; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theurbantutors.com"; classtype:trojan-activity; sid:100003137; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thosewebbs.com"; classtype:trojan-activity; sid:100003138; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thriveink.com"; classtype:trojan-activity; sid:100003139; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tianangdep.com"; classtype:trojan-activity; sid:100003140; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickfoods.tickme.lk"; classtype:trojan-activity; sid:100003141; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tidymasters.com.au"; classtype:trojan-activity; sid:100003142; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"timegonebuy.com"; classtype:trojan-activity; sid:100003143; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tksb.net"; classtype:trojan-activity; sid:100003144; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tlcc.com.gt"; classtype:trojan-activity; sid:100003145; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"todoapp.cstdevs.com"; classtype:trojan-activity; sid:100003146; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonydong.com"; classtype:trojan-activity; sid:100003147; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonyzone.com"; classtype:trojan-activity; sid:100003148; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tooba.tenplusone.my"; classtype:trojan-activity; sid:100003149; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tools.reimclub.com"; classtype:trojan-activity; sid:100003150; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topcell9.com"; classtype:trojan-activity; sid:100003151; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toplevel.com.br"; classtype:trojan-activity; sid:100003152; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topmask.co.za"; classtype:trojan-activity; sid:100003153; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"torresquinterocorp.com"; classtype:trojan-activity; sid:100003154; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toyotacollege.ac.th"; classtype:trojan-activity; sid:100003155; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpke.hu"; classtype:trojan-activity; sid:100003156; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"translaterjemah.com"; classtype:trojan-activity; sid:100003157; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"travelwithmanta.co.za"; classtype:trojan-activity; sid:100003158; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trendyshoes.co.za"; classtype:trojan-activity; sid:100003159; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trezors.io.mahlongwa.com"; classtype:trojan-activity; sid:100003160; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trimestre.bar"; classtype:trojan-activity; sid:100003161; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"troki.com.co"; classtype:trojan-activity; sid:100003162; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tropics.codeleek.net"; classtype:trojan-activity; sid:100003163; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trudelfavreau.com"; classtype:trojan-activity; sid:100003164; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tsd.jxwan.com"; classtype:trojan-activity; sid:100003165; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tulli.info"; classtype:trojan-activity; sid:100003166; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tupperware.michaelroberge.ca"; classtype:trojan-activity; sid:100003167; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"turanggaresources.com"; classtype:trojan-activity; sid:100003168; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uat.indianfilmzone.com"; classtype:trojan-activity; sid:100003169; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ublretailerdemo.cstdevs.com"; classtype:trojan-activity; sid:100003170; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uc-56.ru"; classtype:trojan-activity; sid:100003171; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uisusa.uisusa.com"; classtype:trojan-activity; sid:100003172; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ultimate-24.de"; classtype:trojan-activity; sid:100003173; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"umwelt-kirchhof.de"; classtype:trojan-activity; sid:100003174; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unicorpbrunei.com"; classtype:trojan-activity; sid:100003175; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uniengrisb.com"; classtype:trojan-activity; sid:100003176; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"union.jctrip.cn"; classtype:trojan-activity; sid:100003177; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unyazitelecom.com"; classtype:trojan-activity; sid:100003178; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"up.llw0.com"; classtype:trojan-activity; sid:100003179; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"upcbpta.com"; classtype:trojan-activity; sid:100003180; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"useformoney.000webhostapp.com"; classtype:trojan-activity; sid:100003181; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uss.ac.th"; classtype:trojan-activity; sid:100003182; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uzzepay.com.br"; classtype:trojan-activity; sid:100003183; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vanzare.cabanabrazi2.ro"; classtype:trojan-activity; sid:100003184; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vbcargo.hu"; classtype:trojan-activity; sid:100003185; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vcah.co.uk"; classtype:trojan-activity; sid:100003186; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vectarts.com"; classtype:trojan-activity; sid:100003187; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vegadelcasero.cl"; classtype:trojan-activity; sid:100003188; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vendas.lidiacarmeli.com.br"; classtype:trojan-activity; sid:100003189; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"veterinariadrpopui.com"; classtype:trojan-activity; sid:100003190; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vfocus.net"; classtype:trojan-activity; sid:100003191; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vienen.gblix.srv.br"; classtype:trojan-activity; sid:100003192; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vilaart.rs"; classtype:trojan-activity; sid:100003193; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villamarand.com"; classtype:trojan-activity; sid:100003194; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villatera.com"; classtype:trojan-activity; sid:100003195; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"violinstop.com"; classtype:trojan-activity; sid:100003196; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"virtuleverage.com"; classtype:trojan-activity; sid:100003197; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visions.alnisamart.com"; classtype:trojan-activity; sid:100003198; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visualhome.cl"; classtype:trojan-activity; sid:100003199; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vivationdesign.com"; classtype:trojan-activity; sid:100003200; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"viveirodoiscorregos.com.br"; classtype:trojan-activity; sid:100003201; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vksales.com"; classtype:trojan-activity; sid:100003202; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vocalterra.com"; classtype:trojan-activity; sid:100003203; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vologroup.com.br"; classtype:trojan-activity; sid:100003204; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"voteyouramerica.dekitout.com"; classtype:trojan-activity; sid:100003205; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vpts.co.za"; classtype:trojan-activity; sid:100003206; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vstsample.com"; classtype:trojan-activity; sid:100003207; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vtube.fadlymotivator.com"; classtype:trojan-activity; sid:100003208; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vvsskmodinationalschool.com"; classtype:trojan-activity; sid:100003209; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu"; classtype:trojan-activity; sid:100003210; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepliberia.org"; classtype:trojan-activity; sid:100003211; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepniger.org"; classtype:trojan-activity; sid:100003212; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weareactum.com"; classtype:trojan-activity; sid:100003213; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.eng.ubu.ac.th"; classtype:trojan-activity; sid:100003214; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geomegasoft.net"; classtype:trojan-activity; sid:100003215; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.newinnovationtechnology.com"; classtype:trojan-activity; sid:100003216; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.smarts-works.com"; classtype:trojan-activity; sid:100003217; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.thebeessolution.com"; classtype:trojan-activity; sid:100003218; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webgis.perumdasolo.com"; classtype:trojan-activity; sid:100003219; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webpresario.com"; classtype:trojan-activity; sid:100003220; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weinsteincounseling.com"; classtype:trojan-activity; sid:100003221; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wfinance.com.br"; classtype:trojan-activity; sid:100003222; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whcms.yourpageserver.com"; classtype:trojan-activity; sid:100003223; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteglovetailgate.com"; classtype:trojan-activity; sid:100003224; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteresponse.com"; classtype:trojan-activity; sid:100003225; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wi522012.ferozo.com"; classtype:trojan-activity; sid:100003226; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wikalen.co.za"; classtype:trojan-activity; sid:100003227; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildnights.co.uk"; classtype:trojan-activity; sid:100003228; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildtrust.mediadevstaging.com"; classtype:trojan-activity; sid:100003229; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"willow-nettica.com"; classtype:trojan-activity; sid:100003230; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wimbamusica.com"; classtype:trojan-activity; sid:100003231; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"windcomtechnologies.com"; classtype:trojan-activity; sid:100003232; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wishesconcierge.com"; classtype:trojan-activity; sid:100003233; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woezon.agency"; classtype:trojan-activity; sid:100003234; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wolfgang-brodte.de"; classtype:trojan-activity; sid:100003235; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woodsytech.com"; classtype:trojan-activity; sid:100003236; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wordpress.saleensuporte.com.br"; classtype:trojan-activity; sid:100003237; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wozata.000webhostapp.com"; classtype:trojan-activity; sid:100003238; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wp.readhere.in"; classtype:trojan-activity; sid:100003239; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wpdemo.101clients.com.au"; classtype:trojan-activity; sid:100003240; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"writtendeer.com"; classtype:trojan-activity; sid:100003241; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ws5588.f3322.net"; classtype:trojan-activity; sid:100003242; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wyklej.pl"; classtype:trojan-activity; sid:100003243; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"x2vn.com"; classtype:trojan-activity; sid:100003244; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xia.beihaixue.com"; classtype:trojan-activity; sid:100003245; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xixaoclothing.com"; classtype:trojan-activity; sid:100003246; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xk.996is.com"; classtype:trojan-activity; sid:100003247; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--polimerbizmimarlk-rvc.com"; classtype:trojan-activity; sid:100003248; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ybom.urbanolab.com"; classtype:trojan-activity; sid:100003249; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yeichner.com"; classtype:trojan-activity; sid:100003250; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yeq.i.u.j.ia.n.3@zytrox.tk"; classtype:trojan-activity; sid:100003251; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ylfpremium.com"; classtype:trojan-activity; sid:100003252; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yoast.yourpageserver.com"; classtype:trojan-activity; sid:100003253; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yp.hnggzyjy.cn"; classtype:trojan-activity; sid:100003254; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yummyyogaudaipur.com"; classtype:trojan-activity; sid:100003255; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yzkzixun.com"; classtype:trojan-activity; sid:100003256; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ziyker4gaming@zytrox.tk"; classtype:trojan-activity; sid:100003257; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zmedcoach.com"; classtype:trojan-activity; sid:100003258; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zytrox.tk"; classtype:trojan-activity; sid:100003259; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zz.690tx.com"; classtype:trojan-activity; sid:100003260; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100003261; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/86.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100003262; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c64.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100003263; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; endswith; nocase; http.host; content:"amumufree.weebly.com"; classtype:trojan-activity; sid:100003264; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/proxyi.exe"; endswith; nocase; http.host; content:"analogx.com"; classtype:trojan-activity; sid:100003265; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003266; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/clubhousedev/clubhouse/downloads/clubhousepc.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003267; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvdfv/anjj/downloads/jami.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003268; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/heyhoeee/heyhoename1/downloads/1234.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003269; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/4.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003270; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/6.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003271; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labesoftware/update/downloads/boost-fps.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003272; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labesoftware/update/downloads/install_plugin_x64_x86.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003273; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/labesoftware/update/downloads/vpn_free.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003274; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/clr.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003275; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/dianthus.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003276; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/n.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003277; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/newred.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003278; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/omar.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003279; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/serv.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003280; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/test.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003281; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updachrome.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003282; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatedata.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003283; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatev.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003284; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/work.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003285; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/component.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003286; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003287; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/regsvc.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003288; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skygaming/updates/downloads/update.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003289; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/001.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003290; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1488.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003291; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1_cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003292; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003293; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1fc2d.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003294; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/26a5.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003295; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003296; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/abjects.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003297; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/attached.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003298; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/b7f2c.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003299; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/battletext.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003300; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003301; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003302; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003303; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_makros.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003304; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_silent.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003305; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_sup.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003306; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003307; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003308; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003309; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildss.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003310; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientnik.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003311; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientrevers.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003312; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dcrat.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003313; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003314; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003315; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hans.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003316; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hulu.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003317; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfive.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003318; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfour.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003319; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelone.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003320; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelthree.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003321; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/inteltwo.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003322; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003323; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/kleiman.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003324; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003325; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/notepadplus.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003326; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003327; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003328; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003329; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003330; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/putty.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003331; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/rockethcd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003332; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/scvhost900.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003333; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/sessionwin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003334; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/siliculose.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003335; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/statemobi.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003336; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003337; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003338; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stgedo.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003339; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/svcperf.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003340; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003341; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurjok.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003342; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurusbabac.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003343; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/telekiller.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003344; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateanddr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003345; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateandr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003346; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/vhajeja.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003347; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/word.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003348; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/www.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003349; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/xlsd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003350; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003351; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100003352; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmatrix/data/hack1226.exe"; endswith; nocase; http.host; content:"cd.textfiles.com"; classtype:trojan-activity; sid:100003353; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003354; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/775238059083038744/829993648186851338/pslmlyfnpzgsgitrwwvalcfunumfmac"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003355; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/816070119281131570/816070273254162442/all.txt"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003356; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/826848185246023750/loaddd.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003357; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/826848348342059008/zeppelin.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003358; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/826848405258633277/build.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003359; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/825372018244583454/830455061724528690/v1.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003360; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/826198252025675816/826537386485612574/china.png"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003361; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003362; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100003363; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razor/rzr-winner_intro.zip"; endswith; nocase; http.host; content:"chiptune.com"; classtype:trojan-activity; sid:100003364; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100003365; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100003366; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meteoradminz/hidden-tear/zip/master"; endswith; nocase; http.host; content:"codeload.github.com"; classtype:trojan-activity; sid:100003367; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; endswith; nocase; http.host; content:"colfincas.com"; classtype:trojan-activity; sid:100003368; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ktcghnmcwws43wzscphukbfnwtuaxidx&revid=0b8z0b7_i5sirk2xrtehmstg0vxvit3b4n3lmbdrdrjrodndrpq"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100003369; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1qze6qzzh1uf7iaj4rqixttznx6u1--gc&revid=0b45wwmcofx7fuvnmdhpkt1d0k3rhzldyoffnuc83auzkslvrpq"; endswith; nocase; http.host; content:"docs.google.com"; classtype:trojan-activity; sid:100003370; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; endswith; nocase; http.host; content:"drive.google.com.it-barcelona.com"; classtype:trojan-activity; sid:100003371; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003372; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=11idvvx22jx_1lw-hxnpmlwuvjgdyp63g"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003373; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=12khl-unz2np4q54b2jgpwlsh6cuz0pss"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003374; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003375; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003376; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=16yyvhney9_-nygeipjqgnlcmwfoyiaxo"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003377; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=17pl-4i0otjbyxwrtrdagxxebirdh2wl8"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003378; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003379; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003380; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1br5iufkkmmfeipqo3ecviqykbcdgcnio"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003381; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1bwtwpqmeqdvctbcqcc2gil5xzjf28c0z"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003382; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003383; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003384; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1d0ij6qkgrf6irywv6ftk1m7p5l3weh3a"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003385; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1dzx_cflers_zntlrip3fhbxb5who03u0"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003386; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1gprlk2mcrl6law-zk5r0pjogaqrxwepd"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003387; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003388; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003389; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1jdqcxydqvz3bjodp66ieiocbjcz8foi6"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003390; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1l5urks5wzib2zcb16bfsk76bjrdsejms"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003391; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ldxaekbcbzb-zfdix-ucj4rilobnbswx"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003392; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ljz-kmuibyiehba6blw37guu_yr799y0"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003393; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1lsv4sko083sywwjndgqnsh_6sgqodqtu"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003394; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003395; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003396; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003397; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1oek6vmzbv15nyho_uqcbk4_vaq1ezowv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003398; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ph-lri07dohowhmuczrrvjwrtsvmnu9s"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003399; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003400; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1r1flwyfwtyziyr47y5sk3q821r6_tgsl"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003401; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1r9f9irwhutxozsbp2h9erd_a7fa2pwko"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003402; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1s221a6wpx6i7nfrztnhh9priojtybuxq"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003403; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1sutnyikgc4qw-tbvnnvzm8uz9thch0vz"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003404; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003405; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1taubixyqiqdgfbhmc2rv_aitvkbqhzwz"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003406; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1tpd_qbnl_mtmhfsv4a-qtfsnuiimyoy6"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003407; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003408; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vjq92eqivh01yxmal20whl2es3ld6nxb"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003409; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1voqnsh0cmxl5hty4zpc18pgnkud5rtvy"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003410; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vy1nx5zefluh5ewihr-6pcndlyex7xcm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003411; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1wpqa2nnnktbhzs4j0r-erosvgyaagi_a"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003412; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xbp7hvw2ybwjrftbvdkjvwzrfuk4ope9"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003413; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003414; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003415; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003416; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003417; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ywkgalidldb32pio6ywmbyvdk7oar3yy"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003418; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003419; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100003420; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/1zilg/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100003421; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/qcgfmfvh/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100003422; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/emclick.zip"; endswith; nocase; http.host; content:"e-mudhra.com"; classtype:trojan-activity; sid:100003423; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe"; endswith; nocase; http.host; content:"evertkok.nl"; classtype:trojan-activity; sid:100003424; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe"; endswith; nocase; http.host; content:"evertkok.nl"; classtype:trojan-activity; sid:100003425; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100003426; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100003427; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100003428; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003429; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003430; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003431; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100003432; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; endswith; nocase; http.host; content:"file.elecfans.com"; classtype:trojan-activity; sid:100003433; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100003434; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100003435; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; endswith; nocase; http.host; content:"gist.githubusercontent.com"; classtype:trojan-activity; sid:100003436; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; endswith; nocase; http.host; content:"hqdecig.com"; classtype:trojan-activity; sid:100003437; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/suy/"; endswith; nocase; http.host; content:"hsecaravans.co.uk"; classtype:trojan-activity; sid:100003438; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19/items/startup_20210219/startup.txt"; endswith; nocase; http.host; content:"ia801802.us.archive.org"; classtype:trojan-activity; sid:100003439; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/online-timer-kvhxz/ilxl/"; endswith; nocase; http.host; content:"ie-best.net"; classtype:trojan-activity; sid:100003440; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100003441; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100003442; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebook/cs17.exe"; endswith; nocase; http.host; content:"jcedu.org"; classtype:trojan-activity; sid:100003443; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100003444; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100003445; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100003446; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; endswith; nocase; http.host; content:"karmakoincodes.weebly.com"; classtype:trojan-activity; sid:100003447; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dg/etrac/nf4emwz/"; endswith; nocase; http.host; content:"kotakwarna.co.id"; classtype:trojan-activity; sid:100003448; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/docs/adatgyujtesek/elektra/csv_to_xml.exe"; endswith; nocase; http.host; content:"ksh.hu"; classtype:trojan-activity; sid:100003449; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/affiliate/kuaizip_setup_10029.exe"; endswith; nocase; http.host; content:"kuaizip.com"; classtype:trojan-activity; sid:100003450; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linuxforensicscode.zip"; endswith; nocase; http.host; content:"linuxforensicsbook.com.s3.amazonaws.com"; classtype:trojan-activity; sid:100003451; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl8.exe"; endswith; nocase; http.host; content:"lojavirtual.top"; classtype:trojan-activity; sid:100003452; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dl8v2.exe"; endswith; nocase; http.host; content:"lojavirtual.top"; classtype:trojan-activity; sid:100003453; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k/big5/1giof6/"; endswith; nocase; http.host; content:"minpic.de"; classtype:trojan-activity; sid:100003454; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-contentbak/t9m/"; endswith; nocase; http.host; content:"morrobaydrugandgift.com"; classtype:trojan-activity; sid:100003455; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; endswith; nocase; http.host; content:"my.cloudme.com"; classtype:trojan-activity; sid:100003456; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/aacenc.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100003457; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/doxillionsetup.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100003458; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/4/1/6/6/4166984/keygen.exe"; endswith; nocase; http.host; content:"newyarlfm.weebly.com"; classtype:trojan-activity; sid:100003459; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; endswith; nocase; http.host; content:"nhipcauytevietnhat.com"; classtype:trojan-activity; sid:100003460; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; endswith; nocase; http.host; content:"note.youdao.com"; classtype:trojan-activity; sid:100003461; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; endswith; nocase; http.host; content:"oldschoolvalue.s3.amazonaws.com"; classtype:trojan-activity; sid:100003462; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20cid=ba02d68febf523dc&resid=ba02d68febf523dc!1431&authkey=afbifi7o9ywbjpm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003463; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?%20cid=ba02d68febf523dc&resid=ba02d68febf523dc%211431&authkey=afbifi7o9ywbjpm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003464; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003465; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003466; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003467; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003468; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003469; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003470; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003471; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003472; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003473; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003474; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003475; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003476; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003477; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003478; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003479; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003480; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003481; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003482; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003483; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003484; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003485; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003486; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0412fba39d6c52de&resid=412fba39d6c52de%2122008&authkey=amn2bgbswxwgpma"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003487; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003488; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003489; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003490; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003491; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003492; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d!184&authkey=ackbiiarirejcam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003493; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0cc3238b46a1ac6d&resid=cc3238b46a1ac6d%21184&authkey=ackbiiarirejcam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003494; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003495; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003496; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003497; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003498; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0!1667&authkey=an8otd7jzc7xgho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003499; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d7729ca9a2b7fa0&resid=d7729ca9a2b7fa0%211667&authkey=an8otd7jzc7xgho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003500; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003501; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003502; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003503; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003504; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003505; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003506; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003507; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003508; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=15d9646f4dbf9553&resid=15d9646f4dbf9553%21110&authkey=ag0eg1lha_lwgi0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003509; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003510; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003511; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003512; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003513; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003514; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003515; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003516; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003517; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003518; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003519; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003520; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003521; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003522; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003523; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003524; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003525; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003526; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba!112&authkey=afjxmbcllibdbvo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003527; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba!114&authkey=adecqvkvvvadznc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003528; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba%21112&authkey=afjxmbcllibdbvo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003529; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=20bb12e82cb1e8ba&resid=20bb12e82cb1e8ba%21114&authkey=adecqvkvvvadznc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003530; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=216ef243e34992b8&resid=216ef243e34992b8!330&authkey=apiugomnim7heom"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003531; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=216ef243e34992b8&resid=216ef243e34992b8%21330&authkey=apiugomnim7heom"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003532; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=23423a594eafc2de&resid=23423a594eafc2de%21130&authkey=aeh1dm0c-5hp44a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003533; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003534; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003535; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003536; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003537; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003538; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003539; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003540; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003541; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003542; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b!287&authkey=advpfy_0ry8upmi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003543; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b!288&authkey=aembucxemjjo3bk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003544; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b%21287&authkey=advpfy_0ry8upmi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003545; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2a56f979f12efc6b&resid=2a56f979f12efc6b%21288&authkey=aembucxemjjo3bk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003546; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003547; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003548; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003549; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003550; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003551; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003552; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003553; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003554; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003555; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003556; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003557; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003558; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3004cdd743a543f5&resid=3004cdd743a543f5%21170&authkey=ao8vz-4rkwuiyn8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003559; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003560; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003561; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003562; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003563; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003564; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003565; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1!223&authkey=aajr842bzum0yg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003566; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3258f281cd827eb1&resid=3258f281cd827eb1%21223&authkey=aajr842bzum0yg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003567; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003568; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003569; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003570; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34ddb7fad56e5c0f&resid=34ddb7fad56e5c0f%21419&authkey=ah0olx87c2izsk8,standard,n/a,n/a,urlhaus"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003571; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003572; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003573; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003574; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003575; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003576; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003577; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003578; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003579; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003580; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0!119&authkey=adkqcwv8_3k86z4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003581; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3afef9312d3573c0&resid=3afef9312d3573c0%21119&authkey=adkqcwv8_3k86z4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003582; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003583; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003584; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3ee68228c34c236d&resid=3ee68228c34c236d%21129&authkey=apll6hu3-xetzxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003585; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003586; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003587; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003588; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003589; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003590; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003591; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003592; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003593; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003594; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003595; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21141&authkey=aazwaw2xjms24o0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003596; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=46de06f83c43e1aa&resid=46de06f83c43e1aa%21145&authkey=aaenjqj018fjmc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003597; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003598; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003599; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003600; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003601; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003602; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003603; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003604; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003605; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003606; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003607; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003608; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003609; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003610; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003611; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003612; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003613; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003614; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003615; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003616; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003617; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003618; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003619; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003620; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003621; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003622; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003623; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003624; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003625; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003626; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003627; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003628; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003629; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003630; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003631; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003632; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003633; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003634; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003635; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003636; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003637; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003638; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003639; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003640; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003641; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003642; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003643; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003644; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003645; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003646; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003647; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003648; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003649; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003650; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003651; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003652; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003653; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003654; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003655; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003656; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003657; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003658; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003659; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003660; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003661; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003662; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003663; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003664; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003665; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003666; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003667; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003668; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003669; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003670; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003671; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003672; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003673; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003674; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003675; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003676; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003677; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003678; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003679; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003680; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003681; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003682; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003683; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003684; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003685; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003686; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003687; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003688; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003689; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003690; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003691; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003692; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003693; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003694; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003695; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003696; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003697; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003698; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003699; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003700; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003701; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003702; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003703; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003704; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003705; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21198&authkey=akq4jrbjm6spd9m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003706; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003707; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003708; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003709; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1099&authkey=alxq-bvz7nqbv4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003710; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003711; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211099&authkey=alxq-bvz7nqbv4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003712; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003713; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003714; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003715; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003716; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003717; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003718; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003719; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003720; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003721; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003722; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003723; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003724; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003725; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003726; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003727; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003728; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003729; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003730; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003731; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003732; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003733; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003734; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003735; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003736; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003737; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003738; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003739; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003740; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003741; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003742; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003743; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003744; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003745; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003746; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003747; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003748; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003749; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003750; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003751; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003752; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003753; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003754; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003755; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003756; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003757; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003758; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003759; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003760; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003761; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=855b20b0e8399717&resid=855b20b0e8399717%21110&authkey=afhxx21ztsd7hbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003762; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003763; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003764; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003765; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003766; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003767; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003768; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003769; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003770; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003771; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003772; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003773; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003774; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003775; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003776; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003777; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!112&authkey=af43qpcgl0t2f5o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003778; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2!113&authkey=ag92_wxfvrsuix8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003779; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21112&authkey=af43qpcgl0t2f5o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003780; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=92462ab265d53cb2&resid=92462ab265d53cb2%21113&authkey=ag92_wxfvrsuix8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003781; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003782; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003783; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003784; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003785; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003786; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003787; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003788; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003789; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003790; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003791; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003792; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003793; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003794; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003795; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003796; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003797; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003798; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003799; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003800; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003801; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003802; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003803; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003804; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003805; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003806; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003807; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003808; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003809; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003810; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114!256&authkey=aapnly5qifymcvw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003811; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21251&authkey=ainluv1ppu-8ogu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003812; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6d02acf038b0114&resid=a6d02acf038b0114%21256&authkey=aapnly5qifymcvw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003813; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003814; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003815; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003816; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003817; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003818; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003819; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003820; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003821; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003822; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818!129&authkey=aesewk3cf5vbrxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003823; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a88c38fdad791818&resid=a88c38fdad791818%21129&authkey=aesewk3cf5vbrxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003824; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003825; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5!2423&authkey=aoiqjwenlzfiqe0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003826; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212417&authkey=aa2zjoxjz1c83ns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003827; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212418&authkey=akjeumqon_fyj9c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003828; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ab4c382b1f6e93e5&resid=ab4c382b1f6e93e5%212423&authkey=aoiqjwenlzfiqe0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003829; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003830; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003831; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003832; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003833; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003834; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003835; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003836; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003837; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003838; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003839; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003840; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003841; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003842; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003843; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003844; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003845; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003846; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003847; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003848; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003849; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003850; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003851; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003852; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003853; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003854; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003855; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ba02d68febf523dc&resid=ba02d68febf523dc%211431&authkey=afbifi7o9ywbjpm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003856; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540!1047&authkey=aod6jbxyicq2v4g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003857; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bd6fbb121626b540&resid=bd6fbb121626b540%211047&authkey=aod6jbxyicq2v4g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003858; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003859; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003860; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003861; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003862; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003863; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003864; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c29fdbf45b3d2671&resid=c29fdbf45b3d2671%21608&authkey=aafwhzmybg1czta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003865; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003866; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003867; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003868; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003869; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003870; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003871; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003872; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003873; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003874; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003875; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003876; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003877; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003878; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003879; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003880; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003881; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003882; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003883; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003884; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003885; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003886; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003887; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003888; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003889; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003890; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003891; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003892; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!357&authkey=alw3vqqxz6myrle"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003893; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!362&authkey=alycl9izrvfl7oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003894; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21354&authkey=aa_ukeour7rex1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003895; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21355&authkey=aajjwf_sm4xdqdk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003896; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21357&authkey=alw3vqqxz6myrle"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003897; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21362&authkey=alycl9izrvfl7oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003898; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003899; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003900; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003901; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003902; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003903; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003904; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003905; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003906; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003907; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003908; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003909; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003910; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003911; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003912; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003913; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d4d413b6e7cf7088&resid=d4d413b6e7cf7088%211271&authkey=akz65bxpgvdxjb8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003914; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003915; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003916; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003917; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003918; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003919; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003920; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003921; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003922; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003923; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003924; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003925; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003926; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003927; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003928; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003929; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003930; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003931; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003932; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003933; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003934; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003935; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2!107&authkey=af-bicrg1c6vgck"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003936; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1a2f9756fffc8d2&resid=e1a2f9756fffc8d2%21107&authkey=af-bicrg1c6vgck"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003937; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2!129&authkey=afk5vdt49soo3co"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003938; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e2ea0eaee1f43ce2&resid=e2ea0eaee1f43ce2%21129&authkey=afk5vdt49soo3co"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003939; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003940; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003941; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003942; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003943; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003944; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003945; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003946; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003947; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e74fdc1373fe6eb7&resid=e74fdc1373fe6eb7!142&authkey=apwl64nhnjaj8ke"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003948; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003949; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003950; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003951; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003952; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003953; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003954; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003955; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003956; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003957; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003958; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003959; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003960; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003961; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003962; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003963; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003964; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003965; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003966; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003967; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003968; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003969; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003970; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003971; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003972; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003973; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003974; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003975; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003976; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003977; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003978; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003979; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003980; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003981; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003982; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003983; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!847&authkey=aemnhwbhlskovgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003984; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352!848&authkey=ag1_e421v-t5r9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003985; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21847&authkey=aemnhwbhlskovgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003986; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fdc68d2b6039f352&resid=fdc68d2b6039f352%21848&authkey=ag1_e421v-t5r9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003987; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003988; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003989; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003990; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003991; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003992; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003993; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003994; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003995; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003996; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003997; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100003998; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/77jhk0iw"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100003999; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/89hkc7wb"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100004000; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/yqvsvlvq"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100004001; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/llc/mwcacs65xienqdp/"; endswith; nocase; http.host; content:"pierreconsulting.info"; classtype:trojan-activity; sid:100004002; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skoda22.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100004003; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100004004; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; endswith; nocase; http.host; content:"qjbutterflyevents.co.za"; classtype:trojan-activity; sid:100004005; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004006; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004007; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004008; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004009; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004010; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004011; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myqseeaccount/one/main/one.htm"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004012; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004013; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004014; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004015; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tennc/webshell/master/other/small_shell.txt"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100004016; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; endswith; nocase; http.host; content:"res.yeshen.com"; classtype:trojan-activity; sid:100004017; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/q05z91"; endswith; nocase; http.host; content:"sendspace.com"; classtype:trojan-activity; sid:100004018; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ey4lpx8rx.zip"; endswith; nocase; http.host; content:"shribharatvatika.com"; classtype:trojan-activity; sid:100004019; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; endswith; nocase; http.host; content:"sites.google.com"; classtype:trojan-activity; sid:100004020; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004021; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004022; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004023; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004024; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004025; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004026; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004027; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004028; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004029; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100004030; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-nurse-ss8d9/z/"; endswith; nocase; http.host; content:"technologydistilled.com"; classtype:trojan-activity; sid:100004031; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crisanar/defis/jek_crackme1.7.zip"; endswith; nocase; http.host; content:"users.skynet.be"; classtype:trojan-activity; sid:100004032; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/amowvegfrt9ja/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100004033; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100004034; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wuk/kuqyslbgavnwlmcuk0qalhxifzp4mgze8anlcewu1pa8fw4lfex0y/"; endswith; nocase; http.host; content:"vokasi.ub.ac.id"; classtype:trojan-activity; sid:100004035; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100004036; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100004037; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004038; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb%5efr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004039; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb^fr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004040; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004041; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/151_155/tidex_-_short_stuff.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100004042; rev:1;) +alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syria-files/attach/222/222051_instruction.zip"; endswith; nocase; http.host; content:"wikileaks.org"; classtype:trojan-activity; sid:100004043; rev:1;) diff --git a/urlhaus-filter-unbound-online.conf b/urlhaus-filter-unbound-online.conf index 1ef8df1f..fa33f74a 100644 --- a/urlhaus-filter-unbound-online.conf +++ b/urlhaus-filter-unbound-online.conf @@ -1,5 +1,5 @@ # Title: Online Malicious Domains Unbound Blocklist -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -33,7 +33,6 @@ local-zone: "addahealingmusic.com" always_nxdomain local-zone: "adithimedia.com" always_nxdomain local-zone: "adithimedia.memengers.com" always_nxdomain local-zone: "admin.erapor.smk-alasror.net" always_nxdomain -local-zone: "admin.gentbcn.org" always_nxdomain local-zone: "admin.grandoceanvilla.com" always_nxdomain local-zone: "admission.kmctartskuttippuram.org" always_nxdomain local-zone: "adventureexplorer.in" always_nxdomain @@ -49,6 +48,7 @@ local-zone: "aiecons.com" always_nxdomain local-zone: "aiqtest.com" always_nxdomain local-zone: "ajpharmaholding.com" always_nxdomain local-zone: "akdvidyalaya.com" always_nxdomain +local-zone: "al-wahd.com" always_nxdomain local-zone: "alasdemariposas.org" always_nxdomain local-zone: "alberts.diamondrelationscrm.us" always_nxdomain local-zone: "alemelektronik.com" always_nxdomain @@ -86,7 +86,6 @@ local-zone: "aps-sv.com" always_nxdomain local-zone: "artedibujoyarquitectura.com" always_nxdomain local-zone: "arwenyapi.com" always_nxdomain local-zone: "ask-regard.call-save.biz" always_nxdomain -local-zone: "asucssa.live" always_nxdomain local-zone: "atfile.com" always_nxdomain local-zone: "athenacapsg.com" always_nxdomain local-zone: "atlasconcreteworks.com" always_nxdomain @@ -98,15 +97,17 @@ local-zone: "australianpga.com.au" always_nxdomain local-zone: "automaticrefreshments.com" always_nxdomain local-zone: "avadhanagames.com" always_nxdomain local-zone: "aventuramotorhome.com" always_nxdomain +local-zone: "awumad01.top" always_nxdomain +local-zone: "awuqze02.top" always_nxdomain local-zone: "ayahuascasp.com.br" always_nxdomain local-zone: "ayamallah.com" always_nxdomain -local-zone: "aycconsultoriaempresarial.com" always_nxdomain local-zone: "azmeasurement.com" always_nxdomain local-zone: "azraktours.com" always_nxdomain local-zone: "b.r.uce.lee.b.es.t@zytrox.tk" always_nxdomain local-zone: "b2b.toptanakaryakit.com.tr" always_nxdomain local-zone: "backgrounds.pk" always_nxdomain local-zone: "badeggdesign.com" always_nxdomain +local-zone: "bakamla.go.id" always_nxdomain local-zone: "balealgodon.mx" always_nxdomain local-zone: "bangkok-orchids.com" always_nxdomain local-zone: "bangladeshunbound.com" always_nxdomain @@ -127,7 +128,6 @@ local-zone: "beor360.com" always_nxdomain local-zone: "bespokeweddings.ie" always_nxdomain local-zone: "bestcarenepal.com" always_nxdomain local-zone: "betone.co.kr" always_nxdomain -local-zone: "betycopaints.com" always_nxdomain local-zone: "beveragesmiami.solucioneslink.com" always_nxdomain local-zone: "bhavaniengineering.com" always_nxdomain local-zone: "bigmikesupplies.co.za" always_nxdomain @@ -183,12 +183,12 @@ local-zone: "canadianwork.cc" always_nxdomain local-zone: "capitalgroup-kw.com" always_nxdomain local-zone: "capoeiraventrelivre.com" always_nxdomain local-zone: "cashyinvestment.org" always_nxdomain +local-zone: "casiomaneflirt.cf" always_nxdomain local-zone: "catchpoolshetlands.co.uk" always_nxdomain local-zone: "cazyacustomfurniture.com" always_nxdomain local-zone: "cbn.hypervoizd.com" always_nxdomain local-zone: "ccauthority.net" always_nxdomain local-zone: "cdaonline.com.ar" always_nxdomain -local-zone: "cdn-10049480.file.myqcloud.com" always_nxdomain local-zone: "cec.asso.ac-amiens.fr" always_nxdomain local-zone: "cellas.sk" always_nxdomain local-zone: "cendekiabinaaksara.com" always_nxdomain @@ -202,17 +202,17 @@ local-zone: "chinhdropfile.myvnc.com" always_nxdomain local-zone: "chinhdropfile80.myvnc.com" always_nxdomain local-zone: "cible-energy.com" always_nxdomain local-zone: "cifeer.net" always_nxdomain +local-zone: "citiconstructioncorp.com" always_nxdomain local-zone: "citihits.lk" always_nxdomain local-zone: "citssolutions.co.za" always_nxdomain -local-zone: "citycapproperty.ru" always_nxdomain local-zone: "cityglobalgospel.com" always_nxdomain local-zone: "civi.istmejia.com" always_nxdomain local-zone: "cleanbydesignllc.com" always_nxdomain local-zone: "cloud.fc.co.mz" always_nxdomain local-zone: "cnc.tacobelllover.tk" always_nxdomain local-zone: "codsambal.com" always_nxdomain -local-zone: "colinde.pricesne.com" always_nxdomain local-zone: "colorpak.pl" always_nxdomain +local-zone: "columbia.aula-web.net" always_nxdomain local-zone: "community.reimclub.com" always_nxdomain local-zone: "competancy.indigoconsult.net" always_nxdomain local-zone: "conceptimagine.ro" always_nxdomain @@ -222,9 +222,11 @@ local-zone: "constructoralyon.com" always_nxdomain local-zone: "consulateins.solucioneslink.com" always_nxdomain local-zone: "contributeindustry.com" always_nxdomain local-zone: "copelandscapes.com" always_nxdomain +local-zone: "corwin-tommie06f.ru.com" always_nxdomain local-zone: "coulsongraphics.com" always_nxdomain local-zone: "count.mail.163.com.impactmedfoundation.com" always_nxdomain local-zone: "covid19.cyberschool.or.id" always_nxdomain +local-zone: "covid19vaccinations.hopto.org" always_nxdomain local-zone: "cr-sq.com" always_nxdomain local-zone: "craftech.nxtnet.ga" always_nxdomain local-zone: "crearechile.cl" always_nxdomain @@ -287,6 +289,7 @@ local-zone: "dl.1003b.56a.com" always_nxdomain local-zone: "dl.198424.com" always_nxdomain local-zone: "dl.installcdn-aws.com" always_nxdomain local-zone: "dl.packetstormsecurity.net" always_nxdomain +local-zone: "dl.pandasecur.com" always_nxdomain local-zone: "dl.rina-roleplay.com" always_nxdomain local-zone: "dnn.alibuf.com" always_nxdomain local-zone: "dns.alibuf.com" always_nxdomain @@ -343,11 +346,11 @@ local-zone: "endurotanzania.co.tz" always_nxdomain local-zone: "ennovate.elin.co.za" always_nxdomain local-zone: "equimination.ee" always_nxdomain local-zone: "erp.nanotechproautocare.com" always_nxdomain +local-zone: "esaja09.top" always_nxdomain local-zone: "escola.probommar.org.br" always_nxdomain local-zone: "eservices.immigration.gov.lk" always_nxdomain local-zone: "esnconsultants.com" always_nxdomain local-zone: "essentia.org.br" always_nxdomain -local-zone: "ethereality.info" always_nxdomain local-zone: "eubanks7.com" always_nxdomain local-zone: "europeanzonexxi.com" always_nxdomain local-zone: "exilum.com" always_nxdomain @@ -365,7 +368,7 @@ local-zone: "fineartgallerym.com" always_nxdomain local-zone: "fisconline.bar" always_nxdomain local-zone: "fisconline.casa" always_nxdomain local-zone: "fix-america-now.org" always_nxdomain -local-zone: "fixauto.illumetechnology.com" always_nxdomain +local-zone: "fkd.derpcity.ru" always_nxdomain local-zone: "flexypay.dsquaregroup.com" always_nxdomain local-zone: "flintspin.com" always_nxdomain local-zone: "flyingbuddhadesign.com" always_nxdomain @@ -386,7 +389,6 @@ local-zone: "fusionfiresolutions.com" always_nxdomain local-zone: "futbolpr.com" always_nxdomain local-zone: "futuregraphics.com.ar" always_nxdomain local-zone: "g.pinmonkey.xyz" always_nxdomain -local-zone: "gaditastour.com" always_nxdomain local-zone: "gametwogame.com" always_nxdomain local-zone: "garciadogshow.com" always_nxdomain local-zone: "garenanow.myvnc.com" always_nxdomain @@ -416,7 +418,6 @@ local-zone: "goldenasiacapital.com" always_nxdomain local-zone: "goldmen.in" always_nxdomain local-zone: "gpotecnosystems.com" always_nxdomain local-zone: "gracejukes.com" always_nxdomain -local-zone: "greataccesstoserver.com" always_nxdomain local-zone: "grupoinmare.com" always_nxdomain local-zone: "gruposelt.000webhostapp.com" always_nxdomain local-zone: "gs.monerorx.com" always_nxdomain @@ -447,17 +448,13 @@ local-zone: "hitstation.nl" always_nxdomain local-zone: "hmpmall.co.kr" always_nxdomain local-zone: "hoagietesting10.com" always_nxdomain local-zone: "hoayeuthuong-my.sharepoint.com" always_nxdomain -local-zone: "holmesservices.mobiledevsite.co" always_nxdomain local-zone: "homefindersolutions.com" always_nxdomain local-zone: "hometownchick.com" always_nxdomain -local-zone: "hongluosi.com" always_nxdomain local-zone: "hookedupboatclub.com" always_nxdomain local-zone: "hostingparacolombia.com" always_nxdomain local-zone: "hostzaa.com" always_nxdomain -local-zone: "houstonshutters.site" always_nxdomain local-zone: "hr2019.vrcom7.com" always_nxdomain local-zone: "hseda.com" always_nxdomain -local-zone: "hsmwebapp.com" always_nxdomain local-zone: "htownbars.com" always_nxdomain local-zone: "hubtech.co.za" always_nxdomain local-zone: "huellacero.cl" always_nxdomain @@ -505,6 +502,8 @@ local-zone: "isso.ps" always_nxdomain local-zone: "it123.ru" always_nxdomain local-zone: "italiandirezione.casa" always_nxdomain local-zone: "itc-demo.softgig.co.ke" always_nxdomain +local-zone: "itsrlytry.000webhostapp.com" always_nxdomain +local-zone: "jaishomo.info" always_nxdomain local-zone: "jamiekaylive.com" always_nxdomain local-zone: "jamshed.pk" always_nxdomain local-zone: "jansen-heesch.nl" always_nxdomain @@ -532,11 +531,11 @@ local-zone: "kalogirosfinance.com" always_nxdomain local-zone: "kaptaanchapal.com" always_nxdomain local-zone: "karer.by" always_nxdomain local-zone: "katanvetov.co.il" always_nxdomain +local-zone: "katelynn9506a.ru.com" always_nxdomain local-zone: "kensingtondriving.com" always_nxdomain local-zone: "ketofitnessexpert.com" always_nxdomain local-zone: "kevinjewelry.com.co" always_nxdomain local-zone: "keywatch.yourpageserver.com" always_nxdomain -local-zone: "kihn-delaney30gn.ru.com" always_nxdomain local-zone: "kingssa.co.za" always_nxdomain local-zone: "kjcpromo.com" always_nxdomain local-zone: "kleinendeli.co.za" always_nxdomain @@ -544,7 +543,6 @@ local-zone: "korrectconceptservices.com" always_nxdomain local-zone: "krisbadminton.com" always_nxdomain local-zone: "ktb.sch.id" always_nxdomain local-zone: "kubatoglubaklava.com.tr" always_nxdomain -local-zone: "kullumanalitours.com" always_nxdomain local-zone: "kumaralok.in" always_nxdomain local-zone: "kwanfromhongkong.com" always_nxdomain local-zone: "kz.sldov.ru" always_nxdomain @@ -601,7 +599,6 @@ local-zone: "mail.jeffsono.org" always_nxdomain local-zone: "maksi.feb.unib.ac.id" always_nxdomain local-zone: "malaya.tv" always_nxdomain local-zone: "malwarecoding.github.io" always_nxdomain -local-zone: "managed.oss-cn-beijing.aliyuncs.com" always_nxdomain local-zone: "managemysalon.in" always_nxdomain local-zone: "manantialesdelnorte.uy" always_nxdomain local-zone: "manhtien.net" always_nxdomain @@ -644,6 +641,7 @@ local-zone: "michimal2.000webhostapp.com" always_nxdomain local-zone: "microblading.mirliandias.com.br" always_nxdomain local-zone: "microcomm-group.com" always_nxdomain local-zone: "mikhailmotoringschool.com" always_nxdomain +local-zone: "mills-skyla30ec.com" always_nxdomain local-zone: "mingguanwms.com" always_nxdomain local-zone: "minuevavida.org" always_nxdomain local-zone: "mirror.mypage.sk" always_nxdomain @@ -660,6 +658,7 @@ local-zone: "monetization.business" always_nxdomain local-zone: "moninediy.com" always_nxdomain local-zone: "moreirawag.ac.ug" always_nxdomain local-zone: "motorcomunicacion.com" always_nxdomain +local-zone: "moumitas.com" always_nxdomain local-zone: "msacontabil.com.br" always_nxdomain local-zone: "mumgee.co.za" always_nxdomain local-zone: "muzimbiti.xigubo.co.mz" always_nxdomain @@ -709,6 +708,7 @@ local-zone: "nyasabigbullets.com" always_nxdomain local-zone: "nyeh2o.com.au" always_nxdomain local-zone: "obseques-conseils.com" always_nxdomain local-zone: "oecteam.com" always_nxdomain +local-zone: "ohe.ie" always_nxdomain local-zone: "ohsewgorgeous.co.uk" always_nxdomain local-zone: "oleholeh.memangbeda.website" always_nxdomain local-zone: "omaia.org" always_nxdomain @@ -719,7 +719,6 @@ local-zone: "omscoc.pappai.com" always_nxdomain local-zone: "onedigitalcard.granvizionnecorp.com" always_nxdomain local-zone: "onedrive.listifyapp.co" always_nxdomain local-zone: "online.creedglobal.in" always_nxdomain -local-zone: "open.rawntech.com" always_nxdomain local-zone: "open.warehousesaas.co.uk" always_nxdomain local-zone: "opolis.io" always_nxdomain local-zone: "optimus.com.sg" always_nxdomain @@ -794,6 +793,7 @@ local-zone: "prox.realunix.cc" always_nxdomain local-zone: "pujashoppe.in" always_nxdomain local-zone: "punchdialogues.com" always_nxdomain local-zone: "punjabdevelopersassociation.com.pk" always_nxdomain +local-zone: "pvcprinting.co.uk" always_nxdomain local-zone: "qadir.tickfa.ir" always_nxdomain local-zone: "qatarglobalconsulting.com" always_nxdomain local-zone: "qmsled.com" always_nxdomain @@ -820,16 +820,15 @@ local-zone: "readwrite26.nl" always_nxdomain local-zone: "readymmade.com" always_nxdomain local-zone: "recyclethesurplus.com" always_nxdomain local-zone: "redbats.co.in" always_nxdomain +local-zone: "redboxmultimedia.com" always_nxdomain local-zone: "redchillicrackers.com" always_nxdomain local-zone: "reifenquick.de" always_nxdomain -local-zone: "relaxindulge.co.nz" always_nxdomain local-zone: "renehavis.com.ua" always_nxdomain local-zone: "repatriacioncolombia.com" always_nxdomain local-zone: "res.uf1.cn" always_nxdomain local-zone: "reseller.digimitra.in" always_nxdomain local-zone: "reseller.itechbrasil.com" always_nxdomain local-zone: "resuco.net" always_nxdomain -local-zone: "revolet-sa.com" always_nxdomain local-zone: "rezkabum.ru" always_nxdomain local-zone: "rhema.com.sg" always_nxdomain local-zone: "richmondminerals.co.zm" always_nxdomain @@ -844,6 +843,7 @@ local-zone: "romanianpoints.com" always_nxdomain local-zone: "ronnietucker.co.uk" always_nxdomain local-zone: "roomsvc.servegate.kr" always_nxdomain local-zone: "roshnijewellery.com" always_nxdomain +local-zone: "rotronics.com.ph" always_nxdomain local-zone: "rsgym.net" always_nxdomain local-zone: "rubazar.pro" always_nxdomain local-zone: "rubycityvietnam.com" always_nxdomain @@ -872,6 +872,7 @@ local-zone: "scheff.com" always_nxdomain local-zone: "schoolbustracker.softgig.co.ke" always_nxdomain local-zone: "sculetus.nl" always_nxdomain local-zone: "secure-doc-reader.com" always_nxdomain +local-zone: "secure.activedirect.xyz" always_nxdomain local-zone: "segalsmetals.elin.co.za" always_nxdomain local-zone: "sellmyphonela.com" always_nxdomain local-zone: "selltechtoday.com" always_nxdomain @@ -881,7 +882,9 @@ local-zone: "serendibsourcing.com" always_nxdomain local-zone: "sericaasia.com" always_nxdomain local-zone: "servicemhkd.myvnc.com" always_nxdomain local-zone: "servicemhkd80.myvnc.com" always_nxdomain +local-zone: "serviciovirtual.com.ar" always_nxdomain local-zone: "sexologistpakistan.net" always_nxdomain +local-zone: "sgb.ac.ke" always_nxdomain local-zone: "sgessy.com.br" always_nxdomain local-zone: "shaheentbfoundation.com" always_nxdomain local-zone: "shahikhana.cstdevs.com" always_nxdomain @@ -919,7 +922,6 @@ local-zone: "sobariko.com" always_nxdomain local-zone: "sobethuacademy.com" always_nxdomain local-zone: "soft.110route.com" always_nxdomain local-zone: "soft.officelabo.net" always_nxdomain -local-zone: "sogecoenergy.com" always_nxdomain local-zone: "sohs.conceptechs.info" always_nxdomain local-zone: "solar.amazingtribe.lk" always_nxdomain local-zone: "somcorbera.cat" always_nxdomain @@ -933,7 +935,6 @@ local-zone: "spent.com.pl" always_nxdomain local-zone: "spetsesyachtcharter.gr" always_nxdomain local-zone: "spititourism.com" always_nxdomain local-zone: "spittinfire.com" always_nxdomain -local-zone: "springbedspetroleum.com" always_nxdomain local-zone: "src1.minibai.com" always_nxdomain local-zone: "sreenivasapaintingworks.com" always_nxdomain local-zone: "sriglobalit.com" always_nxdomain @@ -944,16 +945,23 @@ local-zone: "st.devcodin.com" always_nxdomain local-zone: "staging.apparelpunch.com" always_nxdomain local-zone: "starcountry.net" always_nxdomain local-zone: "static.3001.net" always_nxdomain +local-zone: "stdynbnbnewagedevixz.dns.army" always_nxdomain +local-zone: "stdynmxwllminoragest.dns.army" always_nxdomain +local-zone: "stdyunitedkesokokgst.dns.army" always_nxdomain +local-zone: "stdyworkfinetraingst.dns.army" always_nxdomain +local-zone: "stdyzgchgcloudgostxs.dns.army" always_nxdomain local-zone: "stiau.iuc.ac" always_nxdomain local-zone: "sticker.jewsjuice.com" always_nxdomain local-zone: "stiepancasetia.ac.id" always_nxdomain local-zone: "stlukesohag.com" always_nxdomain local-zone: "store.ericalgarin.com" always_nxdomain local-zone: "stott-thompson.co.uk" always_nxdomain +local-zone: "stratexec.co.za" always_nxdomain local-zone: "streetdemo.yourpageserver.com" always_nxdomain local-zone: "suboldesign.com" always_nxdomain local-zone: "sumerians.org" always_nxdomain local-zone: "sunaryem.com.tr" always_nxdomain +local-zone: "sunbrero.com.au" always_nxdomain local-zone: "sunmarkholidays.com" always_nxdomain local-zone: "support-4-free.com" always_nxdomain local-zone: "support.clz.kr" always_nxdomain @@ -1032,7 +1040,6 @@ local-zone: "topcell9.com" always_nxdomain local-zone: "toplevel.com.br" always_nxdomain local-zone: "topmask.co.za" always_nxdomain local-zone: "torresquinterocorp.com" always_nxdomain -local-zone: "towme.services" always_nxdomain local-zone: "toyotacollege.ac.th" always_nxdomain local-zone: "tpke.hu" always_nxdomain local-zone: "translaterjemah.com" always_nxdomain @@ -1059,7 +1066,6 @@ local-zone: "union.jctrip.cn" always_nxdomain local-zone: "unyazitelecom.com" always_nxdomain local-zone: "up.llw0.com" always_nxdomain local-zone: "upcbpta.com" always_nxdomain -local-zone: "used-jeans.fr" always_nxdomain local-zone: "useformoney.000webhostapp.com" always_nxdomain local-zone: "uss.ac.th" always_nxdomain local-zone: "uzzepay.com.br" always_nxdomain @@ -1068,7 +1074,6 @@ local-zone: "vbcargo.hu" always_nxdomain local-zone: "vcah.co.uk" always_nxdomain local-zone: "vectarts.com" always_nxdomain local-zone: "vegadelcasero.cl" always_nxdomain -local-zone: "velma-harber30ku.com" always_nxdomain local-zone: "vendas.lidiacarmeli.com.br" always_nxdomain local-zone: "veterinariadrpopui.com" always_nxdomain local-zone: "vfocus.net" always_nxdomain @@ -1084,7 +1089,6 @@ local-zone: "vivationdesign.com" always_nxdomain local-zone: "viveirodoiscorregos.com.br" always_nxdomain local-zone: "vksales.com" always_nxdomain local-zone: "vocalterra.com" always_nxdomain -local-zone: "vokasi.ub.ac.id" always_nxdomain local-zone: "vologroup.com.br" always_nxdomain local-zone: "voteyouramerica.dekitout.com" always_nxdomain local-zone: "vpts.co.za" always_nxdomain @@ -1105,6 +1109,7 @@ local-zone: "webpresario.com" always_nxdomain local-zone: "weinsteincounseling.com" always_nxdomain local-zone: "wfinance.com.br" always_nxdomain local-zone: "whcms.yourpageserver.com" always_nxdomain +local-zone: "whiteglovetailgate.com" always_nxdomain local-zone: "whiteresponse.com" always_nxdomain local-zone: "wi522012.ferozo.com" always_nxdomain local-zone: "wikalen.co.za" always_nxdomain @@ -1134,6 +1139,7 @@ local-zone: "yeichner.com" always_nxdomain local-zone: "yeq.i.u.j.ia.n.3@zytrox.tk" always_nxdomain local-zone: "ylfpremium.com" always_nxdomain local-zone: "yoast.yourpageserver.com" always_nxdomain +local-zone: "yp.hnggzyjy.cn" always_nxdomain local-zone: "yummyyogaudaipur.com" always_nxdomain local-zone: "yzkzixun.com" always_nxdomain local-zone: "ziyker4gaming@zytrox.tk" always_nxdomain diff --git a/urlhaus-filter-unbound.conf b/urlhaus-filter-unbound.conf index 2590d558..a3ae17e9 100644 --- a/urlhaus-filter-unbound.conf +++ b/urlhaus-filter-unbound.conf @@ -1,5 +1,5 @@ # Title: Malicious Domains Unbound Blocklist -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -1438,7 +1438,6 @@ local-zone: "6481254.ru" always_nxdomain local-zone: "649924.nchsoftwarecom.com" always_nxdomain local-zone: "64x9bg.ch.files.1drv.com" always_nxdomain local-zone: "650x.com" always_nxdomain -local-zone: "654tyfcdr4654fytfy.top" always_nxdomain local-zone: "65k2.com" always_nxdomain local-zone: "66-gifts.com" always_nxdomain local-zone: "662ekeep6.com" always_nxdomain @@ -1476,7 +1475,6 @@ local-zone: "6gsdlmpym.com" always_nxdomain local-zone: "6gue98ddw4220152.freebackup.site" always_nxdomain local-zone: "6hffgq.dm.files.1drv.com" always_nxdomain local-zone: "6hu.xyz" always_nxdomain -local-zone: "6ip.us" always_nxdomain local-zone: "6iptv.com" always_nxdomain local-zone: "6itokam.com" always_nxdomain local-zone: "6kd743o1w.com" always_nxdomain @@ -1869,7 +1867,6 @@ local-zone: "a.deadnig.ga" always_nxdomain local-zone: "a.doko.moe" always_nxdomain local-zone: "a.gg.fm" always_nxdomain local-zone: "a.heritageandterre.com" always_nxdomain -local-zone: "a.pomf.cat" always_nxdomain local-zone: "a.pomf.se" always_nxdomain local-zone: "a.pomf.space" always_nxdomain local-zone: "a.pomf.su" always_nxdomain @@ -6583,7 +6580,6 @@ local-zone: "anmingsi.com" always_nxdomain local-zone: "anmocnhien.vn" always_nxdomain local-zone: "anmolanwar.com" always_nxdomain local-zone: "ann141.net" always_nxdomain -local-zone: "anna.websaiting.ru" always_nxdomain local-zone: "annaaluminium.annagroup.net" always_nxdomain local-zone: "annabelle-hamande.be" always_nxdomain local-zone: "annabphotography.co.uk" always_nxdomain @@ -7098,6 +7094,7 @@ local-zone: "app.bigplan-alex.com" always_nxdomain local-zone: "app.boxrcdn.com" always_nxdomain local-zone: "app.bridgeimpex.org" always_nxdomain local-zone: "app.calag.at" always_nxdomain +local-zone: "app.casetabs.com" always_nxdomain local-zone: "app.catholicchurch.co.in" always_nxdomain local-zone: "app.choiphui.com" always_nxdomain local-zone: "app.cloudindustry.net" always_nxdomain @@ -9004,6 +9001,7 @@ local-zone: "atpcsm.be" always_nxdomain local-zone: "atphitech.com" always_nxdomain local-zone: "atpn.ir" always_nxdomain local-zone: "atprofessional.org" always_nxdomain +local-zone: "atpscan.global.hornetsecurity.com" always_nxdomain local-zone: "atr.it" always_nxdomain local-zone: "atradex.com" always_nxdomain local-zone: "atragon.co.uk" always_nxdomain @@ -9764,6 +9762,8 @@ local-zone: "awswx.xyz" always_nxdomain local-zone: "awsxb.xyz" always_nxdomain local-zone: "awsyscloud.com" always_nxdomain local-zone: "awtinfostore.co.business" always_nxdomain +local-zone: "awumad01.top" always_nxdomain +local-zone: "awuqze02.top" always_nxdomain local-zone: "ax-yogado.com" always_nxdomain local-zone: "axalize.vn" always_nxdomain local-zone: "axalta.grupojenrab.mx" always_nxdomain @@ -11161,6 +11161,7 @@ local-zone: "bbfjjf8.com" always_nxdomain local-zone: "bbfr.cba.pl" always_nxdomain local-zone: "bbgiardinodoriente.it" always_nxdomain local-zone: "bbgk.de" always_nxdomain +local-zone: "bbgroup.com.vn" always_nxdomain local-zone: "bbh-design.de" always_nxdomain local-zone: "bbhdata.com" always_nxdomain local-zone: "bbhs.org.ng" always_nxdomain @@ -11600,7 +11601,6 @@ local-zone: "bekurov.org" always_nxdomain local-zone: "bel-med-tour.ru" always_nxdomain local-zone: "belabargelro.com" always_nxdomain local-zone: "belair.btwstudio.ch" always_nxdomain -local-zone: "belairinternet.com" always_nxdomain local-zone: "belamater.com.br" always_nxdomain local-zone: "belangel.by" always_nxdomain local-zone: "belanja-berkah.xyz" always_nxdomain @@ -11719,7 +11719,6 @@ local-zone: "belyi.ug" always_nxdomain local-zone: "belz-development.de" always_nxdomain local-zone: "belznerdesign.de" always_nxdomain local-zone: "bem.fkep.unpad.ac.id" always_nxdomain -local-zone: "bem.hukum.ub.ac.id" always_nxdomain local-zone: "bem.unimal.ac.id" always_nxdomain local-zone: "bemagazine.club" always_nxdomain local-zone: "bemakeup.ru" always_nxdomain @@ -12492,6 +12491,7 @@ local-zone: "bieres.lavachenoiresud.com" always_nxdomain local-zone: "bierne-les-villages.fr" always_nxdomain local-zone: "biese.eu" always_nxdomain local-zone: "bietthubien.org" always_nxdomain +local-zone: "bietthudep902.com" always_nxdomain local-zone: "bietthulambach.com" always_nxdomain local-zone: "bietthulienkegamuda.net" always_nxdomain local-zone: "bietthumau.com" always_nxdomain @@ -16387,7 +16387,6 @@ local-zone: "callonenergy.com" always_nxdomain local-zone: "callpetercatering.com" always_nxdomain local-zone: "callrealtyaz.com" always_nxdomain local-zone: "callshaal.com" always_nxdomain -local-zone: "callsmaster.com" always_nxdomain local-zone: "calltoprimus.ru" always_nxdomain local-zone: "callumstokes.com" always_nxdomain local-zone: "calm-tech.africa" always_nxdomain @@ -17647,7 +17646,6 @@ local-zone: "cdncomfortgroup.website" always_nxdomain local-zone: "cdndownloadlp.club" always_nxdomain local-zone: "cdnmultimedia.com" always_nxdomain local-zone: "cdnpic.mgyun.com" always_nxdomain -local-zone: "cdnrep.reimageplus.com" always_nxdomain local-zone: "cdnxh.net" always_nxdomain local-zone: "cdoconsult.com.br" always_nxdomain local-zone: "cdolechon.com" always_nxdomain @@ -18439,7 +18437,6 @@ local-zone: "cheekie2.neagoeandrei.com" always_nxdomain local-zone: "cheematransxpressinc.com" always_nxdomain local-zone: "cheerchile.cl" always_nxdomain local-zone: "cheerfulgiversneverlack.com" always_nxdomain -local-zone: "cheerfullydo.com" always_nxdomain local-zone: "cheesecakery.com.br" always_nxdomain local-zone: "cheetahridge.mediadevstaging.com" always_nxdomain local-zone: "chef-solutions.dreamscape.co.in" always_nxdomain @@ -19370,6 +19367,7 @@ local-zone: "clarrywillow.top" always_nxdomain local-zone: "clarte-thailand.com" always_nxdomain local-zone: "clashofclansgems.nl" always_nxdomain local-zone: "clasificados.diaadianews.com" always_nxdomain +local-zone: "clasificadosmaule.com" always_nxdomain local-zone: "class.britishonline.co" always_nxdomain local-zone: "class.snph.ir" always_nxdomain local-zone: "classbrain.net" always_nxdomain @@ -19667,6 +19665,7 @@ local-zone: "clntnjkstdycloudstcy.dns.army" always_nxdomain local-zone: "cloakingtds.xyz" always_nxdomain local-zone: "clock.noixun.com" always_nxdomain local-zone: "clodflarechk.com" always_nxdomain +local-zone: "clodura.ai" always_nxdomain local-zone: "clone.affordable.cm" always_nxdomain local-zone: "clone.system-standex.dk" always_nxdomain local-zone: "cloned.in" always_nxdomain @@ -19852,7 +19851,6 @@ local-zone: "cmeaststar.de" always_nxdomain local-zone: "cmecobrancas.com" always_nxdomain local-zone: "cmelik.com" always_nxdomain local-zone: "cmessagers.com" always_nxdomain -local-zone: "cmg.asia" always_nxdomain local-zone: "cmg.ma" always_nxdomain local-zone: "cmgroup.com.ua" always_nxdomain local-zone: "cmhighschool.edu.bd" always_nxdomain @@ -22391,7 +22389,6 @@ local-zone: "cuacuonsieure.com" always_nxdomain local-zone: "cuadros.pe" always_nxdomain local-zone: "cuahangphongthuy.net" always_nxdomain local-zone: "cuahangstore.com" always_nxdomain -local-zone: "cuahangvattu.com" always_nxdomain local-zone: "cualtis.com" always_nxdomain local-zone: "cuanhomxingfanhapkhau.com" always_nxdomain local-zone: "cuasotinhoc.net" always_nxdomain @@ -22820,6 +22817,7 @@ local-zone: "d.powerofwish.com" always_nxdomain local-zone: "d.qiluwl.com" always_nxdomain local-zone: "d.teamworx.ph" always_nxdomain local-zone: "d.techmartbd.com" always_nxdomain +local-zone: "d.top4top.io" always_nxdomain local-zone: "d.top4top.net" always_nxdomain local-zone: "d.ttr3p.com" always_nxdomain local-zone: "d04.data39.helldata.com" always_nxdomain @@ -24801,6 +24799,7 @@ local-zone: "deportetotal.mx" always_nxdomain local-zone: "deposayim.ml" always_nxdomain local-zone: "depositoclara.com.br" always_nxdomain local-zone: "depot7.com" always_nxdomain +local-zone: "depozituldegeneratoare.ro" always_nxdomain local-zone: "depraetere.net" always_nxdomain local-zone: "deprealty.ru" always_nxdomain local-zone: "depressionted.com" always_nxdomain @@ -26527,7 +26526,6 @@ local-zone: "dl-45538429.onedrives-en-live.com" always_nxdomain local-zone: "dl-675423.store-downloads.com" always_nxdomain local-zone: "dl-80076342.md-downloads.com" always_nxdomain local-zone: "dl-97674424.md-downloads.com" always_nxdomain -local-zone: "dl-gameplayer.dmm.com" always_nxdomain local-zone: "dl-link.link" always_nxdomain local-zone: "dl-link.live" always_nxdomain local-zone: "dl-link.network" always_nxdomain @@ -26550,9 +26548,9 @@ local-zone: "dl.ikiki.cn" always_nxdomain local-zone: "dl.imht.ir" always_nxdomain local-zone: "dl.installcdn-aws.com" always_nxdomain local-zone: "dl.mqego.com" always_nxdomain -local-zone: "dl.mydown.com" always_nxdomain local-zone: "dl.ossdown.fun" always_nxdomain local-zone: "dl.packetstormsecurity.net" always_nxdomain +local-zone: "dl.pandasecur.com" always_nxdomain local-zone: "dl.popupgrade.com" always_nxdomain local-zone: "dl.repairlabshost.com" always_nxdomain local-zone: "dl.rina-roleplay.com" always_nxdomain @@ -26729,6 +26727,9 @@ local-zone: "dobrojutrodjevojke.com" always_nxdomain local-zone: "dobroviz.com.ua" always_nxdomain local-zone: "dobrovorot.su" always_nxdomain local-zone: "dobsoncentral.com" always_nxdomain +local-zone: "doc-0s-7c-docs.googleusercontent.com" always_nxdomain +local-zone: "doc-10-0c-docs.googleusercontent.com" always_nxdomain +local-zone: "doc-10-8s-docs.googleusercontent.com" always_nxdomain local-zone: "doc-hub.healthycheapfast.com" always_nxdomain local-zone: "doc-japan.com" always_nxdomain local-zone: "doc.albaspizzaastoria.com" always_nxdomain @@ -29003,6 +29004,7 @@ local-zone: "ec2-52-56-233-157.eu-west-2.compute.amazonaws.com" always_nxdomain local-zone: "ec2-54-207-92-161.sa-east-1.compute.amazonaws.com" always_nxdomain local-zone: "ec2-54-212-231-68.us-west-2.compute.amazonaws.com" always_nxdomain local-zone: "ec2-54-94-215-87.sa-east-1.compute.amazonaws.com" always_nxdomain +local-zone: "ec2euc1.boxcloud.com" always_nxdomain local-zone: "ec2test.ga" always_nxdomain local-zone: "ec3-design.com" always_nxdomain local-zone: "ecadigital.com" always_nxdomain @@ -31303,6 +31305,7 @@ local-zone: "es.thevoucherstop.com" always_nxdomain local-zone: "esaarc.com" always_nxdomain local-zone: "esacbd.com" always_nxdomain local-zone: "esagarautomobiles.com" always_nxdomain +local-zone: "esaja09.top" always_nxdomain local-zone: "esanjobs.org" always_nxdomain local-zone: "esar.weenets.com" always_nxdomain local-zone: "esascom.com" always_nxdomain @@ -37097,7 +37100,6 @@ local-zone: "genregis.com" always_nxdomain local-zone: "genrjw.dm.files.1drv.com" always_nxdomain local-zone: "genstaff.gov.kg" always_nxdomain local-zone: "gentcreativa.com" always_nxdomain -local-zone: "gentecoyol.com" always_nxdomain local-zone: "gentesanluis.com" always_nxdomain local-zone: "gentiane-salers.com" always_nxdomain local-zone: "gentlechirocenter.com" always_nxdomain @@ -39846,6 +39848,7 @@ local-zone: "gvou7g.by.files.1drv.com" always_nxdomain local-zone: "gvpcdpgc.edu.in" always_nxdomain local-zone: "gvpmacademy.co.za" always_nxdomain local-zone: "gvsme.com" always_nxdomain +local-zone: "gw.daelimcloud.com" always_nxdomain local-zone: "gw.hitlin.com" always_nxdomain local-zone: "gwangjuhotels.kr" always_nxdomain local-zone: "gwavellc.com" always_nxdomain @@ -42657,7 +42660,6 @@ local-zone: "hotelvip-bron.ru" always_nxdomain local-zone: "hotelwaldblick.com" always_nxdomain local-zone: "hotexpress.co" always_nxdomain local-zone: "hotfacts.org" always_nxdomain -local-zone: "hotgifts.online" always_nxdomain local-zone: "hotilife.com" always_nxdomain local-zone: "hotissue.xyz" always_nxdomain local-zone: "hotkine.com" always_nxdomain @@ -43035,7 +43037,6 @@ local-zone: "hukouec-ltd.com" always_nxdomain local-zone: "hukuen-motokare.xyz" always_nxdomain local-zone: "hukuki.site" always_nxdomain local-zone: "hukukportal.com" always_nxdomain -local-zone: "hukum.ub.ac.id" always_nxdomain local-zone: "hukum.unwiku.ac.id" always_nxdomain local-zone: "hulianwang114.com" always_nxdomain local-zone: "huliot.in" always_nxdomain @@ -43357,6 +43358,7 @@ local-zone: "i-sharecloud.com" always_nxdomain local-zone: "i-supportcharity.com" always_nxdomain local-zone: "i-vnsweyu.pl" always_nxdomain local-zone: "i-voda.com" always_nxdomain +local-zone: "i.fiery.me" always_nxdomain local-zone: "i.fluffy.cc" always_nxdomain local-zone: "i.funtourspt.eu" always_nxdomain local-zone: "i.n.t.e.rloca.l.qs.j.y@jfas.top" always_nxdomain @@ -46637,6 +46639,7 @@ local-zone: "itspread.com" always_nxdomain local-zone: "itspsc.com.ua" always_nxdomain local-zone: "itspueh.nl" always_nxdomain local-zone: "itsquare.yrcreations.com" always_nxdomain +local-zone: "itsrlytry.000webhostapp.com" always_nxdomain local-zone: "itssprout.com" always_nxdomain local-zone: "itstelecom.com.br" always_nxdomain local-zone: "itsweezle.com" always_nxdomain @@ -46836,6 +46839,7 @@ local-zone: "j-skill.ru" always_nxdomain local-zone: "j-stage.jp" always_nxdomain local-zone: "j-toputvoutfitters.com" always_nxdomain local-zone: "j.kyryl.ru" always_nxdomain +local-zone: "j.top4top.io" always_nxdomain local-zone: "j11g9xecuxe43xu.xyz" always_nxdomain local-zone: "j12z7407gwtzk.xyz" always_nxdomain local-zone: "j13.biz" always_nxdomain @@ -46968,6 +46972,7 @@ local-zone: "jaipurjungle.co.in" always_nxdomain local-zone: "jaipurweddingphotography.com" always_nxdomain local-zone: "jairathsnatural.ca" always_nxdomain local-zone: "jairozapata.000webhostapp.com" always_nxdomain +local-zone: "jaishomo.info" always_nxdomain local-zone: "jaishritours.com" always_nxdomain local-zone: "jaiswalsupplement.com" always_nxdomain local-zone: "jajadomains.com" always_nxdomain @@ -50996,7 +51001,6 @@ local-zone: "kodiakpro.ca" always_nxdomain local-zone: "kodim0112sabang.com" always_nxdomain local-zone: "kodingeko.com" always_nxdomain local-zone: "kodip.nfile.net" always_nxdomain -local-zone: "kodjdsjsdjf.tk" always_nxdomain local-zone: "kodlacan.site" always_nxdomain local-zone: "kodmuje.com" always_nxdomain local-zone: "kodolios.000webhostapp.com" always_nxdomain @@ -53636,6 +53640,7 @@ local-zone: "library.arihantmbainstitute.ac.in" always_nxdomain local-zone: "library.cifor.org" always_nxdomain local-zone: "library.dhl-xom.com" always_nxdomain local-zone: "library.iainbengkulu.ac.id" always_nxdomain +local-zone: "library.mju.ac.th" always_nxdomain local-zone: "library.phibi.my.id" always_nxdomain local-zone: "library.piet.co.in" always_nxdomain local-zone: "library.strophicmusic.com" always_nxdomain @@ -54322,7 +54327,6 @@ local-zone: "livechallenge.fr" always_nxdomain local-zone: "livecigarevent.com" always_nxdomain local-zone: "livecricketscorecard.info" always_nxdomain local-zone: "livedaynews.com" always_nxdomain -local-zone: "livedemo00.template-help.com" always_nxdomain local-zone: "livedownload.in" always_nxdomain local-zone: "livedrumtracks.com" always_nxdomain local-zone: "livefarma.com" always_nxdomain @@ -54355,7 +54359,6 @@ local-zone: "livesouvenir.com" always_nxdomain local-zone: "livestreams.vn" always_nxdomain local-zone: "livesuitesapartdaire.com" always_nxdomain local-zone: "livesurgerycourse.ir" always_nxdomain -local-zone: "liveswinburneeduau-my.sharepoint.com" always_nxdomain local-zone: "liveswindow.casa" always_nxdomain local-zone: "liveswindow.cyou" always_nxdomain local-zone: "liveswindows.bar" always_nxdomain @@ -55530,7 +55533,6 @@ local-zone: "luzbarbosa.com.br" always_nxdomain local-zone: "luzconsulting.com.br" always_nxdomain local-zone: "luzevida.com.br" always_nxdomain local-zone: "luzfloral.com" always_nxdomain -local-zone: "luzy.vn" always_nxdomain local-zone: "luzzeri.com" always_nxdomain local-zone: "lvajnczdy.cf" always_nxdomain local-zone: "lvcfund.org.vn" always_nxdomain @@ -58568,7 +58570,6 @@ local-zone: "mecflui.com.br" always_nxdomain local-zone: "mecgwl.ac.in" always_nxdomain local-zone: "mechanicaltools.club" always_nxdomain local-zone: "mechanicsthatcometoyou.com" always_nxdomain -local-zone: "mecharnise.ir" always_nxdomain local-zone: "mechathrones.com" always_nxdomain local-zone: "mechauto.co.za" always_nxdomain local-zone: "mechdesign.com" always_nxdomain @@ -59154,7 +59155,6 @@ local-zone: "menxhiqi.com" always_nxdomain local-zone: "menziesadvisory-my.sharepoint.com" always_nxdomain local-zone: "menzway.com" always_nxdomain local-zone: "meogiambeo.com" always_nxdomain -local-zone: "meohaybotui.com" always_nxdomain local-zone: "meolamdephay.com" always_nxdomain local-zone: "mepsgen.com" always_nxdomain local-zone: "mera.ddns.net" always_nxdomain @@ -59472,6 +59472,7 @@ local-zone: "mfmr.gov.sl" always_nxdomain local-zone: "mfomjr.com" always_nxdomain local-zone: "mfotovideo.ro" always_nxdomain local-zone: "mfpburundi.bi" always_nxdomain +local-zone: "mfpc.org.my" always_nxdomain local-zone: "mfppanel.xyz" always_nxdomain local-zone: "mfpvision.com" always_nxdomain local-zone: "mfronza.com.br" always_nxdomain @@ -64504,7 +64505,6 @@ local-zone: "nhadatphonglinh.com" always_nxdomain local-zone: "nhadatquan2.xyz" always_nxdomain local-zone: "nhadatthienthoi.com" always_nxdomain local-zone: "nhadephungyen.com" always_nxdomain -local-zone: "nhadepkientruc.net" always_nxdomain local-zone: "nhahangdaihung.com" always_nxdomain local-zone: "nhahanghaivuong.vn" always_nxdomain local-zone: "nhahanglegiang.vn" always_nxdomain @@ -64718,7 +64718,6 @@ local-zone: "nikanbearing.com" always_nxdomain local-zone: "nikanpolimer.ir" always_nxdomain local-zone: "nikastroi.ru" always_nxdomain local-zone: "nikavkuchyni.sk" always_nxdomain -local-zone: "nikayu.com" always_nxdomain local-zone: "nikbox.ru" always_nxdomain local-zone: "nikeshyadav.com" always_nxdomain local-zone: "nikhil.webscript.co.in" always_nxdomain @@ -67234,7 +67233,6 @@ local-zone: "optimusforce.nl" always_nxdomain local-zone: "option47.us" always_nxdomain local-zone: "optioncapitalgroup.ru" always_nxdomain local-zone: "optionrp.com" always_nxdomain -local-zone: "optionscity.com" always_nxdomain local-zone: "optisaving.com" always_nxdomain local-zone: "optitechsa.co.za" always_nxdomain local-zone: "optocen.ru" always_nxdomain @@ -67529,7 +67527,6 @@ local-zone: "osethmaayurveda.com" always_nxdomain local-zone: "osezrayonner.ma" always_nxdomain local-zone: "osgbforum.com" always_nxdomain local-zone: "oshattorney.com" always_nxdomain -local-zone: "oshi.at" always_nxdomain local-zone: "oshodrycleaning.com" always_nxdomain local-zone: "oshonafitness.com" always_nxdomain local-zone: "oshop.es" always_nxdomain @@ -71229,7 +71226,6 @@ local-zone: "posmaster.co.kr" always_nxdomain local-zone: "posmicrosystems.com" always_nxdomain local-zone: "posnxqmp.ru" always_nxdomain local-zone: "pospeeps.com" always_nxdomain -local-zone: "posqit.net" always_nxdomain local-zone: "possessionnow.com" always_nxdomain local-zone: "possible.re" always_nxdomain local-zone: "possopagar.com.br" always_nxdomain @@ -71865,7 +71861,6 @@ local-zone: "prishaartcreations.com" always_nxdomain local-zone: "prisidmart.com" always_nxdomain local-zone: "priskat.net" always_nxdomain local-zone: "prism-photo.com" always_nxdomain -local-zone: "prisma.fp.ub.ac.id" always_nxdomain local-zone: "prismaxis.com" always_nxdomain local-zone: "prismfox.com" always_nxdomain local-zone: "prismware.ml" always_nxdomain @@ -72457,6 +72452,7 @@ local-zone: "protech.binarybizz.com" always_nxdomain local-zone: "protech.mn" always_nxdomain local-zone: "protechcarpetcare.com" always_nxdomain local-zone: "protechgroup1.com" always_nxdomain +local-zone: "protect.mimecast-offshore.com" always_nxdomain local-zone: "protectiadatelor.biz" always_nxdomain local-zone: "protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org" always_nxdomain local-zone: "protection.pecol.eu" always_nxdomain @@ -72538,6 +72534,7 @@ local-zone: "proxima-solution.com" always_nxdomain local-zone: "proxy-ipv4.com" always_nxdomain local-zone: "proxy.2u0apcm6ylhdy7s.com" always_nxdomain local-zone: "proxy.hueaudio.com" always_nxdomain +local-zone: "proxy.qualtrics.com" always_nxdomain local-zone: "proxygrnd.xyz" always_nxdomain local-zone: "proxyholding.com" always_nxdomain local-zone: "proxyresume.com" always_nxdomain @@ -75051,6 +75048,7 @@ local-zone: "redlk.com" always_nxdomain local-zone: "redlogisticsmaroc.com" always_nxdomain local-zone: "redloop.io" always_nxdomain local-zone: "redlotusevents.com" always_nxdomain +local-zone: "redm1az1.000webhostapp.com" always_nxdomain local-zone: "redmag.by" always_nxdomain local-zone: "redmarcial.ossmarcial.com" always_nxdomain local-zone: "redmediasigns.com" always_nxdomain @@ -76222,6 +76220,7 @@ local-zone: "rkbicycle.com" always_nxdomain local-zone: "rkcable.co.in" always_nxdomain local-zone: "rkfplumbing.co.uk" always_nxdomain local-zone: "rkinstitute.org" always_nxdomain +local-zone: "rkkrstdygorgiousejbg.dns.army" always_nxdomain local-zone: "rkkrstdygorgiousejds.dns.army" always_nxdomain local-zone: "rkkrstdygorgiousejtw.dns.army" always_nxdomain local-zone: "rklkpgcollege.com" always_nxdomain @@ -76778,6 +76777,7 @@ local-zone: "rotiyes.co.id" always_nxdomain local-zone: "rotoblast.org" always_nxdomain local-zone: "rotor.olsztyn.pl" always_nxdomain local-zone: "rotoscoop.com" always_nxdomain +local-zone: "rotronics.com.ph" always_nxdomain local-zone: "rott-mtr.de" always_nxdomain local-zone: "rotterdammeetings.nl" always_nxdomain local-zone: "rotulosalarcon.com" always_nxdomain @@ -77191,7 +77191,6 @@ local-zone: "runmagazine.es" always_nxdomain local-zone: "runmureed.com" always_nxdomain local-zone: "runmyweb.com" always_nxdomain local-zone: "runnected.kaiman.fr" always_nxdomain -local-zone: "runnerbd.com" always_nxdomain local-zone: "runnerschool.com" always_nxdomain local-zone: "running-bike.com" always_nxdomain local-zone: "runningcrewteam.com" always_nxdomain @@ -78713,6 +78712,7 @@ local-zone: "savemodificationgloballyfromthepinaltypo.duckdns.org" always_nxdoma local-zone: "savemyfile.3utilities.com" always_nxdomain local-zone: "savemyseatnow.com" always_nxdomain local-zone: "saveraahealthcare.com" always_nxdomain +local-zone: "saveserpnow.com" always_nxdomain local-zone: "saveserpresults.com" always_nxdomain local-zone: "savestudio.com" always_nxdomain local-zone: "savetax.idfcmf.com" always_nxdomain @@ -79390,6 +79390,7 @@ local-zone: "secure-net.tech" always_nxdomain local-zone: "secure-risk.namaskara.me" always_nxdomain local-zone: "secure-snupa.com" always_nxdomain local-zone: "secure.accounts.resourses.com" always_nxdomain +local-zone: "secure.activedirect.xyz" always_nxdomain local-zone: "secure.anchorssb.co" always_nxdomain local-zone: "secure.app-amazon.com.recovery-account.amazon.com.alphatravelmongolia.com" always_nxdomain local-zone: "secure.bodybuilderabs.net" always_nxdomain @@ -80067,7 +80068,6 @@ local-zone: "service.atlink.ir" always_nxdomain local-zone: "service.dawat.fr" always_nxdomain local-zone: "service.drnjithendran.com" always_nxdomain local-zone: "service.eftformotherissues.com" always_nxdomain -local-zone: "service.ezsoftwareupdater.com" always_nxdomain local-zone: "service.heritageimagingcenter.com" always_nxdomain local-zone: "service.hybridhomesteam.com" always_nxdomain local-zone: "service.idealfurnitureoutlet.com" always_nxdomain @@ -80572,6 +80572,7 @@ local-zone: "shareallfilesthroughsecureexchangesystem.duckdns.org" always_nxdoma local-zone: "sharebook.tk" always_nxdomain local-zone: "sharechautari.com" always_nxdomain local-zone: "shared-cnd.com" always_nxdomain +local-zone: "shared.outlook.inky.com" always_nxdomain local-zone: "shareddocuments.ml" always_nxdomain local-zone: "shareddynamics.com" always_nxdomain local-zone: "sharedeconomy.eu" always_nxdomain @@ -84935,9 +84936,11 @@ local-zone: "stdymjventsluzcafoik.dns.army" always_nxdomain local-zone: "stdymjventsluzcafsrp.dns.army" always_nxdomain local-zone: "stdymorcmmylntwincdq.dns.army" always_nxdomain local-zone: "stdymorcmmylntwinstr.dns.army" always_nxdomain +local-zone: "stdynbnbnewagedevixz.dns.army" always_nxdomain local-zone: "stdynbnbnewagedevsmn.dns.army" always_nxdomain local-zone: "stdynbnbnewagedevxaz.dns.army" always_nxdomain local-zone: "stdyneverwalkachinese2loneinlifekstgqm.ydns.eu" always_nxdomain +local-zone: "stdynmxwllminoragest.dns.army" always_nxdomain local-zone: "stdyperezluzcafeyzst.dns.navy" always_nxdomain local-zone: "stdypmrimelimtwstogy.dns.army" always_nxdomain local-zone: "stdypycsslwinnerscot.dns.army" always_nxdomain @@ -84968,6 +84971,7 @@ local-zone: "stdytoprehtwoyertwfd.dns.army" always_nxdomain local-zone: "stdytopreoneenversrw.dns.army" always_nxdomain local-zone: "stdytopreoneenvervaj.dns.army" always_nxdomain local-zone: "stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu" always_nxdomain +local-zone: "stdyunitedkesokokgst.dns.army" always_nxdomain local-zone: "stdyunitedkesokostdr.dns.army" always_nxdomain local-zone: "stdyunitedkesokostri.dns.navy" always_nxdomain local-zone: "stdyunitedkesokostxc.dns.army" always_nxdomain @@ -84977,7 +84981,9 @@ local-zone: "stdyworkfineanotherrainbowlomoyentstbmd.duckdns.org" always_nxdomai local-zone: "stdyworkfineanotherrainbowlomoyentwkgls.duckdns.org" always_nxdomain local-zone: "stdyworkfinesanotherrainbowlomoyentstfcp.ydns.eu" always_nxdomain local-zone: "stdyworkfinesanotherrainbowlomoyentstgot.ydns.eu" always_nxdomain +local-zone: "stdyworkfinetraingst.dns.army" always_nxdomain local-zone: "stdyzgchgcloudgostgt.dns.army" always_nxdomain +local-zone: "stdyzgchgcloudgostxs.dns.army" always_nxdomain local-zone: "steadyrestmanufacturers.com" always_nxdomain local-zone: "steak.wpress.dk" always_nxdomain local-zone: "steakhouse.com.ua" always_nxdomain @@ -85537,6 +85543,7 @@ local-zone: "strend.net" always_nxdomain local-zone: "strengthandvigour.com" always_nxdomain local-zone: "strengthrer.com" always_nxdomain local-zone: "strenover.ga" always_nxdomain +local-zone: "stressing.pw" always_nxdomain local-zone: "stressnada.com" always_nxdomain local-zone: "stretchpilates.fit" always_nxdomain local-zone: "strewn.org" always_nxdomain @@ -86228,6 +86235,7 @@ local-zone: "supercrystal.am" always_nxdomain local-zone: "supercutscissors.com" always_nxdomain local-zone: "superdad.id" always_nxdomain local-zone: "superdigitalguy.xyz" always_nxdomain +local-zone: "superdomain1709.info" always_nxdomain local-zone: "superdot.rs" always_nxdomain local-zone: "superecruiters.com" always_nxdomain local-zone: "superfacil.center" always_nxdomain @@ -86331,7 +86339,6 @@ local-zone: "support.m2mservices.com" always_nxdomain local-zone: "support.mdsol.com" always_nxdomain local-zone: "support.nordenrecycling.com" always_nxdomain local-zone: "support.nuvemit.com" always_nxdomain -local-zone: "support.pubg.com" always_nxdomain local-zone: "support.redbook.aero" always_nxdomain local-zone: "support.revolus.xyz" always_nxdomain local-zone: "support.servu.co.uk" always_nxdomain @@ -86676,7 +86683,6 @@ local-zone: "swiat-ksiegowosci.pl" always_nxdomain local-zone: "swicoservers.co.uk" always_nxdomain local-zone: "swieradowbiega.pl" always_nxdomain local-zone: "swifck.xmr.ac" always_nxdomain -local-zone: "swift-cloud.com" always_nxdomain local-zone: "swiftbusinesspay.com" always_nxdomain local-zone: "swiftee.co.uk" always_nxdomain local-zone: "swiftender.com" always_nxdomain @@ -87521,7 +87527,6 @@ local-zone: "tarexfinal.trade" always_nxdomain local-zone: "targas.de" always_nxdomain local-zone: "targat-china.com" always_nxdomain local-zone: "target-events.com" always_nxdomain -local-zone: "target-support.online" always_nxdomain local-zone: "target2cloud.com" always_nxdomain local-zone: "targetbizbd.com" always_nxdomain local-zone: "targetcm.net" always_nxdomain @@ -89102,7 +89107,6 @@ local-zone: "thacci.com.br" always_nxdomain local-zone: "thachastew.com" always_nxdomain local-zone: "thachvietstone.com" always_nxdomain local-zone: "thadathilfarmresort.com" always_nxdomain -local-zone: "thaddeusarmstrong.com" always_nxdomain local-zone: "thadinnoo.co" always_nxdomain local-zone: "thagreymatter.com" always_nxdomain local-zone: "thai-chana.asia" always_nxdomain @@ -90824,7 +90828,6 @@ local-zone: "tlcc.com.gt" always_nxdomain local-zone: "tlcid.org" always_nxdomain local-zone: "tlckids-or.ga" always_nxdomain local-zone: "tlcmoto.com" always_nxdomain -local-zone: "tldrbox.top" always_nxdomain local-zone: "tldrnet.top" always_nxdomain local-zone: "tlextreme.com" always_nxdomain local-zone: "tlfthelifefactory.com.au" always_nxdomain @@ -92421,6 +92424,7 @@ local-zone: "ts-deals.me" always_nxdomain local-zone: "ts.7rb.xyz" always_nxdomain local-zone: "ts0ev73.com" always_nxdomain local-zone: "tsal.com" always_nxdomain +local-zone: "tsapparel.com.my" always_nxdomain local-zone: "tsareva-garden.ru" always_nxdomain local-zone: "tsatsi.co.za" always_nxdomain local-zone: "tsauctions.com" always_nxdomain @@ -92648,6 +92652,7 @@ local-zone: "tunnelpros.com" always_nxdomain local-zone: "tunnelview.co.uk" always_nxdomain local-zone: "tunuvo.com" always_nxdomain local-zone: "tuobrasocial.com.ar" always_nxdomain +local-zone: "tuoitrethainguyen.vn" always_nxdomain local-zone: "tupibaje.com" always_nxdomain local-zone: "tupperware.michaelroberge.ca" always_nxdomain local-zone: "tur.000webhostapp.com" always_nxdomain @@ -93794,7 +93799,6 @@ local-zone: "unlimit517.co.jp" always_nxdomain local-zone: "unlimited.nu" always_nxdomain local-zone: "unlimitedbags.club" always_nxdomain local-zone: "unlimitedfreightco.com" always_nxdomain -local-zone: "unlimitedimportandexport.com" always_nxdomain local-zone: "unlock-king.com" always_nxdomain local-zone: "unlock2.neagoeandrei.com" always_nxdomain local-zone: "unlockall.neagoeandrei.com" always_nxdomain @@ -94120,6 +94124,7 @@ local-zone: "url-update.com" always_nxdomain local-zone: "url-validation-clients.com" always_nxdomain local-zone: "url.246546.com" always_nxdomain local-zone: "url.57569.fr.snd52.ch" always_nxdomain +local-zone: "url2.mailanyone.net" always_nxdomain local-zone: "url3.mailanyone.net" always_nxdomain local-zone: "url5459.41southbar.com" always_nxdomain local-zone: "url675.textilmallorca.com" always_nxdomain @@ -94323,7 +94328,6 @@ local-zone: "utterstock.in" always_nxdomain local-zone: "utting.org" always_nxdomain local-zone: "utv.sakeronline.se" always_nxdomain local-zone: "utv1.enliden.net" always_nxdomain -local-zone: "uujian.cn" always_nxdomain local-zone: "uumove.com" always_nxdomain local-zone: "uurty87e8rt7rt.com" always_nxdomain local-zone: "uutiset.helppokoti.fi" always_nxdomain @@ -96297,7 +96301,6 @@ local-zone: "voin.staysafe.pk" always_nxdomain local-zone: "voingani.it" always_nxdomain local-zone: "voip96.ru" always_nxdomain local-zone: "voipminic.com" always_nxdomain -local-zone: "vokasi.ub.ac.id" always_nxdomain local-zone: "vokzalrf.ru" always_nxdomain local-zone: "vol.agency" always_nxdomain local-zone: "vol2.pw" always_nxdomain @@ -96925,7 +96928,6 @@ local-zone: "washnworks.com" always_nxdomain local-zone: "washuis.nl" always_nxdomain local-zone: "wasidora.com" always_nxdomain local-zone: "wasilewski-online.de" always_nxdomain -local-zone: "wasimjee.com" always_nxdomain local-zone: "wasino.co.th" always_nxdomain local-zone: "wasobd.net" always_nxdomain local-zone: "waspha.com" always_nxdomain @@ -98465,7 +98467,6 @@ local-zone: "woaldi2.com" always_nxdomain local-zone: "woatinkwoo.com" always_nxdomain local-zone: "woclawoffers.fun" always_nxdomain local-zone: "wocomm.marketingmindz.com" always_nxdomain -local-zone: "wodfitapparel.fr" always_nxdomain local-zone: "wodmetaldom.pl" always_nxdomain local-zone: "wodsuit.com" always_nxdomain local-zone: "woelf.in" always_nxdomain @@ -101094,7 +101095,9 @@ local-zone: "yoyoplease.com" always_nxdomain local-zone: "yoyoso.nz" always_nxdomain local-zone: "yoyoteacher.cn" always_nxdomain local-zone: "yp.dcyazilim.com" always_nxdomain +local-zone: "yp.hnggzyjy.cn" always_nxdomain local-zone: "ypbb.or.id" always_nxdomain +local-zone: "ypddf.org" always_nxdomain local-zone: "ypicsdy.cf" always_nxdomain local-zone: "ypko-55.gq" always_nxdomain local-zone: "ypom.com.br" always_nxdomain @@ -101253,7 +101256,6 @@ local-zone: "yusukelife.com" always_nxdomain local-zone: "yuti.kr" always_nxdomain local-zone: "yuvann.com" always_nxdomain local-zone: "yuvikadvertisments.com" always_nxdomain -local-zone: "yuwaraja.vokasi.ub.ac.id" always_nxdomain local-zone: "yuweis.com" always_nxdomain local-zone: "yuxigon.com" always_nxdomain local-zone: "yuxuanknit.com" always_nxdomain diff --git a/urlhaus-filter-vivaldi-online.txt b/urlhaus-filter-vivaldi-online.txt index ab3bf571..7d5a8017 100644 --- a/urlhaus-filter-vivaldi-online.txt +++ b/urlhaus-filter-vivaldi-online.txt @@ -1,5 +1,5 @@ ! Title: Online Malicious URL Blocklist (Vivaldi) -! Updated: Mon, 12 Apr 2021 00:12:54 UTC +! Updated: Mon, 12 Apr 2021 12:13:00 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -39,7 +39,6 @@ ||1.246.222.98$document ||1.246.223.10$document ||1.246.223.105$document -||1.246.223.109$document ||1.246.223.126$document ||1.246.223.127$document ||1.246.223.130$document @@ -70,7 +69,8 @@ ||1008691.com$document ||101.108.129.251$document ||101.108.130.121$document -||101.108.131.47$document +||101.108.131.99$document +||101.108.138.150$document ||101.16.183.179$document ||101.229.85.127$document ||101.255.36.154$document @@ -78,6 +78,8 @@ ||101.28.218.245$document ||101.28.76.34$document ||101.75.157.99$document +||101.99.91.200$document +||101.99.94.15$document ||102.130.115.14$document ||102.141.240.139$document ||103.113.99.79$document @@ -92,25 +94,18 @@ ||103.237.21.36$document ||103.238.228.3$document ||103.240.249.121$document -||103.4.117.26$document -||103.47.104.246$document ||103.79.112.254$document -||103.82.98.170$document +||103.82.81.37$document ||103.84.240.130$document ||103.84.241.94$document ||103.91.245.12$document -||103.91.245.13$document ||103.91.245.14$document -||103.91.245.16$document -||103.91.245.17$document -||103.91.245.27$document -||103.91.245.3$document +||103.91.245.19$document ||103.91.245.36$document -||103.91.245.46$document -||103.91.245.47$document +||103.91.245.48$document ||103.92.25.90$document ||103.92.25.95$document -||104.168.44.57$document +||103.97.184.180$document ||104.184.75.123$document ||104.206.93.94$document ||104.33.52.85$document @@ -121,6 +116,7 @@ ||106.105.33.43$document ||107.172.104.105$document ||107.172.141.115$document +||107.172.156.3$document ||107.172.249.148$document ||107.173.219.80$document ||107.173.23.240$document @@ -137,10 +133,10 @@ ||108.190.250.48$document ||108.239.155.26$document ||108.249.194.121$document -||109.104.151.108$document ||109.124.90.229$document ||109.233.196.232$document ||109.235.7.228$document +||109.248.58.238$document ||109.86.85.253$document ||109.95.200.102$document ||109.95.200.230$document @@ -156,13 +152,13 @@ ||110.248.251.194$document ||110.251.10.18$document ||110.253.213.198$document +||110.35.145.127$document ||110.35.208.21$document -||110.35.209.175$document -||110.35.223.92$document -||110.35.225.24$document +||110.35.221.77$document ||110.35.235.57$document +||110.35.249.21$document ||110.35.4.2$document -||111.118.88.128$document +||110.89.10.147$document ||111.118.88.61$document ||111.119.245.114$document ||111.125.67.125$document @@ -177,12 +173,9 @@ ||111.185.49.223$document ||111.38.103.114$document ||111.38.103.122$document -||111.38.104.141$document ||111.38.121.222$document -||111.38.121.223$document ||111.38.121.226$document ||111.38.123.136$document -||111.38.123.15$document ||111.38.123.200$document ||111.38.26.243$document ||111.38.8.81$document @@ -203,12 +196,8 @@ ||112.230.168.103$document ||112.232.0.112$document ||112.237.141.241$document -||112.237.144.226$document -||112.237.75.157$document -||112.237.99.207$document ||112.238.143.135$document ||112.238.190.207$document -||112.238.227.228$document ||112.238.39.2$document ||112.239.101.146$document ||112.240.216.17$document @@ -222,6 +211,7 @@ ||112.247.214.146$document ||112.247.240.226$document ||112.247.82.122$document +||112.248.109.156$document ||112.248.148.90$document ||112.248.63.212$document ||112.249.109.217$document @@ -241,6 +231,7 @@ ||112.27.124.143$document ||112.27.124.147$document ||112.27.124.149$document +||112.27.124.150$document ||112.27.124.158$document ||112.27.124.165$document ||112.27.124.175$document @@ -273,34 +264,34 @@ ||112.30.1.60$document ||112.30.1.90$document ||112.30.1.91$document +||112.30.110.30$document ||112.30.110.38$document ||112.30.110.45$document ||112.30.110.60$document ||112.30.35.237$document -||112.30.4.103$document ||112.30.4.118$document ||112.30.4.124$document ||112.30.4.53$document ||112.30.4.61$document ||112.30.4.68$document -||112.30.4.70$document ||112.30.4.73$document ||112.30.4.90$document ||112.31.0.113$document ||112.31.177.39$document -||112.31.211.135$document ||112.31.216.207$document -||112.31.240.239$document ||112.53.224.79$document ||112.53.227.66$document ||112.65.53.175$document +||112.72.162.159$document ||112.72.162.49$document ||112.72.175.147$document ||112.72.176.112$document +||112.72.176.84$document ||112.72.226.202$document ||112.80.215.101$document ||112.82.146.253$document ||112.82.224.139$document +||112.9.155.122$document ||112.93.29.211$document ||113.11.95.254$document ||113.118.249.97$document @@ -308,65 +299,77 @@ ||113.13.241.32$document ||113.161.58.249$document ||113.161.78.185$document +||113.194.131.72$document +||113.194.135.223$document +||113.226.42.250$document ||113.230.86.107$document ||113.231.184.245$document ||113.231.211.131$document ||113.254.169.251$document ||113.59.128.133$document +||113.59.136.39$document +||113.59.144.42$document ||113.59.149.125$document -||113.59.154.21$document -||113.59.180.40$document ||113.59.191.47$document ||113.61.204.205$document ||113.65.10.139$document -||113.88.153.5$document -||113.88.192.87$document +||113.88.123.22$document +||113.88.228.152$document ||113.89.43.165$document -||114.199.204.37$document ||114.199.253.235$document ||114.201.201.68$document ||114.224.203.128$document ||114.30.54.64$document -||114.35.254.7$document ||114.79.172.42$document ||115.165.216.112$document ||115.171.204.161$document ||115.42.47.36$document -||115.48.140.22$document -||115.49.77.222$document +||115.49.232.197$document +||115.50.172.22$document +||115.50.2.148$document ||115.51.106.238$document +||115.51.91.81$document ||115.53.203.161$document -||115.54.241.214$document +||115.54.212.175$document ||115.55.156.203$document +||115.55.7.9$document ||115.56.131.242$document ||115.56.133.96$document ||115.56.155.202$document -||115.56.178.168$document -||115.56.182.146$document -||115.56.182.151$document -||115.58.111.76$document -||115.58.132.140$document -||115.59.203.197$document ||115.59.214.205$document ||115.59.233.160$document ||115.59.252.120$document ||115.61.110.120$document +||115.61.167.21$document +||115.62.172.140$document +||115.62.26.113$document ||115.73.3.11$document ||115.75.217.79$document ||115.88.133.148$document ||115.92.174.231$document -||115.97.139.110$document +||116.108.92.154$document ||116.124.219.2$document ||116.206.164.46$document ||116.211.100.26$document +||117.194.162.12$document ||117.20.204.138$document ||117.20.204.5$document ||117.20.210.52$document +||117.20.220.126$document ||117.20.243.40$document ||117.201.205.232$document -||117.251.59.124$document +||117.202.64.149$document +||117.213.12.177$document +||117.213.47.94$document +||117.213.9.42$document +||117.215.249.250$document +||117.222.173.91$document +||117.222.175.134$document +||117.242.208.197$document +||117.247.201.45$document ||117.26.124.173$document ||117.63.113.146$document +||117.63.133.251$document ||117.63.53.15$document ||117.86.105.110$document ||118.101.7.28$document @@ -390,10 +393,9 @@ ||118.233.65.93$document ||118.42.125.246$document ||118.43.180.33$document +||118.79.113.239$document ||118.79.218.213$document ||118.79.50.203$document -||118.79.74.77$document -||118.91.41.135$document ||118.99.179.164$document ||118.99.183.235$document ||118.99.239.217$document @@ -412,6 +414,7 @@ ||119.179.43.1$document ||119.179.58.163$document ||119.18.38.144$document +||119.18.88.78$document ||119.180.106.217$document ||119.181.119.21$document ||119.182.97.232$document @@ -427,14 +430,14 @@ ||119.191.255.236$document ||119.204.30.144$document ||119.250.129.231$document -||119.251.105.221$document ||119.56.131.155$document ||119.56.143.46$document ||119.56.143.71$document ||119.56.148.115$document ||119.56.155.57$document -||119.56.166.36$document +||119.56.206.43$document ||119.96.38.150$document +||119.99.52.69$document ||12.132.113.2$document ||12.15.69.83$document ||12.178.187.6$document @@ -457,23 +460,20 @@ ||120.193.91.201$document ||120.193.91.202$document ||120.193.91.204$document -||120.193.91.208$document ||120.193.91.215$document ||120.193.91.233$document +||120.209.126.206$document ||120.209.126.235$document ||120.209.126.239$document -||120.209.126.25$document ||120.209.126.250$document ||120.209.126.60$document ||120.209.126.74$document ||120.209.99.127$document ||120.50.66.60$document ||120.50.93.115$document -||120.57.123.202$document ||120.6.8.11$document ||120.7.75.99$document ||120.83.79.42$document -||120.85.172.111$document ||121.100.114.164$document ||121.100.96.8$document ||121.121.44.222$document @@ -494,6 +494,7 @@ ||121.254.76.17$document ||121.61.96.158$document ||121.61.97.64$document +||121.8.107.214$document ||121.88.99.236$document ||122.100.150.204$document ||122.137.53.134$document @@ -505,7 +506,7 @@ ||122.232.227.128$document ||122.254.33.214$document ||123.0.240.58$document -||123.10.137.193$document +||123.10.32.252$document ||123.11.202.178$document ||123.110.124.244$document ||123.110.170.237$document @@ -513,7 +514,6 @@ ||123.110.19.248$document ||123.110.200.98$document ||123.110.238.188$document -||123.12.164.165$document ||123.129.2.28$document ||123.129.84.36$document ||123.130.208.52$document @@ -527,6 +527,7 @@ ||123.134.14.130$document ||123.135.20.164$document ||123.135.246.180$document +||123.14.95.26$document ||123.154.236.114$document ||123.159.8.100$document ||123.183.16.71$document @@ -552,11 +553,11 @@ ||123.241.148.58$document ||123.241.184.124$document ||123.28.217.23$document -||123.4.204.223$document -||123.4.251.81$document -||123.8.250.132$document -||123.9.193.253$document -||123.9.85.25$document +||123.4.242.19$document +||123.4.47.57$document +||123.5.148.182$document +||123.5.189.15$document +||123.9.36.120$document ||124.129.221.150$document ||124.129.76.230$document ||124.130.40.31$document @@ -592,24 +593,20 @@ ||125.40.1.235$document ||125.40.146.46$document ||125.40.3.71$document +||125.41.14.228$document ||125.43.82.59$document -||125.44.8.154$document ||125.45.186.88$document ||125.45.66.253$document -||125.47.244.8$document +||125.47.244.126$document ||125.47.74.230$document -||125.47.93.160$document ||126.39.155.210$document ||128.116.133.92$document -||13.114.247.134$document ||130.255.159.133$document -||134.119.186.214$document ||135.148.36.127$document ||138.99.204.224$document ||139.159.226.180$document ||139.170.173.198$document ||139.216.102.151$document -||14.102.17.222$document ||14.136.80.242$document ||14.138.8.215$document ||14.138.8.51$document @@ -623,10 +620,15 @@ ||14.50.129.248$document ||14.55.29.2$document ||140.237.12.32$document +||141.105.65.94$document ||142.11.216.5$document ||142.177.56.127$document +||143.198.120.58$document ||148.69.108.177$document ||149.255.15.134$document +||149.255.15.170$document +||149.255.15.29$document +||149.255.15.44$document ||149.255.15.99$document ||149.3.124.194$document ||14karatvisions.com$document @@ -646,9 +648,8 @@ ||162.191.165.238$document ||162.194.28.60$document ||162.209.98.174$document -||163.125.200.234$document +||162.245.221.121$document ||163.125.206.193$document -||163.53.206.228$document ||167.114.172.177$document ||170.81.238.178$document ||171.121.255.12$document @@ -686,17 +687,18 @@ ||175.201.104.192$document ||175.208.230.8$document ||175.213.25.192$document -||175.42.46.118$document ||176.111.174.35$document ||176.111.174.66$document ||176.111.174.67$document ||176.113.161.104$document ||176.113.161.121$document ||176.113.161.59$document +||176.113.161.65$document ||176.113.161.66$document ||176.113.161.71$document ||176.113.161.76$document ||176.113.161.84$document +||176.113.161.91$document ||176.113.161.95$document ||176.12.117.70$document ||176.123.7.115$document @@ -704,7 +706,6 @@ ||176.124.7.225$document ||176.221.188.251$document ||176.240.84.106$document -||177.11.92.78$document ||177.131.226.235$document ||177.54.82.154$document ||178.124.182.187$document @@ -712,7 +713,6 @@ ||178.150.174.65$document ||178.151.143.2$document ||178.165.122.141$document -||178.17.171.144$document ||178.175.0.145$document ||178.175.0.24$document ||178.175.1.179$document @@ -721,128 +721,130 @@ ||178.175.10.124$document ||178.175.10.182$document ||178.175.10.221$document +||178.175.10.247$document ||178.175.10.96$document +||178.175.100.104$document ||178.175.100.151$document +||178.175.101.212$document ||178.175.101.252$document ||178.175.102.207$document ||178.175.102.217$document ||178.175.102.25$document -||178.175.103.52$document +||178.175.103.14$document ||178.175.103.58$document ||178.175.104.112$document +||178.175.104.115$document ||178.175.105.67$document -||178.175.105.89$document ||178.175.106.160$document ||178.175.106.179$document -||178.175.106.199$document +||178.175.107.135$document ||178.175.107.142$document -||178.175.107.156$document ||178.175.107.224$document ||178.175.108.127$document ||178.175.108.173$document -||178.175.108.87$document ||178.175.109.165$document ||178.175.109.181$document +||178.175.11.100$document ||178.175.11.101$document ||178.175.11.139$document ||178.175.11.6$document ||178.175.110.191$document ||178.175.110.195$document -||178.175.111.190$document ||178.175.112.111$document ||178.175.112.183$document -||178.175.112.254$document ||178.175.112.85$document +||178.175.112.87$document ||178.175.113.174$document +||178.175.114.117$document ||178.175.114.151$document ||178.175.114.51$document ||178.175.115.106$document ||178.175.115.208$document ||178.175.116.254$document -||178.175.116.56$document -||178.175.117.110$document -||178.175.118.112$document -||178.175.118.129$document ||178.175.118.174$document ||178.175.118.41$document ||178.175.119.161$document ||178.175.119.43$document -||178.175.12.222$document ||178.175.12.68$document +||178.175.12.91$document ||178.175.120.12$document +||178.175.121.125$document +||178.175.121.130$document ||178.175.121.151$document ||178.175.121.169$document +||178.175.121.243$document +||178.175.121.77$document ||178.175.122.172$document -||178.175.122.28$document +||178.175.122.197$document ||178.175.122.47$document -||178.175.123.202$document ||178.175.123.53$document +||178.175.124.113$document ||178.175.124.38$document -||178.175.125.149$document ||178.175.125.218$document -||178.175.125.52$document ||178.175.126.129$document ||178.175.126.18$document ||178.175.126.234$document -||178.175.126.46$document +||178.175.126.43$document ||178.175.126.80$document ||178.175.127.202$document ||178.175.127.90$document -||178.175.14.222$document -||178.175.14.248$document -||178.175.14.34$document +||178.175.13.219$document ||178.175.15.19$document +||178.175.15.196$document ||178.175.15.232$document ||178.175.15.250$document ||178.175.15.72$document +||178.175.16.224$document ||178.175.16.26$document ||178.175.16.86$document -||178.175.17.13$document ||178.175.17.135$document ||178.175.17.14$document ||178.175.17.50$document -||178.175.17.54$document ||178.175.17.9$document -||178.175.19.163$document -||178.175.2.183$document +||178.175.18.177$document +||178.175.18.31$document ||178.175.2.189$document ||178.175.2.217$document +||178.175.2.23$document ||178.175.2.46$document ||178.175.2.71$document ||178.175.20.117$document ||178.175.20.126$document ||178.175.20.231$document ||178.175.21.194$document -||178.175.21.34$document +||178.175.21.53$document ||178.175.21.71$document ||178.175.22.120$document +||178.175.22.198$document ||178.175.22.206$document ||178.175.22.51$document +||178.175.22.74$document ||178.175.22.93$document ||178.175.22.94$document ||178.175.24.107$document ||178.175.24.176$document ||178.175.24.183$document -||178.175.24.232$document -||178.175.25.114$document -||178.175.25.56$document +||178.175.24.52$document +||178.175.25.162$document ||178.175.26.215$document ||178.175.27.151$document +||178.175.27.203$document ||178.175.27.32$document -||178.175.28.48$document +||178.175.27.43$document ||178.175.28.5$document ||178.175.29.135$document ||178.175.29.233$document -||178.175.29.35$document ||178.175.3.109$document ||178.175.30.187$document -||178.175.30.254$document ||178.175.30.71$document +||178.175.30.90$document ||178.175.31.128$document +||178.175.31.216$document ||178.175.31.55$document ||178.175.31.92$document ||178.175.32.34$document ||178.175.33.190$document +||178.175.33.233$document ||178.175.34.180$document ||178.175.34.222$document ||178.175.35.83$document @@ -853,18 +855,18 @@ ||178.175.36.250$document ||178.175.36.98$document ||178.175.37.10$document -||178.175.37.122$document ||178.175.37.149$document ||178.175.37.215$document ||178.175.37.234$document ||178.175.38.12$document ||178.175.38.74$document ||178.175.38.88$document -||178.175.39.157$document +||178.175.39.110$document ||178.175.39.158$document ||178.175.39.203$document ||178.175.39.210$document ||178.175.4.120$document +||178.175.4.14$document ||178.175.4.180$document ||178.175.4.225$document ||178.175.40.108$document @@ -873,87 +875,91 @@ ||178.175.41.139$document ||178.175.41.182$document ||178.175.41.217$document +||178.175.41.230$document ||178.175.41.68$document ||178.175.42.221$document ||178.175.42.28$document ||178.175.42.46$document ||178.175.43.114$document ||178.175.43.217$document -||178.175.43.238$document +||178.175.43.90$document ||178.175.44.186$document ||178.175.44.38$document ||178.175.44.56$document ||178.175.44.78$document -||178.175.45.125$document ||178.175.45.234$document +||178.175.46.110$document ||178.175.46.113$document -||178.175.46.196$document -||178.175.46.208$document ||178.175.47.11$document ||178.175.47.122$document +||178.175.47.127$document ||178.175.47.2$document ||178.175.47.222$document ||178.175.47.75$document ||178.175.47.80$document ||178.175.47.99$document +||178.175.48.164$document ||178.175.48.185$document ||178.175.48.194$document ||178.175.48.223$document +||178.175.49.104$document +||178.175.49.253$document ||178.175.49.30$document ||178.175.49.51$document ||178.175.49.54$document ||178.175.49.82$document -||178.175.5.254$document +||178.175.5.223$document ||178.175.5.44$document ||178.175.50.217$document ||178.175.50.3$document ||178.175.50.42$document ||178.175.50.54$document ||178.175.50.68$document -||178.175.51.177$document +||178.175.51.117$document ||178.175.51.2$document +||178.175.52.114$document +||178.175.52.139$document ||178.175.52.15$document ||178.175.52.176$document ||178.175.52.181$document ||178.175.52.24$document +||178.175.52.255$document ||178.175.53.214$document ||178.175.53.231$document ||178.175.53.62$document ||178.175.53.79$document +||178.175.53.87$document ||178.175.54.100$document -||178.175.54.196$document +||178.175.54.119$document +||178.175.54.78$document +||178.175.55.118$document ||178.175.55.170$document ||178.175.55.60$document ||178.175.55.99$document ||178.175.56.30$document ||178.175.56.64$document ||178.175.56.74$document -||178.175.57.112$document +||178.175.57.121$document ||178.175.57.145$document ||178.175.58.12$document -||178.175.58.235$document +||178.175.58.130$document +||178.175.58.18$document ||178.175.59.103$document -||178.175.59.106$document ||178.175.59.12$document -||178.175.59.158$document -||178.175.6.144$document -||178.175.6.180$document -||178.175.60.158$document -||178.175.60.49$document -||178.175.60.7$document -||178.175.61.250$document +||178.175.59.173$document +||178.175.59.8$document +||178.175.6.201$document +||178.175.6.203$document +||178.175.61.212$document ||178.175.61.28$document -||178.175.62.137$document +||178.175.62.130$document ||178.175.62.151$document ||178.175.62.206$document -||178.175.63.223$document ||178.175.63.53$document ||178.175.64.116$document ||178.175.65.234$document ||178.175.65.237$document -||178.175.66.140$document ||178.175.66.186$document -||178.175.66.214$document ||178.175.67.28$document ||178.175.67.65$document ||178.175.68.140$document @@ -964,9 +970,7 @@ ||178.175.68.35$document ||178.175.68.4$document ||178.175.68.5$document -||178.175.69.18$document ||178.175.7.113$document -||178.175.7.19$document ||178.175.7.198$document ||178.175.70.108$document ||178.175.70.177$document @@ -977,40 +981,37 @@ ||178.175.71.69$document ||178.175.72.208$document ||178.175.72.220$document +||178.175.72.58$document ||178.175.74.223$document ||178.175.75.94$document ||178.175.76.146$document ||178.175.76.221$document ||178.175.76.33$document +||178.175.76.34$document ||178.175.76.8$document -||178.175.77.47$document ||178.175.78.118$document -||178.175.78.125$document ||178.175.78.250$document ||178.175.79.128$document ||178.175.79.146$document ||178.175.79.198$document +||178.175.79.27$document ||178.175.8.119$document -||178.175.8.13$document -||178.175.8.130$document ||178.175.8.40$document -||178.175.81.114$document ||178.175.81.144$document ||178.175.81.189$document ||178.175.82.110$document ||178.175.82.73$document ||178.175.83.125$document +||178.175.83.17$document +||178.175.84.146$document ||178.175.84.154$document ||178.175.84.201$document ||178.175.84.237$document ||178.175.85.190$document -||178.175.86.117$document ||178.175.86.49$document -||178.175.86.59$document ||178.175.87.151$document ||178.175.87.161$document ||178.175.87.202$document -||178.175.87.207$document ||178.175.87.227$document ||178.175.88.102$document ||178.175.88.130$document @@ -1018,34 +1019,31 @@ ||178.175.88.204$document ||178.175.88.85$document ||178.175.89.152$document -||178.175.89.69$document +||178.175.89.195$document +||178.175.9.217$document ||178.175.9.223$document -||178.175.9.24$document ||178.175.90.137$document ||178.175.90.236$document ||178.175.90.3$document ||178.175.90.79$document +||178.175.91.243$document ||178.175.91.3$document ||178.175.91.97$document ||178.175.92.170$document -||178.175.93.115$document +||178.175.92.213$document ||178.175.93.120$document +||178.175.93.204$document ||178.175.93.234$document ||178.175.93.42$document -||178.175.93.98$document -||178.175.94.248$document -||178.175.94.27$document ||178.175.95.105$document ||178.175.95.54$document +||178.175.95.83$document ||178.175.96.136$document ||178.175.96.177$document -||178.175.96.198$document ||178.175.96.225$document ||178.175.97.248$document -||178.175.97.70$document ||178.175.98.63$document ||178.175.99.45$document -||178.175.99.90$document ||178.19.183.14$document ||178.205.101.33$document ||178.21.164.68$document @@ -1073,7 +1071,9 @@ ||180.177.104.65$document ||180.177.180.6$document ||180.177.242.73$document +||180.177.5.36$document ||180.218.5.171$document +||180.248.80.38$document ||180.66.111.36$document ||180.66.53.93$document ||180.94.170.166$document @@ -1090,40 +1090,45 @@ ||181.49.236.4$document ||181.49.59.162$document ||182.112.177.134$document -||182.114.88.240$document -||182.114.88.247$document -||182.115.176.253$document +||182.113.4.247$document +||182.114.194.183$document ||182.116.102.190$document -||182.116.35.52$document +||182.117.29.27$document ||182.119.200.55$document +||182.119.23.75$document +||182.119.48.230$document ||182.120.16.22$document ||182.120.192.88$document ||182.120.34.180$document -||182.121.73.158$document +||182.121.200.137$document +||182.121.205.246$document ||182.122.254.7$document +||182.126.109.194$document +||182.126.126.162$document ||182.126.87.210$document ||182.126.87.246$document -||182.127.213.136$document +||182.127.207.187$document +||182.127.80.240$document ||182.160.98.250$document ||182.233.0.252$document ||182.235.252.31$document ||182.53.197.62$document -||182.59.170.157$document ||182.88.27.89$document ||183.105.104.83$document ||183.109.169.45$document +||183.141.61.174$document ||183.17.145.112$document ||183.188.144.204$document -||183.188.146.216$document -||183.83.109.216$document +||183.49.86.54$document ||183.83.14.20$document ||183.97.40.9$document ||184.164.185.41$document ||184.175.115.10$document ||184.74.149.230$document ||185.106.209.68$document -||185.107.3.8$document ||185.117.2.107$document +||185.117.21.212$document +||185.132.53.182$document ||185.172.110.209$document ||185.172.110.235$document ||185.174.101.41$document @@ -1140,14 +1145,13 @@ ||185.245.96.94$document ||185.26.113.95$document ||185.34.16.231$document +||185.38.142.194$document ||185.55.1.182$document ||185.68.230.207$document ||185.81.154.208$document ||185.81.157.186$document ||185.82.217.185$document ||185.82.217.213$document -||185.82.219.160$document -||185.82.219.161$document ||185.82.219.219$document ||185.82.219.80$document ||186.151.144.85$document @@ -1161,7 +1165,6 @@ ||186.28.60.184$document ||186.34.4.40$document ||186.73.188.132$document -||186.73.188.134$document ||187.12.10.98$document ||187.135.141.192$document ||187.188.124.229$document @@ -1173,12 +1176,15 @@ ||188.152.41.141$document ||188.169.178.50$document ||188.169.179.127$document +||188.169.199.59$document ||188.169.30.30$document ||188.169.36.163$document +||188.169.45.140$document ||188.242.242.144$document ||188.69.251.12$document ||188.83.202.25$document -||189.201.250.184$document +||189.171.22.132$document +||189.175.214.112$document ||189.252.184.115$document ||190.0.42.106$document ||190.109.178.139$document @@ -1193,7 +1199,6 @@ ||190.122.112.42$document ||190.122.112.76$document ||190.130.20.14$document -||190.141.117.41$document ||190.147.16.184$document ||190.159.240.9$document ||190.210.214.130$document @@ -1209,19 +1214,20 @@ ||190.98.37.200$document ||190.98.41.33$document ||191.255.248.220$document -||192.153.57.94$document ||192.210.175.130$document +||192.227.185.106$document ||192.227.220.55$document ||192.227.228.67$document +||192.99.221.230$document ||192.99.240.77$document ||194.113.107.243$document ||194.147.142.230$document -||194.15.36.167$document ||194.152.35.139$document ||194.38.20.199$document ||195.139.126.51$document ||195.228.231.218$document ||195.24.94.187$document +||195.5.3.162$document ||196.202.26.182$document ||196.218.48.82$document ||196.221.148.90$document @@ -1229,15 +1235,12 @@ ||197.159.2.106$document ||197.50.27.115$document ||198.23.133.218$document -||198.23.174.104$document -||198.23.207.121$document +||198.23.213.61$document ||198.23.251.105$document -||198.46.132.132$document ||1am.co.nz$document ||2.239.22.188$document ||2.36.231.201$document ||2.37.149.230$document -||2.37.203.65$document ||2.45.111.158$document ||2.45.4.24$document ||2.55.125.182$document @@ -1248,11 +1251,11 @@ ||2.83.152.16$document ||2.indexsinas.me:811/64.exe$document ||2.indexsinas.me:811/86.exe$document +||2.indexsinas.me:811/c64.exe$document ||20.185.42.197$document ||200.105.167.98$document ||200.111.189.70$document ||200.194.4.24$document -||200.2.161.171$document ||200.29.105.207$document ||200.30.132.50$document ||201.170.46.2$document @@ -1263,14 +1266,13 @@ ||202.107.233.41$document ||202.111.131.236$document ||202.166.217.54$document -||202.182.125.175$document ||202.29.95.12$document ||202.4.124.58$document -||202.44.228.125$document ||202.51.176.114$document ||202.51.191.174$document ||202.74.236.9$document ||203.109.201.243$document +||203.130.69.205$document ||203.159.80.128$document ||203.159.80.129$document ||203.159.80.164$document @@ -1297,12 +1299,12 @@ ||210.180.237.212$document ||210.216.152.122$document ||210.216.153.142$document -||210.57.237.70$document ||210.57.245.109$document ||210.68.242.114$document ||211.187.132.204$document ||211.187.75.220$document ||211.200.160.239$document +||211.203.111.207$document ||211.204.215.157$document ||211.210.66.179$document ||211.210.93.93$document @@ -1311,7 +1313,6 @@ ||211.237.120.13$document ||211.237.246.137$document ||211.238.83.238$document -||211.247.5.96$document ||212.122.86.105$document ||212.156.215.178$document ||212.46.197.114$document @@ -1321,7 +1322,7 @@ ||213.14.173.117$document ||213.149.190.193$document ||213.163.104.160$document -||213.163.104.99$document +||213.163.104.20$document ||213.163.113.225$document ||213.163.113.51$document ||213.163.114.202$document @@ -1338,7 +1339,7 @@ ||213.163.118.227$document ||213.163.126.176$document ||213.163.126.201$document -||213.163.126.7$document +||213.163.127.204$document ||213.163.127.250$document ||213.163.127.46$document ||213.189.178.163$document @@ -1358,7 +1359,6 @@ ||218.2.40.34$document ||218.234.165.18$document ||218.238.246.3$document -||218.32.118.1$document ||218.35.207.119$document ||218.35.227.133$document ||218.35.68.35$document @@ -1368,11 +1368,12 @@ ||218.79.103.159$document ||218.93.102.63$document ||218.93.102.75$document +||219.154.113.171$document ||219.154.127.194$document -||219.154.137.93$document -||219.156.73.171$document +||219.155.226.205$document ||219.157.136.212$document -||219.157.139.165$document +||219.157.14.239$document +||219.157.178.196$document ||219.157.37.210$document ||219.241.6.180$document ||219.68.1.148$document @@ -1387,7 +1388,6 @@ ||219.85.145.194$document ||21robo.com$document ||220.126.237.74$document -||220.132.106.247$document ||220.173.160.185$document ||220.200.22.163$document ||220.81.134.72$document @@ -1395,7 +1395,9 @@ ||221.124.78.15$document ||221.13.150.74$document ||221.14.162.20$document +||221.14.47.204$document ||221.15.127.60$document +||221.15.182.72$document ||221.15.3.50$document ||221.157.191.178$document ||221.160.136.213$document @@ -1413,18 +1415,17 @@ ||221.232.183.167$document ||221.235.137.36$document ||221.3.68.16$document +||222.107.145.56$document ||222.108.17.64$document ||222.118.248.149$document ||222.119.65.145$document -||222.132.125.138$document ||222.135.9.5$document ||222.137.122.105$document ||222.137.139.86$document -||222.137.170.17$document ||222.137.72.66$document ||222.138.133.186$document -||222.138.17.203$document ||222.139.21.190$document +||222.140.163.181$document ||222.140.17.245$document ||222.187.9.178$document ||222.211.72.66$document @@ -1447,9 +1448,9 @@ ||23.24.213.121$document ||23.243.149.13$document ||23.243.21.167$document -||23.92.213.108$document ||23.94.190.101$document ||23.95.122.24$document +||23.95.122.25$document ||24.103.74.180$document ||24.11.141.134$document ||24.119.158.74$document @@ -1520,9 +1521,7 @@ ||27.213.255.202$document ||27.213.66.112$document ||27.213.84.74$document -||27.214.37.129$document ||27.215.139.242$document -||27.215.190.172$document ||27.215.212.209$document ||27.215.253.149$document ||27.215.71.243$document @@ -1534,7 +1533,6 @@ ||27.217.191.58$document ||27.218.135.3$document ||27.219.132.71$document -||27.219.151.83$document ||27.219.160.112$document ||27.219.176.72$document ||27.219.83.244$document @@ -1550,16 +1548,14 @@ ||27.35.154.13$document ||27.35.212.124$document ||27.35.58.5$document -||27.40.120.108$document -||27.40.73.175$document +||27.40.79.170$document ||27.41.36.97$document -||27.45.90.246$document -||27.5.44.190$document ||31.0.98.131$document ||31.11.51.57$document ||31.13.23.180$document ||31.168.124.130$document ||31.168.146.199$document +||31.168.16.68$document ||31.168.179.83$document ||31.168.184.59$document ||31.168.191.243$document @@ -1609,7 +1605,6 @@ ||39.113.245.254$document ||39.113.98.136$document ||39.114.137.102$document -||39.115.0.100$document ||39.117.31.162$document ||39.162.104.119$document ||39.162.98.216$document @@ -1670,27 +1665,34 @@ ||40.88.2.151$document ||41.139.209.46$document ||41.165.130.43$document -||41.190.63.174$document ||41.193.192.100$document ||41.219.185.171$document ||41.226.60.115$document +||41.72.203.82$document +||41.76.157.2$document ||41.86.18.147$document ||41.86.18.152$document -||41.86.18.204$document -||41.86.19.146$document -||41.86.19.206$document -||41.86.21.28$document -||41.86.21.60$document -||41.86.5.198$document +||41.86.21.38$document +||41.86.21.59$document +||41.86.5.103$document +||41.86.5.197$document +||41.86.5.48$document ||42.202.101.181$document ||42.202.101.199$document +||42.224.171.165$document ||42.224.176.27$document +||42.224.254.220$document +||42.224.4.110$document +||42.227.222.189$document +||42.227.225.253$document ||42.228.40.143$document -||42.228.60.114$document +||42.230.143.162$document +||42.233.97.141$document +||42.235.84.85$document ||42.236.161.72$document ||42.236.212.157$document +||42.237.114.80$document ||42.238.141.250$document -||42.56.15.227$document ||42.61.99.155$document ||42.82.217.241$document ||43.230.207.204$document @@ -1709,6 +1711,7 @@ ||45.144.225.27$document ||45.148.10.47$document ||45.148.10.94$document +||45.15.143.191$document ||45.176.108.248$document ||45.176.109.205$document ||45.176.110.146$document @@ -1717,6 +1720,7 @@ ||45.229.53.148$document ||45.27.253.137$document ||45.51.104.59$document +||45.77.9.151$document ||45.85.90.131$document ||45.9.148.37$document ||45.92.108.35$document @@ -1737,8 +1741,8 @@ ||46.42.118.86$document ||46.42.86.128$document ||46.97.76.242$document +||47.136.96.53$document ||47.145.152.26$document -||47.151.23.172$document ||47.157.97.71$document ||47.16.131.51$document ||47.21.202.98$document @@ -1758,6 +1762,7 @@ ||5.14.122.233$document ||5.188.62.111$document ||5.95.226.154$document +||50.115.174.103$document ||50.115.174.106$document ||50.121.91.255$document ||50.247.83.66$document @@ -1782,32 +1787,39 @@ ||58.240.147.97$document ||58.241.78.55$document ||58.242.91.219$document -||58.249.73.208$document +||58.249.22.24$document ||58.249.75.128$document +||58.249.75.146$document +||58.249.77.141$document ||58.249.80.36$document -||58.252.176.140$document ||58.253.15.184$document ||58.51.219.200$document ||58.72.165.153$document ||58.72.165.39$document ||59.0.211.161$document ||59.102.168.189$document -||59.126.26.220$document ||59.151.202.3$document ||59.151.214.4$document -||59.151.237.51$document -||59.151.246.125$document ||59.173.135.51$document ||59.175.63.177$document ||59.23.114.97$document ||59.26.181.228$document ||59.30.12.254$document -||59.60.117.163$document +||59.50.23.23$document +||59.89.242.116$document +||59.92.217.215$document +||59.92.218.82$document +||59.93.21.140$document +||59.93.21.172$document +||59.94.182.212$document +||59.95.175.49$document +||59.97.170.146$document ||60.13.61.12$document ||60.209.122.57$document ||60.209.216.23$document ||60.209.233.94$document ||60.211.6.112$document +||60.211.80.216$document ||60.212.100.83$document ||60.212.111.39$document ||60.212.206.246$document @@ -1815,31 +1827,30 @@ ||60.212.220.167$document ||60.212.254.178$document ||60.213.83.55$document +||60.214.53.159$document ||60.214.85.149$document ||60.217.177.196$document ||60.217.86.208$document -||60.220.159.240$document -||60.253.15.104$document -||60.253.39.88$document ||60.253.4.72$document ||60.253.51.127$document ||60.253.60.174$document ||60.253.8.81$document -||60.254.36.135$document ||60.7.10.121$document ||60.7.8.43$document ||61.146.108.150$document +||61.163.131.67$document ||61.179.91.194$document ||61.247.224.66$document +||61.3.150.101$document ||61.52.101.143$document +||61.52.186.186$document ||61.52.241.252$document ||61.52.57.40$document ||61.52.9.166$document +||61.52.97.68$document ||61.52.98.43$document ||61.52.99.161$document ||61.53.117.152$document -||61.53.249.58$document -||61.53.74.236$document ||61.54.103.56$document ||61.56.180.67$document ||61.56.181.7$document @@ -1871,7 +1882,6 @@ ||66.108.199.144$document ||66.57.55.210$document ||66.74.7.197$document -||66.91.21.31$document ||66.97.181.196$document ||67.245.151.203$document ||67.8.138.101$document @@ -1933,6 +1943,7 @@ ||74.64.139.223$document ||74.75.165.81$document ||75.127.141.52$document +||75.83.102.27$document ||75.99.213.61$document ||76.170.11.82$document ||76.178.22.145$document @@ -1942,14 +1953,12 @@ ||76.84.134.33$document ||76.89.107.69$document ||76.95.12.137$document -||77.111.182.31$document ||77.237.25.210$document ||77.71.50.153$document ||77.89.203.238$document ||77st.net$document ||78.138.98.134$document ||78.145.224.45$document -||78.187.141.144$document ||78.187.41.200$document ||78.188.106.235$document ||78.188.168.64$document @@ -1970,7 +1979,6 @@ ||80.107.89.207$document ||80.19.101.218$document ||80.211.181.77$document -||80.217.12.7$document ||80.99.128.61$document ||81.136.146.213$document ||81.165.44.109$document @@ -1987,7 +1995,6 @@ ||81.92.36.96$document ||82.103.108.72$document ||82.135.196.130$document -||82.166.212.178$document ||82.166.85.112$document ||82.207.61.194$document ||82.209.250.155$document @@ -2038,14 +2045,17 @@ ||85.105.208.25$document ||85.105.224.141$document ||85.105.241.2$document -||85.108.133.19$document ||85.214.149.236$document ||85.241.39.182$document +||85.250.147.134$document ||85.64.181.50$document ||85.74.215.180$document ||85.97.130.227$document ||86.35.43.220$document +||86.98.23.78$document +||87.117.11.46$document ||87.172.19.130$document +||87.251.71.78$document ||87du.vip$document ||88.119.171.253$document ||88.129.208.43$document @@ -2072,7 +2082,6 @@ ||8poieq.bn.files.1drv.com$document ||90.152.144.139$document ||91.132.197.39$document -||91.138.215.5$document ||91.177.139.132$document ||91.187.103.32$document ||91.212.150.241$document @@ -2087,6 +2096,7 @@ ||92.54.237.237$document ||92.83.62.139$document ||92.85.18.138$document +||93.157.63.221$document ||93.159.169.190$document ||93.173.235.110$document ||93.21.224.154$document @@ -2100,13 +2110,13 @@ ||94.136.69.199$document ||94.143.53.34$document ||94.154.17.170$document +||94.154.82.190$document ||94.200.16.22$document ||94.224.83.208$document ||94.53.120.109$document ||94.85.0.3$document ||95.132.129.250$document ||95.133.158.20$document -||95.154.20.231$document ||95.158.19.130$document ||95.170.113.227$document ||95.170.201.34$document @@ -2142,7 +2152,6 @@ ||adithimedia.com$document ||adithimedia.memengers.com$document ||admin.erapor.smk-alasror.net$document -||admin.gentbcn.org$document ||admin.grandoceanvilla.com$document ||admission.kmctartskuttippuram.org$document ||adventureexplorer.in$document @@ -2158,6 +2167,7 @@ ||aiqtest.com$document ||ajpharmaholding.com$document ||akdvidyalaya.com$document +||al-wahd.com$document ||alasdemariposas.org$document ||alberts.diamondrelationscrm.us$document ||alemelektronik.com$document @@ -2198,7 +2208,6 @@ ||artedibujoyarquitectura.com$document ||arwenyapi.com$document ||ask-regard.call-save.biz$document -||asucssa.live$document ||atfile.com$document ||athenacapsg.com$document ||atlasconcreteworks.com$document @@ -2210,15 +2219,17 @@ ||automaticrefreshments.com$document ||avadhanagames.com$document ||aventuramotorhome.com$document +||awumad01.top$document +||awuqze02.top$document ||ayahuascasp.com.br$document ||ayamallah.com$document -||aycconsultoriaempresarial.com$document ||azmeasurement.com$document ||azraktours.com$document ||b.r.uce.lee.b.es.t@zytrox.tk$document ||b2b.toptanakaryakit.com.tr$document ||backgrounds.pk$document ||badeggdesign.com$document +||bakamla.go.id$document ||balealgodon.mx$document ||bangkok-orchids.com$document ||bangladeshunbound.com$document @@ -2239,7 +2250,6 @@ ||bespokeweddings.ie$document ||bestcarenepal.com$document ||betone.co.kr$document -||betycopaints.com$document ||beveragesmiami.solucioneslink.com$document ||bhavaniengineering.com$document ||bigmikesupplies.co.za$document @@ -2252,6 +2262,7 @@ ||birdi.elin.co.za$document ||birminghamlink.org$document ||bitbucket.org/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe$document +||bitbucket.org/clubhousedev/clubhouse/downloads/clubhousepc.exe$document ||bitbucket.org/dvdfv/anjj/downloads/jami.exe$document ||bitbucket.org/heyhoeee/heyhoename1/downloads/1234.exe$document ||bitbucket.org/jpavelski/chpock/downloads/4.exe$document @@ -2299,7 +2310,6 @@ ||bitbucket.org/tanake5518/fi/downloads/clientrevers.txt$document ||bitbucket.org/tanake5518/fi/downloads/dcrat.exe$document ||bitbucket.org/tanake5518/fi/downloads/dllservices.exe$document -||bitbucket.org/tanake5518/fi/downloads/dllservices2.exe$document ||bitbucket.org/tanake5518/fi/downloads/exe_morris.mcdermott.exe$document ||bitbucket.org/tanake5518/fi/downloads/hans.txt$document ||bitbucket.org/tanake5518/fi/downloads/hulu.txt$document @@ -2382,23 +2392,23 @@ ||capitalgroup-kw.com$document ||capoeiraventrelivre.com$document ||cashyinvestment.org$document +||casiomaneflirt.cf$document ||catchpoolshetlands.co.uk$document ||cazyacustomfurniture.com$document ||cbn.hypervoizd.com$document ||ccauthority.net$document ||cd.textfiles.com/hmatrix/data/hack1226.exe$document ||cdaonline.com.ar$document -||cdn-10049480.file.myqcloud.com$document -||cdn.discordapp.com/attachments/712408764354920490/829413679866839120/echelon_protected.exe$document ||cdn.discordapp.com/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq$document +||cdn.discordapp.com/attachments/775238059083038744/829993648186851338/pslmlyfnpzgsgitrwwvalcfunumfmac$document ||cdn.discordapp.com/attachments/816070119281131570/816070273254162442/all.txt$document ||cdn.discordapp.com/attachments/825372018244583454/826848185246023750/loaddd.exe$document ||cdn.discordapp.com/attachments/825372018244583454/826848348342059008/zeppelin.exe$document ||cdn.discordapp.com/attachments/825372018244583454/826848405258633277/build.exe$document +||cdn.discordapp.com/attachments/825372018244583454/830455061724528690/v1.exe$document ||cdn.discordapp.com/attachments/826198252025675816/826537386485612574/china.png$document ||cdn.discordapp.com/attachments/826376903400751108/826431600383361065/remcmcmcm_mjvbsmlrc45.bin$document ||cdn.discordapp.com/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe$document -||cdn.discordapp.com/attachments/829721030112182363/829724335526510622/dcratbuild.exe$document ||cec.asso.ac-amiens.fr$document ||cellas.sk$document ||cendekiabinaaksara.com$document @@ -2413,9 +2423,9 @@ ||chiptune.com/razor/rzr-winner_intro.zip$document ||cible-energy.com$document ||cifeer.net$document +||citiconstructioncorp.com$document ||citihits.lk$document ||citssolutions.co.za$document -||citycapproperty.ru$document ||cityglobalgospel.com$document ||civi.istmejia.com$document ||cleanbydesignllc.com$document @@ -2426,8 +2436,8 @@ ||codeload.github.com/meteoradminz/hidden-tear/zip/master$document ||codsambal.com$document ||colfincas.com/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/$document -||colinde.pricesne.com$document ||colorpak.pl$document +||columbia.aula-web.net$document ||community.reimclub.com$document ||competancy.indigoconsult.net$document ||conceptimagine.ro$document @@ -2437,9 +2447,11 @@ ||consulateins.solucioneslink.com$document ||contributeindustry.com$document ||copelandscapes.com$document +||corwin-tommie06f.ru.com$document ||coulsongraphics.com$document ||count.mail.163.com.impactmedfoundation.com$document ||covid19.cyberschool.or.id$document +||covid19vaccinations.hopto.org$document ||cr-sq.com$document ||craftech.nxtnet.ga$document ||crearechile.cl$document @@ -2502,6 +2514,7 @@ ||dl.198424.com$document ||dl.installcdn-aws.com$document ||dl.packetstormsecurity.net$document +||dl.pandasecur.com$document ||dl.rina-roleplay.com$document ||dnn.alibuf.com$document ||dns.alibuf.com$document @@ -2549,6 +2562,7 @@ ||drive.google.com/uc?export=download&id=1byj1kld84im01lyhb239rds4kvoyaxkv$document ||drive.google.com/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben$document ||drive.google.com/uc?export=download&id=1d0ij6qkgrf6irywv6ftk1m7p5l3weh3a$document +||drive.google.com/uc?export=download&id=1dzx_cflers_zntlrip3fhbxb5who03u0$document ||drive.google.com/uc?export=download&id=1gprlk2mcrl6law-zk5r0pjogaqrxwepd$document ||drive.google.com/uc?export=download&id=1ieolbiw9ao8m8umyi7owwqlt-_-7byei$document ||drive.google.com/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr$document @@ -2575,6 +2589,7 @@ ||drive.google.com/uc?export=download&id=1voqnsh0cmxl5hty4zpc18pgnkud5rtvy$document ||drive.google.com/uc?export=download&id=1vy1nx5zefluh5ewihr-6pcndlyex7xcm$document ||drive.google.com/uc?export=download&id=1wpqa2nnnktbhzs4j0r-erosvgyaagi_a$document +||drive.google.com/uc?export=download&id=1xbp7hvw2ybwjrftbvdkjvwzrfuk4ope9$document ||drive.google.com/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e$document ||drive.google.com/uc?export=download&id=1xqmjyd-syoy31suhjuqzlg4rblxq9ohi$document ||drive.google.com/uc?export=download&id=1xt-g7waixr7glvz_rdxglblidv6qgu58$document @@ -2611,11 +2626,11 @@ ||ennovate.elin.co.za$document ||equimination.ee$document ||erp.nanotechproautocare.com$document +||esaja09.top$document ||escola.probommar.org.br$document ||eservices.immigration.gov.lk$document ||esnconsultants.com$document ||essentia.org.br$document -||ethereality.info$document ||eubanks7.com$document ||europeanzonexxi.com$document ||evertkok.nl/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe$document @@ -2645,7 +2660,7 @@ ||fisconline.bar$document ||fisconline.casa$document ||fix-america-now.org$document -||fixauto.illumetechnology.com$document +||fkd.derpcity.ru$document ||flexypay.dsquaregroup.com$document ||flintspin.com$document ||flyingbuddhadesign.com$document @@ -2666,7 +2681,6 @@ ||futbolpr.com$document ||futuregraphics.com.ar$document ||g.pinmonkey.xyz$document -||gaditastour.com$document ||gametwogame.com$document ||garciadogshow.com$document ||garenanow.myvnc.com$document @@ -2697,7 +2711,6 @@ ||goldmen.in$document ||gpotecnosystems.com$document ||gracejukes.com$document -||greataccesstoserver.com$document ||grupoinmare.com$document ||gruposelt.000webhostapp.com$document ||gs.monerorx.com$document @@ -2728,19 +2741,15 @@ ||hmpmall.co.kr$document ||hoagietesting10.com$document ||hoayeuthuong-my.sharepoint.com$document -||holmesservices.mobiledevsite.co$document ||homefindersolutions.com$document ||hometownchick.com$document -||hongluosi.com$document ||hookedupboatclub.com$document ||hostingparacolombia.com$document ||hostzaa.com$document -||houstonshutters.site$document ||hqdecig.com/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/$document ||hr2019.vrcom7.com$document ||hsecaravans.co.uk/wp-admin/suy/$document ||hseda.com$document -||hsmwebapp.com$document ||htownbars.com$document ||hubtech.co.za$document ||huellacero.cl$document @@ -2766,6 +2775,7 @@ ||incrediblepixels.com$document ||incredicole.com$document ||indonesias.me:9998/64.exe$document +||indonesias.me:9998/c64.exe$document ||indrasbikaner.com$document ||infair.vn$document ||infovator.com$document @@ -2791,6 +2801,8 @@ ||it123.ru$document ||italiandirezione.casa$document ||itc-demo.softgig.co.ke$document +||itsrlytry.000webhostapp.com$document +||jaishomo.info$document ||jamiekaylive.com$document ||jamshed.pk$document ||jansen-heesch.nl$document @@ -2823,12 +2835,11 @@ ||karer.by$document ||karmakoincodes.weebly.com/uploads/3/2/8/8/3288864/karma_koin_codes.exe$document ||katanvetov.co.il$document -||kautilyaclasses.com/ds/index.html$document +||katelynn9506a.ru.com$document ||kensingtondriving.com$document ||ketofitnessexpert.com$document ||kevinjewelry.com.co$document ||keywatch.yourpageserver.com$document -||kihn-delaney30gn.ru.com$document ||kingssa.co.za$document ||kjcpromo.com$document ||kleinendeli.co.za$document @@ -2839,7 +2850,6 @@ ||ktb.sch.id$document ||kuaizip.com/down/affiliate/kuaizip_setup_10029.exe$document ||kubatoglubaklava.com.tr$document -||kullumanalitours.com$document ||kumaralok.in$document ||kwanfromhongkong.com$document ||kz.sldov.ru$document @@ -2899,7 +2909,6 @@ ||maksi.feb.unib.ac.id$document ||malaya.tv$document ||malwarecoding.github.io$document -||managed.oss-cn-beijing.aliyuncs.com$document ||managemysalon.in$document ||manantialesdelnorte.uy$document ||manhtien.net$document @@ -2942,6 +2951,7 @@ ||microblading.mirliandias.com.br$document ||microcomm-group.com$document ||mikhailmotoringschool.com$document +||mills-skyla30ec.com$document ||mingguanwms.com$document ||minpic.de/k/big5/1giof6/$document ||minuevavida.org$document @@ -2960,6 +2970,7 @@ ||moreirawag.ac.ug$document ||morrobaydrugandgift.com/wp-contentbak/t9m/$document ||motorcomunicacion.com$document +||moumitas.com$document ||msacontabil.com.br$document ||mumgee.co.za$document ||muzimbiti.xigubo.co.mz$document @@ -3015,6 +3026,7 @@ ||nyeh2o.com.au$document ||obseques-conseils.com$document ||oecteam.com$document +||ohe.ie$document ||ohsewgorgeous.co.uk$document ||oldschoolvalue.s3.amazonaws.com/spreadsheets/osv_stock_valuation-sample-dummy.exe$document ||oleholeh.memangbeda.website$document @@ -3038,6 +3050,7 @@ ||onedrive.live.com/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135$document ||onedrive.live.com/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732$document ||onedrive.live.com/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4$document +||onedrive.live.com/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc$document ||onedrive.live.com/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc$document ||onedrive.live.com/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0$document ||onedrive.live.com/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu$document @@ -3068,6 +3081,7 @@ ||onedrive.live.com/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw$document ||onedrive.live.com/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0$document ||onedrive.live.com/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a$document +||onedrive.live.com/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4$document ||onedrive.live.com/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo$document ||onedrive.live.com/download?cid=15d9646f4dbf9553&resid=15d9646f4dbf9553%21110&authkey=ag0eg1lha_lwgi0$document ||onedrive.live.com/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte$document @@ -3259,12 +3273,14 @@ ||onedrive.live.com/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8$document ||onedrive.live.com/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq$document ||onedrive.live.com/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug$document +||onedrive.live.com/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua$document ||onedrive.live.com/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe$document ||onedrive.live.com/download?cid=607978009e823f21&resid=607978009e823f21!446&authkey=aofddjtovqbb_3i$document ||onedrive.live.com/download?cid=618391b69828cf46&resid=618391b69828cf46%21212&authkey=akmdmweqgestysa$document ||onedrive.live.com/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe$document ||onedrive.live.com/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786!198&authkey=akq4jrbjm6spd9m$document ||onedrive.live.com/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21196&authkey=ape1id1rxx25uhi$document +||onedrive.live.com/download?cid=6573f5e9eaa02786&resid=6573f5e9eaa02786%21198&authkey=akq4jrbjm6spd9m$document ||onedrive.live.com/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi$document ||onedrive.live.com/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e$document ||onedrive.live.com/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90$document @@ -3558,7 +3574,6 @@ ||onedrive.live.com/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm$document ||onedrive.live.com/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta$document ||online.creedglobal.in$document -||open.rawntech.com$document ||open.warehousesaas.co.uk$document ||opolis.io$document ||optimus.com.sg$document @@ -3639,6 +3654,7 @@ ||pujashoppe.in$document ||punchdialogues.com$document ||punjabdevelopersassociation.com.pk$document +||pvcprinting.co.uk$document ||qadir.tickfa.ir$document ||qatarglobalconsulting.com$document ||qjbutterflyevents.co.za/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/$document @@ -3677,9 +3693,9 @@ ||readymmade.com$document ||recyclethesurplus.com$document ||redbats.co.in$document +||redboxmultimedia.com$document ||redchillicrackers.com$document ||reifenquick.de$document -||relaxindulge.co.nz$document ||renehavis.com.ua$document ||repatriacioncolombia.com$document ||res.uf1.cn$document @@ -3687,7 +3703,6 @@ ||reseller.digimitra.in$document ||reseller.itechbrasil.com$document ||resuco.net$document -||revolet-sa.com$document ||rezkabum.ru$document ||rhema.com.sg$document ||richmondminerals.co.zm$document @@ -3702,6 +3717,7 @@ ||ronnietucker.co.uk$document ||roomsvc.servegate.kr$document ||roshnijewellery.com$document +||rotronics.com.ph$document ||rsgym.net$document ||rubazar.pro$document ||rubycityvietnam.com$document @@ -3731,6 +3747,7 @@ ||schoolbustracker.softgig.co.ke$document ||sculetus.nl$document ||secure-doc-reader.com$document +||secure.activedirect.xyz$document ||segalsmetals.elin.co.za$document ||sellmyphonela.com$document ||selltechtoday.com$document @@ -3741,7 +3758,9 @@ ||sericaasia.com$document ||servicemhkd.myvnc.com$document ||servicemhkd80.myvnc.com$document +||serviciovirtual.com.ar$document ||sexologistpakistan.net$document +||sgb.ac.ke$document ||sgessy.com.br$document ||shaheentbfoundation.com$document ||shahikhana.cstdevs.com$document @@ -3781,7 +3800,6 @@ ||sobethuacademy.com$document ||soft.110route.com$document ||soft.officelabo.net$document -||sogecoenergy.com$document ||sohs.conceptechs.info$document ||solar.amazingtribe.lk$document ||somcorbera.cat$document @@ -3795,7 +3813,6 @@ ||spetsesyachtcharter.gr$document ||spititourism.com$document ||spittinfire.com$document -||springbedspetroleum.com$document ||src1.minibai.com$document ||sreenivasapaintingworks.com$document ||sriglobalit.com$document @@ -3806,6 +3823,11 @@ ||staging.apparelpunch.com$document ||starcountry.net$document ||static.3001.net$document +||stdynbnbnewagedevixz.dns.army$document +||stdynmxwllminoragest.dns.army$document +||stdyunitedkesokokgst.dns.army$document +||stdyworkfinetraingst.dns.army$document +||stdyzgchgcloudgostxs.dns.army$document ||stiau.iuc.ac$document ||sticker.jewsjuice.com$document ||stiepancasetia.ac.id$document @@ -3822,10 +3844,12 @@ ||storage.googleapis.com/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt$document ||store.ericalgarin.com$document ||stott-thompson.co.uk$document +||stratexec.co.za$document ||streetdemo.yourpageserver.com$document ||suboldesign.com$document ||sumerians.org$document ||sunaryem.com.tr$document +||sunbrero.com.au$document ||sunmarkholidays.com$document ||support-4-free.com$document ||support.clz.kr$document @@ -3905,7 +3929,6 @@ ||toplevel.com.br$document ||topmask.co.za$document ||torresquinterocorp.com$document -||towme.services$document ||toyotacollege.ac.th$document ||tpke.hu$document ||translaterjemah.com$document @@ -3932,7 +3955,6 @@ ||unyazitelecom.com$document ||up.llw0.com$document ||upcbpta.com$document -||used-jeans.fr$document ||useformoney.000webhostapp.com$document ||users.skynet.be/crisanar/defis/jek_crackme1.7.zip$document ||uss.ac.th$document @@ -3942,7 +3964,6 @@ ||vcah.co.uk$document ||vectarts.com$document ||vegadelcasero.cl$document -||velma-harber30ku.com$document ||vendas.lidiacarmeli.com.br$document ||veterinariadrpopui.com$document ||vfocus.net$document @@ -3960,7 +3981,7 @@ ||vniel.co.kr/gnuboard/data/scan/amowvegfrt9ja/$document ||vniel.co.kr/gnuboard/data/scan/fu6jvxzzs46uqlp7l/$document ||vocalterra.com$document -||vokasi.ub.ac.id$document +||vokasi.ub.ac.id/wuk/kuqyslbgavnwlmcuk0qalhxifzp4mgze8anlcewu1pa8fw4lfex0y/$document ||vologroup.com.br$document ||voteyouramerica.dekitout.com$document ||vpts.co.za$document @@ -3988,6 +4009,7 @@ ||weinsteincounseling.com$document ||wfinance.com.br$document ||whcms.yourpageserver.com$document +||whiteglovetailgate.com$document ||whiteresponse.com$document ||wi522012.ferozo.com$document ||wikalen.co.za$document @@ -4018,7 +4040,7 @@ ||yeq.i.u.j.ia.n.3@zytrox.tk$document ||ylfpremium.com$document ||yoast.yourpageserver.com$document -||yp.hnggzyjy.cn/common/yz.vbs$document +||yp.hnggzyjy.cn$document ||yummyyogaudaipur.com$document ||yzkzixun.com$document ||ziyker4gaming@zytrox.tk$document diff --git a/urlhaus-filter-vivaldi.txt b/urlhaus-filter-vivaldi.txt index 3320093a..c575ce17 100644 --- a/urlhaus-filter-vivaldi.txt +++ b/urlhaus-filter-vivaldi.txt @@ -1,5 +1,5 @@ ! Title: Malicious URL Blocklist (Vivaldi) -! Updated: Mon, 12 Apr 2021 00:12:54 UTC +! Updated: Mon, 12 Apr 2021 12:13:00 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -1391,6 +1391,7 @@ ||101.0.34.225$document ||101.0.34.229$document ||101.0.34.230$document +||101.0.34.236$document ||101.0.34.244$document ||101.0.34.247$document ||101.0.34.253$document @@ -1657,6 +1658,7 @@ ||101.108.131.81$document ||101.108.131.89$document ||101.108.131.92$document +||101.108.131.99$document ||101.108.132.0$document ||101.108.132.109$document ||101.108.132.110$document @@ -1808,6 +1810,7 @@ ||101.108.137.77$document ||101.108.138.108$document ||101.108.138.109$document +||101.108.138.150$document ||101.108.138.155$document ||101.108.138.160$document ||101.108.138.174$document @@ -6073,6 +6076,7 @@ ||103.91.245.45$document ||103.91.245.46$document ||103.91.245.47$document +||103.91.245.48$document ||103.91.245.49$document ||103.91.245.5$document ||103.91.245.54$document @@ -8785,6 +8789,7 @@ ||107.172.153.90$document ||107.172.156.122$document ||107.172.156.153$document +||107.172.156.3$document ||107.172.157.125$document ||107.172.157.131$document ||107.172.157.176$document @@ -12196,6 +12201,7 @@ ||111.92.81.107$document ||111.92.81.109$document ||111.92.81.111$document +||111.92.81.112$document ||111.92.81.113$document ||111.92.81.116$document ||111.92.81.118$document @@ -17652,6 +17658,7 @@ ||112.248.108.109$document ||112.248.108.18$document ||112.248.108.182$document +||112.248.109.156$document ||112.248.109.95$document ||112.248.11.123$document ||112.248.110.120$document @@ -20362,6 +20369,7 @@ ||112.9.149.240$document ||112.9.153.32$document ||112.9.154.61$document +||112.9.155.122$document ||112.9.157.102$document ||112.9.158.247$document ||112.9.160.95$document @@ -23895,6 +23903,7 @@ ||113.194.131.162$document ||113.194.131.197$document ||113.194.131.210$document +||113.194.131.72$document ||113.194.132.207$document ||113.194.132.253$document ||113.194.132.44$document @@ -23909,6 +23918,7 @@ ||113.194.133.9$document ||113.194.134.64$document ||113.194.135.154$document +||113.194.135.223$document ||113.194.135.230$document ||113.194.135.238$document ||113.194.135.63$document @@ -26566,6 +26576,7 @@ ||113.88.122.63$document ||113.88.122.78$document ||113.88.123.145$document +||113.88.123.22$document ||113.88.123.235$document ||113.88.124.109$document ||113.88.124.119$document @@ -26937,6 +26948,7 @@ ||113.88.211.95$document ||113.88.224.159$document ||113.88.228.13$document +||113.88.228.152$document ||113.88.228.16$document ||113.88.228.211$document ||113.88.228.73$document @@ -27191,6 +27203,7 @@ ||113.88.65.37$document ||113.88.65.38$document ||113.88.65.48$document +||113.88.65.49$document ||113.88.65.54$document ||113.88.65.80$document ||113.88.66.213$document @@ -27397,6 +27410,7 @@ ||113.89.247.90$document ||113.89.248.112$document ||113.89.248.181$document +||113.89.4.189$document ||113.89.4.201$document ||113.89.4.7$document ||113.89.4.74$document @@ -27664,6 +27678,7 @@ ||113.9.241.101$document ||113.9.29.128$document ||113.9.94.126$document +||113.90.133.38$document ||113.90.135.225$document ||113.90.135.231$document ||113.90.160.138$document @@ -28335,6 +28350,7 @@ ||114.223.238.75$document ||114.223.244.108$document ||114.223.28.254$document +||114.223.43.7$document ||114.223.48.158$document ||114.223.61.204$document ||114.223.63.197$document @@ -29093,6 +29109,7 @@ ||114.235.211.48$document ||114.235.211.60$document ||114.235.211.88$document +||114.235.213.31$document ||114.235.22.32$document ||114.235.222.230$document ||114.235.222.24$document @@ -30062,6 +30079,7 @@ ||114.97.224.73$document ||114.97.225.120$document ||114tv.cc$document +||115.110.193.166$document ||115.120.136.248$document ||115.120.204.211$document ||115.127.96.194$document @@ -34706,6 +34724,7 @@ ||115.49.232.129$document ||115.49.232.177$document ||115.49.232.185$document +||115.49.232.197$document ||115.49.232.20$document ||115.49.232.204$document ||115.49.232.210$document @@ -37076,6 +37095,7 @@ ||115.50.172.21$document ||115.50.172.212$document ||115.50.172.216$document +||115.50.172.22$document ||115.50.172.223$document ||115.50.172.225$document ||115.50.172.236$document @@ -37430,6 +37450,7 @@ ||115.50.2.128$document ||115.50.2.132$document ||115.50.2.141$document +||115.50.2.148$document ||115.50.2.149$document ||115.50.2.159$document ||115.50.2.179$document @@ -42352,6 +42373,7 @@ ||115.51.91.62$document ||115.51.91.66$document ||115.51.91.70$document +||115.51.91.81$document ||115.51.91.98$document ||115.51.92.1$document ||115.51.92.114$document @@ -45316,6 +45338,7 @@ ||115.54.212.163$document ||115.54.212.17$document ||115.54.212.173$document +||115.54.212.175$document ||115.54.212.180$document ||115.54.212.183$document ||115.54.212.185$document @@ -49425,6 +49448,7 @@ ||115.55.7.241$document ||115.55.7.55$document ||115.55.7.60$document +||115.55.7.9$document ||115.55.7.92$document ||115.55.70.113$document ||115.55.71.231$document @@ -57124,6 +57148,7 @@ ||115.59.248.228$document ||115.59.25.113$document ||115.59.25.169$document +||115.59.250.37$document ||115.59.250.52$document ||115.59.252.114$document ||115.59.252.12$document @@ -59307,6 +59332,7 @@ ||115.61.167.185$document ||115.61.167.196$document ||115.61.167.207$document +||115.61.167.21$document ||115.61.167.225$document ||115.61.167.227$document ||115.61.167.230$document @@ -59815,6 +59841,7 @@ ||115.61.186.106$document ||115.61.186.11$document ||115.61.186.114$document +||115.61.186.139$document ||115.61.186.144$document ||115.61.186.153$document ||115.61.186.158$document @@ -60696,6 +60723,7 @@ ||115.62.171.71$document ||115.62.171.81$document ||115.62.172.135$document +||115.62.172.140$document ||115.62.172.145$document ||115.62.172.173$document ||115.62.172.200$document @@ -60754,6 +60782,7 @@ ||115.62.25.100$document ||115.62.26.100$document ||115.62.26.102$document +||115.62.26.113$document ||115.62.26.114$document ||115.62.26.120$document ||115.62.26.123$document @@ -66693,6 +66722,7 @@ ||115.96.199.129$document ||115.96.199.132$document ||115.96.199.138$document +||115.96.199.146$document ||115.96.199.160$document ||115.96.199.163$document ||115.96.199.165$document @@ -91492,6 +91522,7 @@ ||116.106.77.111$document ||116.108.32.244$document ||116.108.71.196$document +||116.108.92.154$document ||116.109.108.32$document ||116.109.132.2$document ||116.109.156.14$document @@ -93313,6 +93344,7 @@ ||116.68.96.98$document ||116.68.96.99$document ||116.68.97.1$document +||116.68.97.100$document ||116.68.97.102$document ||116.68.97.104$document ||116.68.97.117$document @@ -93431,6 +93463,7 @@ ||116.68.99.129$document ||116.68.99.132$document ||116.68.99.139$document +||116.68.99.152$document ||116.68.99.155$document ||116.68.99.158$document ||116.68.99.159$document @@ -114169,6 +114202,7 @@ ||117.194.162.117$document ||117.194.162.118$document ||117.194.162.119$document +||117.194.162.12$document ||117.194.162.120$document ||117.194.162.121$document ||117.194.162.122$document @@ -116158,6 +116192,7 @@ ||117.201.197.124$document ||117.201.199.181$document ||117.201.199.230$document +||117.201.200.106$document ||117.201.200.236$document ||117.201.201.33$document ||117.201.202.154$document @@ -119706,6 +119741,7 @@ ||117.213.12.130$document ||117.213.12.148$document ||117.213.12.158$document +||117.213.12.177$document ||117.213.12.208$document ||117.213.12.218$document ||117.213.12.219$document @@ -121203,6 +121239,7 @@ ||117.213.9.1$document ||117.213.9.177$document ||117.213.9.203$document +||117.213.9.42$document ||117.213.9.58$document ||117.213.9.71$document ||117.213.9.77$document @@ -121559,6 +121596,7 @@ ||117.215.249.174$document ||117.215.249.175$document ||117.215.249.181$document +||117.215.249.196$document ||117.215.249.197$document ||117.215.249.199$document ||117.215.249.20$document @@ -121571,6 +121609,7 @@ ||117.215.249.241$document ||117.215.249.242$document ||117.215.249.245$document +||117.215.249.250$document ||117.215.249.251$document ||117.215.249.255$document ||117.215.249.27$document @@ -124073,6 +124112,7 @@ ||117.222.175.122$document ||117.222.175.13$document ||117.222.175.130$document +||117.222.175.134$document ||117.222.175.135$document ||117.222.175.136$document ||117.222.175.138$document @@ -126040,6 +126080,7 @@ ||117.247.201.42$document ||117.247.201.43$document ||117.247.201.44$document +||117.247.201.45$document ||117.247.201.47$document ||117.247.201.49$document ||117.247.201.56$document @@ -128764,6 +128805,7 @@ ||117.63.124.134$document ||117.63.127.23$document ||117.63.130.19$document +||117.63.133.251$document ||117.63.151.77$document ||117.63.156.234$document ||117.63.157.34$document @@ -130764,6 +130806,7 @@ ||118.79.112.110$document ||118.79.112.230$document ||118.79.112.54$document +||118.79.113.239$document ||118.79.113.7$document ||118.79.114.198$document ||118.79.114.78$document @@ -137073,6 +137116,7 @@ ||119.99.251.129$document ||119.99.30.19$document ||119.99.50.91$document +||119.99.52.69$document ||119.99.63.42$document ||11bybbsny.com$document ||11degrees.org$document @@ -145678,6 +145722,7 @@ ||123.10.32.196$document ||123.10.32.200$document ||123.10.32.239$document +||123.10.32.252$document ||123.10.32.87$document ||123.10.32.95$document ||123.10.33.112$document @@ -153468,6 +153513,7 @@ ||123.14.95.219$document ||123.14.95.24$document ||123.14.95.248$document +||123.14.95.26$document ||123.14.96.154$document ||123.14.96.157$document ||123.14.96.209$document @@ -155849,6 +155895,7 @@ ||123.4.242.146$document ||123.4.242.152$document ||123.4.242.163$document +||123.4.242.19$document ||123.4.242.199$document ||123.4.242.204$document ||123.4.242.21$document @@ -156238,6 +156285,7 @@ ||123.4.47.248$document ||123.4.47.25$document ||123.4.47.32$document +||123.4.47.57$document ||123.4.48.128$document ||123.4.48.40$document ||123.4.48.70$document @@ -159050,6 +159098,7 @@ ||123.5.188.85$document ||123.5.188.86$document ||123.5.188.87$document +||123.5.188.9$document ||123.5.188.93$document ||123.5.188.97$document ||123.5.189.101$document @@ -159063,6 +159112,7 @@ ||123.5.189.14$document ||123.5.189.145$document ||123.5.189.147$document +||123.5.189.15$document ||123.5.189.150$document ||123.5.189.151$document ||123.5.189.154$document @@ -161246,6 +161296,7 @@ ||123.9.117.236$document ||123.9.117.245$document ||123.9.118.130$document +||123.9.118.183$document ||123.9.118.79$document ||123.9.119.209$document ||123.9.119.47$document @@ -162414,6 +162465,7 @@ ||123.9.35.198$document ||123.9.35.6$document ||123.9.35.88$document +||123.9.36.120$document ||123.9.36.188$document ||123.9.36.222$document ||123.9.36.6$document @@ -168263,6 +168315,7 @@ ||125.41.14.219$document ||125.41.14.22$document ||125.41.14.220$document +||125.41.14.228$document ||125.41.14.232$document ||125.41.14.235$document ||125.41.14.237$document @@ -188680,6 +188733,7 @@ ||143.198.220.102$document ||143.198.48.37$document ||143.198.54.180$document +||143.198.54.233$document ||143.198.63.143$document ||143.198.65.195$document ||143.198.65.229$document @@ -188946,6 +189000,7 @@ ||149.255.15.134$document ||149.255.15.138$document ||149.255.15.143$document +||149.255.15.170$document ||149.255.15.172$document ||149.255.15.180$document ||149.255.15.182$document @@ -188954,8 +189009,10 @@ ||149.255.15.213$document ||149.255.15.235$document ||149.255.15.27$document +||149.255.15.29$document ||149.255.15.38$document ||149.255.15.43$document +||149.255.15.44$document ||149.255.15.87$document ||149.255.15.99$document ||149.255.36.133$document @@ -190159,6 +190216,7 @@ ||157.90.24.103$document ||157.90.244.110$document ||157.90.244.177$document +||157.90.8.28$document ||157.97.133.128$document ||157.97.17.46$document ||157.97.2.215$document @@ -191391,6 +191449,7 @@ ||162.244.81.158$document ||162.244.81.204$document ||162.244.81.55$document +||162.245.221.121$document ||162.246.15.229$document ||162.246.20.117$document ||162.246.20.236$document @@ -203058,6 +203117,7 @@ ||178.175.10.224$document ||178.175.10.240$document ||178.175.10.244$document +||178.175.10.247$document ||178.175.10.248$document ||178.175.10.251$document ||178.175.10.254$document @@ -203089,6 +203149,7 @@ ||178.175.10.98$document ||178.175.10.99$document ||178.175.100.101$document +||178.175.100.104$document ||178.175.100.106$document ||178.175.100.109$document ||178.175.100.11$document @@ -203239,6 +203300,7 @@ ||178.175.101.21$document ||178.175.101.210$document ||178.175.101.211$document +||178.175.101.212$document ||178.175.101.213$document ||178.175.101.217$document ||178.175.101.219$document @@ -203340,6 +203402,7 @@ ||178.175.102.179$document ||178.175.102.183$document ||178.175.102.184$document +||178.175.102.186$document ||178.175.102.188$document ||178.175.102.189$document ||178.175.102.190$document @@ -203517,6 +203580,7 @@ ||178.175.104.110$document ||178.175.104.112$document ||178.175.104.114$document +||178.175.104.115$document ||178.175.104.116$document ||178.175.104.12$document ||178.175.104.120$document @@ -203863,6 +203927,7 @@ ||178.175.107.127$document ||178.175.107.13$document ||178.175.107.133$document +||178.175.107.135$document ||178.175.107.136$document ||178.175.107.138$document ||178.175.107.140$document @@ -204187,6 +204252,7 @@ ||178.175.109.96$document ||178.175.109.98$document ||178.175.11.0$document +||178.175.11.100$document ||178.175.11.101$document ||178.175.11.104$document ||178.175.11.105$document @@ -204614,6 +204680,7 @@ ||178.175.112.81$document ||178.175.112.85$document ||178.175.112.86$document +||178.175.112.87$document ||178.175.112.89$document ||178.175.112.90$document ||178.175.112.97$document @@ -205646,6 +205713,7 @@ ||178.175.121.12$document ||178.175.121.122$document ||178.175.121.123$document +||178.175.121.125$document ||178.175.121.129$document ||178.175.121.130$document ||178.175.121.133$document @@ -206304,6 +206372,7 @@ ||178.175.126.38$document ||178.175.126.4$document ||178.175.126.41$document +||178.175.126.43$document ||178.175.126.44$document ||178.175.126.46$document ||178.175.126.48$document @@ -206499,6 +206568,7 @@ ||178.175.13.212$document ||178.175.13.213$document ||178.175.13.216$document +||178.175.13.219$document ||178.175.13.220$document ||178.175.13.221$document ||178.175.13.222$document @@ -206602,6 +206672,7 @@ ||178.175.14.251$document ||178.175.14.27$document ||178.175.14.28$document +||178.175.14.29$document ||178.175.14.3$document ||178.175.14.32$document ||178.175.14.33$document @@ -206671,6 +206742,7 @@ ||178.175.15.190$document ||178.175.15.194$document ||178.175.15.195$document +||178.175.15.196$document ||178.175.15.197$document ||178.175.15.198$document ||178.175.15.199$document @@ -206987,6 +207059,7 @@ ||178.175.18.250$document ||178.175.18.253$document ||178.175.18.27$document +||178.175.18.31$document ||178.175.18.32$document ||178.175.18.36$document ||178.175.18.37$document @@ -207170,6 +207243,7 @@ ||178.175.2.224$document ||178.175.2.225$document ||178.175.2.226$document +||178.175.2.23$document ||178.175.2.230$document ||178.175.2.234$document ||178.175.2.236$document @@ -207448,6 +207522,7 @@ ||178.175.22.187$document ||178.175.22.188$document ||178.175.22.194$document +||178.175.22.198$document ||178.175.22.203$document ||178.175.22.206$document ||178.175.22.207$document @@ -207490,6 +207565,7 @@ ||178.175.22.67$document ||178.175.22.69$document ||178.175.22.72$document +||178.175.22.74$document ||178.175.22.75$document ||178.175.22.78$document ||178.175.22.83$document @@ -207725,6 +207801,7 @@ ||178.175.25.155$document ||178.175.25.156$document ||178.175.25.159$document +||178.175.25.162$document ||178.175.25.163$document ||178.175.25.164$document ||178.175.25.166$document @@ -207989,6 +208066,7 @@ ||178.175.27.25$document ||178.175.27.252$document ||178.175.27.253$document +||178.175.27.26$document ||178.175.27.30$document ||178.175.27.32$document ||178.175.27.34$document @@ -207998,6 +208076,7 @@ ||178.175.27.39$document ||178.175.27.4$document ||178.175.27.41$document +||178.175.27.43$document ||178.175.27.46$document ||178.175.27.47$document ||178.175.27.48$document @@ -208411,6 +208490,7 @@ ||178.175.30.80$document ||178.175.30.81$document ||178.175.30.86$document +||178.175.30.90$document ||178.175.30.91$document ||178.175.30.93$document ||178.175.30.96$document @@ -208689,6 +208769,7 @@ ||178.175.33.228$document ||178.175.33.23$document ||178.175.33.231$document +||178.175.33.233$document ||178.175.33.234$document ||178.175.33.236$document ||178.175.33.239$document @@ -209642,6 +209723,7 @@ ||178.175.41.225$document ||178.175.41.229$document ||178.175.41.23$document +||178.175.41.230$document ||178.175.41.231$document ||178.175.41.235$document ||178.175.41.237$document @@ -209999,6 +210081,7 @@ ||178.175.44.89$document ||178.175.44.9$document ||178.175.44.90$document +||178.175.44.93$document ||178.175.44.95$document ||178.175.44.96$document ||178.175.45.10$document @@ -210214,6 +210297,7 @@ ||178.175.46.54$document ||178.175.46.55$document ||178.175.46.59$document +||178.175.46.60$document ||178.175.46.61$document ||178.175.46.63$document ||178.175.46.65$document @@ -210244,6 +210328,7 @@ ||178.175.47.12$document ||178.175.47.122$document ||178.175.47.126$document +||178.175.47.127$document ||178.175.47.128$document ||178.175.47.132$document ||178.175.47.139$document @@ -210374,6 +210459,7 @@ ||178.175.48.161$document ||178.175.48.162$document ||178.175.48.163$document +||178.175.48.164$document ||178.175.48.168$document ||178.175.48.17$document ||178.175.48.172$document @@ -210587,6 +210673,7 @@ ||178.175.5.22$document ||178.175.5.221$document ||178.175.5.222$document +||178.175.5.223$document ||178.175.5.226$document ||178.175.5.227$document ||178.175.5.229$document @@ -210844,6 +210931,7 @@ ||178.175.52.11$document ||178.175.52.111$document ||178.175.52.112$document +||178.175.52.114$document ||178.175.52.115$document ||178.175.52.118$document ||178.175.52.119$document @@ -210903,6 +210991,7 @@ ||178.175.52.249$document ||178.175.52.250$document ||178.175.52.252$document +||178.175.52.255$document ||178.175.52.31$document ||178.175.52.33$document ||178.175.52.34$document @@ -211036,6 +211125,7 @@ ||178.175.53.83$document ||178.175.53.85$document ||178.175.53.86$document +||178.175.53.87$document ||178.175.53.9$document ||178.175.53.90$document ||178.175.53.94$document @@ -211139,6 +211229,7 @@ ||178.175.54.71$document ||178.175.54.72$document ||178.175.54.74$document +||178.175.54.78$document ||178.175.54.80$document ||178.175.54.81$document ||178.175.54.87$document @@ -211159,6 +211250,7 @@ ||178.175.55.113$document ||178.175.55.114$document ||178.175.55.117$document +||178.175.55.118$document ||178.175.55.119$document ||178.175.55.121$document ||178.175.55.125$document @@ -211368,6 +211460,7 @@ ||178.175.57.102$document ||178.175.57.103$document ||178.175.57.104$document +||178.175.57.105$document ||178.175.57.108$document ||178.175.57.11$document ||178.175.57.112$document @@ -211482,6 +211575,7 @@ ||178.175.58.125$document ||178.175.58.126$document ||178.175.58.127$document +||178.175.58.130$document ||178.175.58.133$document ||178.175.58.139$document ||178.175.58.14$document @@ -211504,6 +211598,7 @@ ||178.175.58.175$document ||178.175.58.177$document ||178.175.58.178$document +||178.175.58.18$document ||178.175.58.183$document ||178.175.58.185$document ||178.175.58.188$document @@ -211723,6 +211818,8 @@ ||178.175.6.196$document ||178.175.6.198$document ||178.175.6.2$document +||178.175.6.201$document +||178.175.6.203$document ||178.175.6.204$document ||178.175.6.205$document ||178.175.6.207$document @@ -211909,6 +212006,7 @@ ||178.175.61.206$document ||178.175.61.209$document ||178.175.61.210$document +||178.175.61.212$document ||178.175.61.214$document ||178.175.61.217$document ||178.175.61.219$document @@ -211976,6 +212074,7 @@ ||178.175.62.122$document ||178.175.62.123$document ||178.175.62.128$document +||178.175.62.130$document ||178.175.62.134$document ||178.175.62.137$document ||178.175.62.141$document @@ -212638,6 +212737,7 @@ ||178.175.68.161$document ||178.175.68.162$document ||178.175.68.164$document +||178.175.68.165$document ||178.175.68.166$document ||178.175.68.167$document ||178.175.68.17$document @@ -213270,6 +213370,7 @@ ||178.175.72.53$document ||178.175.72.54$document ||178.175.72.56$document +||178.175.72.58$document ||178.175.72.6$document ||178.175.72.61$document ||178.175.72.65$document @@ -213666,6 +213767,7 @@ ||178.175.76.27$document ||178.175.76.29$document ||178.175.76.33$document +||178.175.76.34$document ||178.175.76.36$document ||178.175.76.37$document ||178.175.76.43$document @@ -213950,6 +214052,7 @@ ||178.175.79.244$document ||178.175.79.247$document ||178.175.79.253$document +||178.175.79.27$document ||178.175.79.30$document ||178.175.79.31$document ||178.175.79.38$document @@ -214424,6 +214527,7 @@ ||178.175.83.156$document ||178.175.83.158$document ||178.175.83.167$document +||178.175.83.17$document ||178.175.83.176$document ||178.175.83.18$document ||178.175.83.180$document @@ -214692,6 +214796,7 @@ ||178.175.85.230$document ||178.175.85.231$document ||178.175.85.234$document +||178.175.85.235$document ||178.175.85.242$document ||178.175.85.243$document ||178.175.85.244$document @@ -215525,6 +215630,7 @@ ||178.175.92.208$document ||178.175.92.210$document ||178.175.92.211$document +||178.175.92.213$document ||178.175.92.214$document ||178.175.92.215$document ||178.175.92.218$document @@ -215634,6 +215740,7 @@ ||178.175.93.200$document ||178.175.93.202$document ||178.175.93.203$document +||178.175.93.204$document ||178.175.93.205$document ||178.175.93.207$document ||178.175.93.210$document @@ -215920,6 +216027,7 @@ ||178.175.95.79$document ||178.175.95.80$document ||178.175.95.82$document +||178.175.95.83$document ||178.175.95.85$document ||178.175.95.86$document ||178.175.95.88$document @@ -218519,6 +218627,7 @@ ||180.177.104.65$document ||180.177.180.6$document ||180.177.242.73$document +||180.177.5.36$document ||180.177.76.161$document ||180.177.80.11$document ||180.178.104.86$document @@ -218626,7 +218735,9 @@ ||180.188.241.91$document ||180.188.241.99$document ||180.188.247.140$document +||180.188.247.172$document ||180.188.247.181$document +||180.188.247.218$document ||180.188.247.26$document ||180.188.252.185$document ||180.188.252.37$document @@ -222743,6 +222854,7 @@ ||182.113.4.209$document ||182.113.4.223$document ||182.113.4.226$document +||182.113.4.247$document ||182.113.4.64$document ||182.113.4.68$document ||182.113.4.88$document @@ -223713,6 +223825,7 @@ ||182.114.193.245$document ||182.114.193.70$document ||182.114.194.116$document +||182.114.194.183$document ||182.114.194.184$document ||182.114.194.206$document ||182.114.194.210$document @@ -235189,6 +235302,7 @@ ||182.119.23.62$document ||182.119.23.70$document ||182.119.23.74$document +||182.119.23.75$document ||182.119.23.9$document ||182.119.23.90$document ||182.119.23.91$document @@ -235634,6 +235748,7 @@ ||182.119.48.200$document ||182.119.48.205$document ||182.119.48.217$document +||182.119.48.230$document ||182.119.48.242$document ||182.119.48.250$document ||182.119.48.255$document @@ -238505,6 +238620,7 @@ ||182.121.123.1$document ||182.121.123.122$document ||182.121.123.124$document +||182.121.123.134$document ||182.121.123.141$document ||182.121.123.142$document ||182.121.123.16$document @@ -239957,6 +240073,7 @@ ||182.121.200.115$document ||182.121.200.119$document ||182.121.200.127$document +||182.121.200.137$document ||182.121.200.143$document ||182.121.200.151$document ||182.121.200.161$document @@ -240149,6 +240266,7 @@ ||182.121.205.223$document ||182.121.205.228$document ||182.121.205.237$document +||182.121.205.246$document ||182.121.205.251$document ||182.121.205.39$document ||182.121.205.47$document @@ -246644,6 +246762,7 @@ ||182.126.109.133$document ||182.126.109.146$document ||182.126.109.150$document +||182.126.109.194$document ||182.126.109.20$document ||182.126.109.25$document ||182.126.109.255$document @@ -247409,6 +247528,7 @@ ||182.126.126.150$document ||182.126.126.16$document ||182.126.126.161$document +||182.126.126.162$document ||182.126.126.170$document ||182.126.126.176$document ||182.126.126.181$document @@ -251639,6 +251759,7 @@ ||182.127.207.156$document ||182.127.207.158$document ||182.127.207.162$document +||182.127.207.187$document ||182.127.207.218$document ||182.127.207.226$document ||182.127.207.247$document @@ -252695,6 +252816,7 @@ ||182.127.80.184$document ||182.127.80.192$document ||182.127.80.229$document +||182.127.80.240$document ||182.127.80.85$document ||182.127.80.89$document ||182.127.81.114$document @@ -253359,6 +253481,7 @@ ||182.235.29.89$document ||182.236.124.160$document ||182.239.129.154$document +||182.240.132.164$document ||182.240.132.203$document ||182.240.213.4$document ||182.240.214.81$document @@ -255111,6 +255234,7 @@ ||182.57.105.110$document ||182.57.105.161$document ||182.57.105.167$document +||182.57.105.175$document ||182.57.106.118$document ||182.57.106.190$document ||182.57.106.237$document @@ -260598,6 +260722,7 @@ ||183.141.54.112$document ||183.141.55.239$document ||183.141.60.120$document +||183.141.61.174$document ||183.141.61.39$document ||183.142.11.225$document ||183.142.115.155$document @@ -261262,6 +261387,7 @@ ||183.17.227.102$document ||183.17.227.109$document ||183.17.227.113$document +||183.17.227.148$document ||183.17.227.162$document ||183.17.227.172$document ||183.17.227.187$document @@ -261821,6 +261947,7 @@ ||183.49.47.56$document ||183.49.85.243$document ||183.49.85.247$document +||183.49.86.54$document ||183.49.87.144$document ||183.49.87.220$document ||183.49.87.27$document @@ -261909,6 +262036,7 @@ ||183.83.103.117$document ||183.83.104.165$document ||183.83.104.44$document +||183.83.104.55$document ||183.83.104.68$document ||183.83.105.181$document ||183.83.105.21$document @@ -262500,6 +262628,7 @@ ||185.117.119.71$document ||185.117.155.20$document ||185.117.2.107$document +||185.117.21.212$document ||185.117.75.111$document ||185.117.75.201$document ||185.117.75.248$document @@ -262589,6 +262718,7 @@ ||185.132.53.161$document ||185.132.53.166$document ||185.132.53.167$document +||185.132.53.182$document ||185.132.53.185$document ||185.132.53.186$document ||185.132.53.191$document @@ -263783,6 +263913,7 @@ ||185.36.59.11$document ||185.36.59.76$document ||185.36.81.43$document +||185.38.142.194$document ||185.38.142.236$document ||185.39.11.105$document ||185.39.183.48$document @@ -265141,6 +265272,7 @@ ||186.33.105.7$document ||186.33.105.8$document ||186.33.105.9$document +||186.33.107.74$document ||186.33.112.100$document ||186.33.112.101$document ||186.33.112.102$document @@ -267391,9 +267523,11 @@ ||189.170.12.149$document ||189.170.178.180$document ||189.170.40.102$document +||189.171.22.132$document ||189.171.31.166$document ||189.172.151.237$document ||189.174.35.248$document +||189.175.214.112$document ||189.176.68.26$document ||189.176.93.82$document ||189.177.144.215$document @@ -270026,6 +270160,7 @@ ||192.99.169.15$document ||192.99.208.196$document ||192.99.214.32$document +||192.99.221.230$document ||192.99.240.77$document ||192.99.242.13$document ||192.99.246.11$document @@ -273894,6 +274029,7 @@ ||202.164.138.156$document ||202.164.138.157$document ||202.164.138.158$document +||202.164.138.159$document ||202.164.138.160$document ||202.164.138.161$document ||202.164.138.162$document @@ -274150,6 +274286,7 @@ ||202.164.139.255$document ||202.164.139.26$document ||202.164.139.28$document +||202.164.139.29$document ||202.164.139.30$document ||202.164.139.31$document ||202.164.139.36$document @@ -274168,6 +274305,7 @@ ||202.164.139.52$document ||202.164.139.55$document ||202.164.139.56$document +||202.164.139.57$document ||202.164.139.58$document ||202.164.139.6$document ||202.164.139.60$document @@ -278154,6 +278292,7 @@ ||206.189.129.96$document ||206.189.131.31$document ||206.189.132.42$document +||206.189.135.162$document ||206.189.135.253$document ||206.189.138.82$document ||206.189.140.181$document @@ -282801,6 +282940,7 @@ ||219.154.113.157$document ||219.154.113.161$document ||219.154.113.163$document +||219.154.113.171$document ||219.154.113.172$document ||219.154.113.177$document ||219.154.113.181$document @@ -285162,6 +285302,7 @@ ||219.155.226.188$document ||219.155.226.194$document ||219.155.226.198$document +||219.155.226.205$document ||219.155.226.225$document ||219.155.226.43$document ||219.155.226.50$document @@ -288414,6 +288555,7 @@ ||219.157.138.38$document ||219.157.138.63$document ||219.157.139.165$document +||219.157.14.239$document ||219.157.14.85$document ||219.157.140.190$document ||219.157.140.255$document @@ -288876,6 +289018,7 @@ ||219.157.178.171$document ||219.157.178.179$document ||219.157.178.192$document +||219.157.178.196$document ||219.157.178.201$document ||219.157.178.205$document ||219.157.178.21$document @@ -291046,6 +291189,7 @@ ||219.157.48.44$document ||219.157.48.45$document ||219.157.48.46$document +||219.157.48.5$document ||219.157.48.51$document ||219.157.48.58$document ||219.157.48.59$document @@ -294211,6 +294355,7 @@ ||221.14.47.162$document ||221.14.47.182$document ||221.14.47.189$document +||221.14.47.204$document ||221.14.47.225$document ||221.14.47.46$document ||221.14.47.77$document @@ -295627,6 +295772,7 @@ ||221.15.182.29$document ||221.15.182.40$document ||221.15.182.48$document +||221.15.182.72$document ||221.15.182.9$document ||221.15.182.94$document ||221.15.183.104$document @@ -297170,6 +297316,7 @@ ||221.15.53.25$document ||221.15.53.42$document ||221.15.53.46$document +||221.15.53.55$document ||221.15.53.57$document ||221.15.53.62$document ||221.15.53.74$document @@ -307792,6 +307939,7 @@ ||222.140.163.15$document ||222.140.163.159$document ||222.140.163.179$document +||222.140.163.181$document ||222.140.163.184$document ||222.140.163.188$document ||222.140.163.208$document @@ -312936,6 +313084,7 @@ ||23.95.116.135$document ||23.95.116.144$document ||23.95.122.24$document +||23.95.122.25$document ||23.95.122.47$document ||23.95.13.131$document ||23.95.13.158$document @@ -323163,6 +323312,7 @@ ||27.40.71.3$document ||27.40.72.200$document ||27.40.73.175$document +||27.40.79.170$document ||27.40.79.70$document ||27.40.82.129$document ||27.40.82.201$document @@ -347530,6 +347680,7 @@ ||31.168.126.45$document ||31.168.146.199$document ||31.168.153.60$document +||31.168.16.68$document ||31.168.177.37$document ||31.168.178.71$document ||31.168.179.83$document @@ -356494,6 +356645,7 @@ ||41.143.247.190$document ||41.143.31.149$document ||41.143.57.149$document +||41.143.69.12$document ||41.144.143.214$document ||41.144.159.85$document ||41.146.243.74$document @@ -358755,6 +358907,7 @@ ||42.224.171.138$document ||42.224.171.162$document ||42.224.171.163$document +||42.224.171.165$document ||42.224.171.168$document ||42.224.171.193$document ||42.224.171.196$document @@ -360540,6 +360693,7 @@ ||42.224.254.199$document ||42.224.254.205$document ||42.224.254.207$document +||42.224.254.220$document ||42.224.254.224$document ||42.224.254.226$document ||42.224.254.228$document @@ -361066,6 +361220,7 @@ ||42.224.4.0$document ||42.224.4.1$document ||42.224.4.100$document +||42.224.4.110$document ||42.224.4.112$document ||42.224.4.12$document ||42.224.4.120$document @@ -365234,6 +365389,7 @@ ||42.227.222.143$document ||42.227.222.158$document ||42.227.222.174$document +||42.227.222.189$document ||42.227.222.229$document ||42.227.222.244$document ||42.227.222.43$document @@ -365269,6 +365425,7 @@ ||42.227.225.154$document ||42.227.225.181$document ||42.227.225.209$document +||42.227.225.253$document ||42.227.225.45$document ||42.227.225.49$document ||42.227.225.81$document @@ -369139,6 +369296,7 @@ ||42.230.142.79$document ||42.230.142.82$document ||42.230.143.130$document +||42.230.143.162$document ||42.230.143.17$document ||42.230.143.174$document ||42.230.143.176$document @@ -373512,6 +373670,7 @@ ||42.232.169.202$document ||42.232.169.203$document ||42.232.169.209$document +||42.232.169.211$document ||42.232.169.219$document ||42.232.169.22$document ||42.232.169.223$document @@ -375217,6 +375376,7 @@ ||42.233.96.52$document ||42.233.96.71$document ||42.233.97.10$document +||42.233.97.141$document ||42.233.97.149$document ||42.233.97.157$document ||42.233.97.160$document @@ -379856,6 +380016,7 @@ ||42.235.84.52$document ||42.235.84.54$document ||42.235.84.73$document +||42.235.84.85$document ||42.235.84.87$document ||42.235.84.88$document ||42.235.84.97$document @@ -381067,6 +381228,7 @@ ||42.237.114.252$document ||42.237.114.48$document ||42.237.114.50$document +||42.237.114.80$document ||42.237.114.87$document ||42.237.115.169$document ||42.237.115.175$document @@ -384953,6 +385115,7 @@ ||45.15.143.158$document ||45.15.143.170$document ||45.15.143.175$document +||45.15.143.191$document ||45.15.143.253$document ||45.15.25.65$document ||45.15.253.88$document @@ -386147,6 +386310,7 @@ ||45.229.54.198$document ||45.229.54.199$document ||45.229.54.200$document +||45.229.54.201$document ||45.229.54.202$document ||45.229.54.203$document ||45.229.54.204$document @@ -386248,6 +386412,7 @@ ||45.229.55.71$document ||45.229.55.75$document ||45.229.55.79$document +||45.229.55.80$document ||45.229.55.83$document ||45.229.55.85$document ||45.229.55.98$document @@ -386931,6 +387096,7 @@ ||45.77.78.41$document ||45.77.79.163$document ||45.77.88.79$document +||45.77.9.151$document ||45.77.97.236$document ||45.77.98.62$document ||45.78.21.150$document @@ -393506,6 +393672,7 @@ ||58.249.75.128$document ||58.249.75.13$document ||58.249.75.14$document +||58.249.75.146$document ||58.249.75.158$document ||58.249.75.159$document ||58.249.75.169$document @@ -393567,6 +393734,7 @@ ||58.249.77.105$document ||58.249.77.119$document ||58.249.77.12$document +||58.249.77.141$document ||58.249.77.142$document ||58.249.77.144$document ||58.249.77.147$document @@ -393904,6 +394072,7 @@ ||58.249.86.20$document ||58.249.86.202$document ||58.249.86.203$document +||58.249.86.214$document ||58.249.86.227$document ||58.249.86.242$document ||58.249.86.31$document @@ -394952,6 +395121,7 @@ ||59.126.128.92$document ||59.126.13.182$document ||59.126.132.4$document +||59.126.132.42$document ||59.126.136.62$document ||59.126.139.144$document ||59.126.148.122$document @@ -398976,6 +399146,7 @@ ||59.5.192.126$document ||59.5.204.218$document ||59.5.230.140$document +||59.50.23.23$document ||59.50.28.100$document ||59.51.10.111$document ||59.51.10.55$document @@ -401274,6 +401445,7 @@ ||59.92.217.210$document ||59.92.217.211$document ||59.92.217.214$document +||59.92.217.215$document ||59.92.217.217$document ||59.92.217.218$document ||59.92.217.219$document @@ -402443,6 +402615,7 @@ ||59.93.21.137$document ||59.93.21.138$document ||59.93.21.14$document +||59.93.21.140$document ||59.93.21.141$document ||59.93.21.146$document ||59.93.21.147$document @@ -403725,6 +403898,7 @@ ||59.94.182.208$document ||59.94.182.21$document ||59.94.182.210$document +||59.94.182.212$document ||59.94.182.216$document ||59.94.182.217$document ||59.94.182.22$document @@ -404616,6 +404790,7 @@ ||59.95.175.46$document ||59.95.175.47$document ||59.95.175.48$document +||59.95.175.49$document ||59.95.175.5$document ||59.95.175.50$document ||59.95.175.51$document @@ -412479,6 +412654,7 @@ ||60.211.80.189$document ||60.211.80.208$document ||60.211.80.213$document +||60.211.80.216$document ||60.211.80.5$document ||60.211.80.9$document ||60.211.81.125$document @@ -413134,6 +413310,7 @@ ||60.214.52.40$document ||60.214.52.50$document ||60.214.52.96$document +||60.214.53.159$document ||60.214.53.170$document ||60.214.53.183$document ||60.214.53.242$document @@ -422642,6 +422819,7 @@ ||60.254.88.6$document ||60.254.88.91$document ||60.254.89.110$document +||60.254.89.158$document ||60.254.89.160$document ||60.254.89.191$document ||60.254.89.195$document @@ -425720,6 +425898,7 @@ ||61.3.149.196$document ||61.3.149.197$document ||61.3.149.216$document +||61.3.149.244$document ||61.3.149.253$document ||61.3.149.26$document ||61.3.149.3$document @@ -425734,6 +425913,7 @@ ||61.3.149.86$document ||61.3.149.89$document ||61.3.150.0$document +||61.3.150.101$document ||61.3.150.104$document ||61.3.150.121$document ||61.3.150.140$document @@ -425775,9 +425955,11 @@ ||61.3.151.90$document ||61.3.152.205$document ||61.3.152.26$document +||61.3.153.224$document ||61.3.154.201$document ||61.3.154.21$document ||61.3.156.130$document +||61.3.156.17$document ||61.3.18.2$document ||61.3.18.216$document ||61.3.23.66$document @@ -426741,6 +426923,7 @@ ||61.52.186.181$document ||61.52.186.184$document ||61.52.186.185$document +||61.52.186.186$document ||61.52.186.192$document ||61.52.186.195$document ||61.52.186.207$document @@ -429680,6 +429863,7 @@ ||61.52.97.57$document ||61.52.97.61$document ||61.52.97.64$document +||61.52.97.68$document ||61.52.97.69$document ||61.52.97.72$document ||61.52.97.74$document @@ -434631,7 +434815,7 @@ ||65.99.158.218$document ||65.99.176.17$document ||650x.com$document -||654tyfcdr4654fytfy.top$document +||654tyfcdr4654fytfy.top/syzsnntnps.vx$document ||65k2.com$document ||66-gifts.com$document ||66.103.9.249$document @@ -435393,7 +435577,7 @@ ||6gue98ddw4220152.freebackup.site$document ||6hffgq.dm.files.1drv.com$document ||6hu.xyz$document -||6ip.us$document +||6ip.us/$document ||6iptv.com$document ||6itokam.com$document ||6ixbling.com/wp-admin/tv9qgaxqruvcumabdu/$document @@ -437826,6 +438010,7 @@ ||80.92.189.5$document ||80.92.189.70$document ||80.92.204.14$document +||80.92.204.57$document ||80.93.182.219$document ||80.99.128.61$document ||80001.me$document @@ -439034,6 +439219,7 @@ ||85.245.162.144$document ||85.247.247.175$document ||85.25.213.151$document +||85.250.147.134$document ||85.250.36.135$document ||85.255.1.93$document ||85.26.250.86$document @@ -439211,6 +439397,7 @@ ||86.7.86.4$document ||86.82.137.79$document ||86.91.10.91$document +||86.98.23.78$document ||860259.com$document ||8650hwvaapy.realbrjuridico.email$document ||866appliance.com$document @@ -439328,6 +439515,7 @@ ||87.248.61.60$document ||87.249.204.194$document ||87.251.235.167$document +||87.251.71.78$document ||87.251.82.211$document ||87.253.0.196$document ||87.253.1.206$document @@ -439903,6 +440091,7 @@ ||89.148.233.85$document ||89.148.234.101$document ||89.148.234.165$document +||89.148.234.217$document ||89.148.234.37$document ||89.148.235.94$document ||89.148.237.100$document @@ -441337,6 +441526,7 @@ ||93.157.62.102$document ||93.157.62.171$document ||93.157.62.58$document +||93.157.63.221$document ||93.157.63.244$document ||93.159.141.165$document ||93.159.141.166$document @@ -442953,7 +443143,19 @@ ||a.doko.moe$document ||a.gg.fm$document ||a.heritageandterre.com$document -||a.pomf.cat$document +||a.pomf.cat/avhmcy.exe$document +||a.pomf.cat/gziqpm.exe$document +||a.pomf.cat/ioxyfx.dat$document +||a.pomf.cat/kiwqkn.exe$document +||a.pomf.cat/madeuz.exe$document +||a.pomf.cat/nmzemw.exe$document +||a.pomf.cat/qhsyxo.exe$document +||a.pomf.cat/qqksvz.exe$document +||a.pomf.cat/uhfhfh.pif$document +||a.pomf.cat/vmwdhb.zip$document +||a.pomf.cat/yckrnz.exe$document +||a.pomf.cat/ymfxrc.jpg$document +||a.pomf.cat/yygruz.exe$document ||a.pomf.se$document ||a.pomf.space$document ||a.pomf.su$document @@ -447845,7 +448047,8 @@ ||anmocnhien.vn$document ||anmolanwar.com$document ||ann141.net$document -||anna.websaiting.ru$document +||anna.websaiting.ru/facturas-pendientes$document +||anna.websaiting.ru/facturas-pendientes/$document ||annaaluminium.annagroup.net$document ||annabelle-hamande.be$document ||annabphotography.co.uk$document @@ -448380,7 +448583,7 @@ ||app.boxrcdn.com$document ||app.bridgeimpex.org$document ||app.calag.at$document -||app.casetabs.com/n/p7nx8575$document +||app.casetabs.com$document ||app.catholicchurch.co.in$document ||app.choiphui.com$document ||app.cloudindustry.net$document @@ -450362,7 +450565,7 @@ ||atphitech.com$document ||atpn.ir$document ||atprofessional.org$document -||atpscan.global.hornetsecurity.com/index.php?atp_str=afw-6ropadyx-4diefo4dbv3e_xmh3-ype0mhrlsyeuhwsqoeebzlbafyf6_bdljtesgdugeymxapym1fsyhxkyylpvifpr0hnjo3w92mx4bqea-rhcujbljf7xs-ie79eig5o9b_hcfg9ygyzdkrnzco-swcs_bodliaxlfflgccv-hkcqkgjzmxadbpvzglcgsaecd8rv4if7ngcqkrxprwlykmzxyjhyncp2kigw8_rjsdchhxd9niyyjjb1jovi-wm8urvrdop7bvnkrinv2g2ef433yzwetxfwlzgfnehnqbtdbrst1zv1hncyrnd3tvjwjjwn-3c5irkywidug4sagusduvudmdsm6oim1nja1ody3mwvlzdyjojoj2og-0apvymvmjggu-mi8gg/$document +||atpscan.global.hornetsecurity.com$document ||atr.it$document ||atradex.com$document ||atragon.co.uk$document @@ -451152,6 +451355,8 @@ ||awsxb.xyz$document ||awsyscloud.com$document ||awtinfostore.co.business$document +||awumad01.top$document +||awuqze02.top$document ||ax-yogado.com$document ||axalize.vn$document ||axalta.grupojenrab.mx$document @@ -452576,8 +452781,7 @@ ||bbfr.cba.pl$document ||bbgiardinodoriente.it$document ||bbgk.de$document -||bbgroup.com.vn/wp-content/32451/$document -||bbgroup.com.vn/wp-content/statement/pwc9q80/4wugo9y-3518181981-77685-cl9yz8-1dbtjnuln9i/$document +||bbgroup.com.vn$document ||bbh-design.de$document ||bbhdata.com$document ||bbhs.org.ng$document @@ -453126,7 +453330,7 @@ ||bel-med-tour.ru$document ||belabargelro.com$document ||belair.btwstudio.ch$document -||belairinternet.com$document +||belairinternet.com/wp-includes/9c8gi-fhbzv-xflschcjz/$document ||belamater.com.br$document ||belangel.by$document ||belanja-berkah.xyz$document @@ -453247,7 +453451,8 @@ ||belz-development.de$document ||belznerdesign.de$document ||bem.fkep.unpad.ac.id$document -||bem.hukum.ub.ac.id$document +||bem.hukum.ub.ac.id/vdtdcc2636944/scan/rechnungszahlung/$document +||bem.hukum.ub.ac.id/wp-content/payments/012019/$document ||bem.unimal.ac.id$document ||bemagazine.club$document ||bemakeup.ru$document @@ -454035,10 +454240,7 @@ ||bierne-les-villages.fr$document ||biese.eu$document ||bietthubien.org$document -||bietthudep902.com/rwevpv/026/kaufvertrag_026_21052020.zip$document -||bietthudep902.com/rwevpv/984295264/kaufvertrag_984295264_21052020.zip$document -||bietthudep902.com/rwevpv/kaufvertrag_098_21052020.zip$document -||bietthudep902.com/rwevpv/kaufvertrag_74788472_21052020.zip$document +||bietthudep902.com$document ||bietthulambach.com$document ||bietthulienkegamuda.net$document ||bietthumau.com$document @@ -454587,6 +454789,7 @@ ||bitbucket.org/busrakulcu/busra-kulcu/downloads/browserguncelleme.apk$document ||bitbucket.org/busrakulcu/busra-kulcu/downloads/browserguncellemesi.apk$document ||bitbucket.org/bzr-company/fortune/downloads/miner.exe$document +||bitbucket.org/clubhousedev/clubhouse/downloads/clubhousepc.exe$document ||bitbucket.org/codedevelop/sourse/downloads/az.exe$document ||bitbucket.org/conan2019/download/downloads/clipper.exe$document ||bitbucket.org/coverengineer/2020/downloads/main.exe$document @@ -458521,7 +458724,7 @@ ||callpetercatering.com$document ||callrealtyaz.com$document ||callshaal.com$document -||callsmaster.com$document +||callsmaster.com/azureink.co.uk/sec_zone/us/sign/com/open_docs/$document ||calltoprimus.ru$document ||calltorepair.com/assets/09erzff/$document ||callumstokes.com$document @@ -460357,6 +460560,7 @@ ||cdn.discordapp.com/attachments/775201330172133379/785293636388519936/dhl_receipt.img$document ||cdn.discordapp.com/attachments/775238059083038744/818196372763181116/qtuar$document ||cdn.discordapp.com/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq$document +||cdn.discordapp.com/attachments/775238059083038744/829993648186851338/pslmlyfnpzgsgitrwwvalcfunumfmac$document ||cdn.discordapp.com/attachments/775303846645334037/784920798212784158/x2.exe$document ||cdn.discordapp.com/attachments/775537284656791553/779777829800771584/androidupdate.apk$document ||cdn.discordapp.com/attachments/775587299214753796/776303350953017414/ozsl506$document @@ -460588,6 +460792,7 @@ ||cdn.discordapp.com/attachments/825372018244583454/826848185246023750/loaddd.exe$document ||cdn.discordapp.com/attachments/825372018244583454/826848348342059008/zeppelin.exe$document ||cdn.discordapp.com/attachments/825372018244583454/826848405258633277/build.exe$document +||cdn.discordapp.com/attachments/825372018244583454/830455061724528690/v1.exe$document ||cdn.discordapp.com/attachments/825686740106870837/825687235973087262/chucks5000_leiqr231.bin$document ||cdn.discordapp.com/attachments/825686740106870837/825688243248562176/tobi5000_pskkckhmf118.bin$document ||cdn.discordapp.com/attachments/825686740106870837/825982118672597042/newdoggy5000_splqq85.bin$document @@ -460666,7 +460871,7 @@ ||cdnpic.mgyun.com$document ||cdnrep.reimage.com/prot/protectorpackagerr2023.exe$document ||cdnrep.reimage.com/ver/reimagepackage1874x64b.exe$document -||cdnrep.reimageplus.com$document +||cdnrep.reimageplus.com/rqt/reimagerepair.exe$document ||cdnxh.net$document ||cdoconsult.com.br$document ||cdolechon.com$document @@ -461479,7 +461684,7 @@ ||cheematransxpressinc.com$document ||cheerchile.cl$document ||cheerfulgiversneverlack.com$document -||cheerfullydo.com$document +||cheerfullydo.com/data/nhtlrr/94046/nbar_94046_29052020.zip$document ||cheesecakery.com.br$document ||cheetahridge.mediadevstaging.com$document ||chef-solutions.dreamscape.co.in$document @@ -462439,7 +462644,7 @@ ||clarte-thailand.com$document ||clashofclansgems.nl$document ||clasificados.diaadianews.com$document -||clasificadosmaule.com/wp-content/sites/szs9n6pvn37fgafd911ss_osiby1-753587659577/$document +||clasificadosmaule.com$document ||class.britishonline.co$document ||class.snph.ir$document ||classbrain.net$document @@ -462779,8 +462984,7 @@ ||clock.noixun.com$document ||clocktowercommunications.com/wp-admin/sre9o6j/$document ||clodflarechk.com$document -||clodura.ai/wp-content/qq46l73r-xole-35619/$document -||clodura.ai/wp-content/vlfqxilre/$document +||clodura.ai$document ||clone.affordable.cm$document ||clone.system-standex.dk$document ||cloned.in$document @@ -462970,7 +463174,9 @@ ||cmecobrancas.com$document ||cmelik.com$document ||cmessagers.com$document -||cmg.asia$document +||cmg.asia/wp-content/uploads/asifb-0wxsmxdavkvdu2_okcqpxaws-nk/$document +||cmg.asia/wp-content/uploads/dok/bkmrgzxziezodqvcvwbtcqinn/$document +||cmg.asia/wp-content/uploads/inc/rvvm3ragsf/$document ||cmg.ma$document ||cmgroup.com.ua$document ||cmhighschool.edu.bd$document @@ -465606,7 +465812,7 @@ ||cuadros.pe$document ||cuahangphongthuy.net$document ||cuahangstore.com$document -||cuahangvattu.com$document +||cuahangvattu.com/cofd/closed_sector/458kmxdg6a0ywt_wum4a4kmr01g2_cloud/46311257516564_txxafmu2a/$document ||cualtis.com$document ||cuanhomxingfanhapkhau.com$document ||cuasotinhoc.net$document @@ -466048,17 +466254,7 @@ ||d.qiluwl.com$document ||d.teamworx.ph$document ||d.techmartbd.com$document -||d.top4top.io/m_18677sx8h1.mp4$document -||d.top4top.io/p_101949r3r1.jpg$document -||d.top4top.io/p_12014tn3x1.jpg$document -||d.top4top.io/p_1519dkp831.jpg$document -||d.top4top.io/p_1567m7an31.png$document -||d.top4top.io/p_1638e5yhh1.jpg$document -||d.top4top.io/p_16819gzhe1.jpg$document -||d.top4top.io/p_1681wdig21.jpg$document -||d.top4top.io/p_169387gdp1.jpg$document -||d.top4top.io/p_1978um31.jpg$document -||d.top4top.io/p_794twvdh1.jpg$document +||d.top4top.io$document ||d.top4top.net$document ||d.ttr3p.com$document ||d04.data39.helldata.com$document @@ -468151,11 +468347,7 @@ ||deposayim.ml$document ||depositoclara.com.br$document ||depot7.com$document -||depozituldegeneratoare.ro/jgipmpwb0g$document -||depozituldegeneratoare.ro/jgipmpwb0g/$document -||depozituldegeneratoare.ro/open-invoices/$document -||depozituldegeneratoare.ro/past-due-invoices/$document -||depozituldegeneratoare.ro/telekom/rechnung/112018/$document +||depozituldegeneratoare.ro$document ||depraetere.net$document ||deprealty.ru$document ||depressionted.com$document @@ -469972,7 +470164,8 @@ ||dl-675423.store-downloads.com$document ||dl-80076342.md-downloads.com$document ||dl-97674424.md-downloads.com$document -||dl-gameplayer.dmm.com$document +||dl-gameplayer.dmm.com/product/apkggame/giga_baldrbringerextendcode/giga_baldrbringerextendcode/win/src/content/data/data/uninstall.exe$document +||dl-gameplayer.dmm.com/product/apkggame/nel_narikiri/nel_narikiri/win/src/content/data/%e3%81%aa%e3%82%8a%e3%81%8d%e3%82%8a%e3%83%90%e3%82%ab%e3%83%83%e3%83%97%e3%83%ab%ef%bc%81.exe$document ||dl-link.link$document ||dl-link.live$document ||dl-link.network$document @@ -470292,9 +470485,10 @@ ||dl.imht.ir$document ||dl.installcdn-aws.com$document ||dl.mqego.com$document -||dl.mydown.com$document +||dl.mydown.com/download/be5abe2da15f5d91d4f29cbf80d5d581/509451398_6/newsoft/tsbrowser_724_4.0.7.20.exe$document ||dl.ossdown.fun$document ||dl.packetstormsecurity.net$document +||dl.pandasecur.com$document ||dl.popupgrade.com$document ||dl.repairlabshost.com$document ||dl.rina-roleplay.com$document @@ -470815,8 +471009,7 @@ ||doc-0s-68-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/q5qe5q1uvep35ccrbr1g80sub349agop/1543320000000/05984462313861663074/*/19esasjydhkmq-f80tgnobrth0yudmgzy$document ||doc-0s-68-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/stiolst1g6i8vasis6jegpqd2b04imod/1543327200000/05984462313861663074/*/19esasjydhkmq-f80tgnobrth0yudmgzy$document ||doc-0s-70-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/6i0lbore8mloquf0s0inmqhshir3jrs8/1542996000000/08141031105246785918/*/1frfmibmbtnbemiolrz9aktbpn7jsr6sr?e=download$document -||doc-0s-7c-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/5bvsb5ttjjkmftcv00posgt0a2lsq6pq/1579680000000/03683026262266078671/*/16rew7icapzdfonn9ubjb-owowh_uiuk5?e=download$document -||doc-0s-7c-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/ml48mc3h16rmkppielv4ukafil7iun3f/1580112000000/11177655664072506190/*/1nybpfnssg325879zor4tfv-8jgmxnlj2?e=download$document +||doc-0s-7c-docs.googleusercontent.com$document ||doc-0s-80-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/nc8mtg3folbcd5haj9bc709btbqsqnoh/1578895200000/09593966995115687919/*/1k8z46ungjn3fizc5ih1syhdji3zbao1w?e=download$document ||doc-0s-8c-docs.googleusercontent.com/docs/securesc/4jc3o0kkf5136n14s0obie5i3338237o/crl1nl7rrivhhkpl1l4rck0f9km8v2t5/1579795200000/11177655664072506190/09384270791473589425/1m-hgvq0i-3aqo0w0pgga_sqanki6ahj3?e=download&authuser=0&nonce=3jhgojl8vukmm&user=09384270791473589425&hash=qa8cgr1tgr33cqmmn859u2qkmrrbrk5m$document ||doc-0s-8s-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/8ne944b43812vrcuv9954p7n8r2suam3/1547575200000/07335649321361492730/*/1dypty3z5gun_lf52eicq3h2hezuqwpkq?e=download$document @@ -470831,8 +471024,7 @@ ||doc-0s-bs-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/ene3b5nenits168gjf4lnni1kuie3jnr/1552039200000/11569688848916399575/*/1hgnjd29qwsmeort3zpfpwxxm8fdd3ygq?e=download$document ||doc-0s-c8-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/4b7n6eqfl7n5boc61bjf0q7b5mksc6lp/1555516800000/16964281332718813838/*/1qerkwklbb2tcmxsqrvylgwn7viz4xhhy$document ||doc-0s-c8-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/uumujnqdoksb2iq336es2fnlcgjkfjop/1601921475000/08069565659861269988/*/1hqi4mjve0ifpo5vwi0okysf2eakt1ljz$document -||doc-10-0c-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/gc8dsf1456d9gmibfmg7o25gs6ectrmo/1551816000000/14063452590226117103/*/1_jo_vxwckb1cbttkzgd7nmqezfuujvhb?e=download$document -||doc-10-0c-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/nhbo71cjafudtbkd3ls3bismqvuj8ig6/1549828800000/14063452590226117103/*/1_jo_vxwckb1cbttkzgd7nmqezfuujvhb?e=download$document +||doc-10-0c-docs.googleusercontent.com$document ||doc-10-28-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/r5fjotq4qok8a7pk9sain44inha7ocft/1580104800000/13535128519197762172/*/1topkmo_eawlxskmpgmjbhsgrjusoj8kc?e=download$document ||doc-10-34-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/hgrdjpkp37sdv3rd3miim43hdd84tv71/1580364000000/06792381463910506630/*/1yrlvbuhbbtzusz9amngr4c6_x7i0db6u?e=download$document ||doc-10-44-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/sg56hqhomngdvphgv21g37ft31vqvjql/1581605100000/08658714528148673336/*/1jzbbjgpebq0xdke_vvydr_dmxwsxuef4?e=download$document @@ -470850,7 +471042,7 @@ ||doc-10-88-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/gs4tf9lgm5e90i6qvfvo78fvi78b2ba7/1579701600000/01423698199670842299/*/1fpnbcmqkjsh5dp_kwvkbusccnzjezbyo?e=download$document ||doc-10-8g-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/bkavgvoa0anttjt05vct2lecdjdofugu/1552564800000/10901782374314873973/*/1os_ldyiqmoy8rhs0ylu3odlgfmf7cdk0$document ||doc-10-8o-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/djvcoprs7ik42sgsnpcn1rhauljdcper/1579586400000/10077574138565375691/*/1zcfkyuetnb51zhkvmx3hm3r7xb2himqu?e=download$document -||doc-10-8s-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/r4rrt36iqlpu59et4hbr6bdvscb5lcno/1547150400000/07335649321361492730/*/1k4wwzw-ai239shkc3qbksuv4rpimdmio?e=download$document +||doc-10-8s-docs.googleusercontent.com$document ||doc-10-98-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/8h1v715bmm41gaeni9q0ca6vqpfptos9/1580104800000/03594737999780208267/*/1csdtiyql0cldrstrazrnftmoubtfzwkk?e=download$document ||doc-10-98-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/99uiri3hlipm4tt7mrai16mbv23797h2/1579003200000/03594737999780208267/*/17eycga79cao3bkde5ov9lh7j_sz1iv-l?e=download$document ||doc-10-98-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/dvfn4tg87qm827b127b5ibb5uo3k8god/1579939200000/03594737999780208267/*/1sd3mqdidoetuy3tmzwujjx2s9kbv6zra?e=download$document @@ -475759,6 +475951,7 @@ ||drive.google.com/uc?export=download&id=1dyhilkcw_idrwtoquewgui5bz3eounv5$document ||drive.google.com/uc?export=download&id=1dz8-iw3l5e1shc2unot8s6v5bweh5n3j$document ||drive.google.com/uc?export=download&id=1dzw-mtd4b5a3jvccvvkdcjsd-bsoqst0$document +||drive.google.com/uc?export=download&id=1dzx_cflers_zntlrip3fhbxb5who03u0$document ||drive.google.com/uc?export=download&id=1e-5ug_mz0zphngg9huvc1mzpx4_qfaw7$document ||drive.google.com/uc?export=download&id=1e-eglblcxhjqkum_hk8mvkg1-p3uvh8n$document ||drive.google.com/uc?export=download&id=1e-gyqr_ugzsyy31zw40u-cprrw15-_tw$document @@ -478035,6 +478228,7 @@ ||drive.google.com/uc?export=download&id=1xbdlhwd5vdtco07vt5-ac0u37e-nycgg$document ||drive.google.com/uc?export=download&id=1xbeqbw67xz4iqpu8dgmdrlkpa6kzotes$document ||drive.google.com/uc?export=download&id=1xbfd2msdcw6hm2swjxtogmijoiuefkqe$document +||drive.google.com/uc?export=download&id=1xbp7hvw2ybwjrftbvdkjvwzrfuk4ope9$document ||drive.google.com/uc?export=download&id=1xbwjfdd21zot8vazb0egqi5kuzw90t7o$document ||drive.google.com/uc?export=download&id=1xc1vhtuzdeuqp-hkpnrix8ursqwurrel$document ||drive.google.com/uc?export=download&id=1xc5botlfmsw23xotatnddimh8r-btiv7$document @@ -489095,7 +489289,7 @@ ||ec2-54-207-92-161.sa-east-1.compute.amazonaws.com$document ||ec2-54-212-231-68.us-west-2.compute.amazonaws.com$document ||ec2-54-94-215-87.sa-east-1.compute.amazonaws.com$document -||ec2euc1.boxcloud.com/d/1/a1!1v6vibwx7vlie5y8jj5xm5ipoc9jdxze8ck08lu22jdqvqu0y23hledgazmxqbcukhlgg95jbfv9p6e7n10-td4omxyxferhngbpik8idewoo81utbhmygy4yzt8uxvxi_dnrwzvwtlndrqwk6hotxffg8jkpj8-j3bybrd7yw7n9nyzemoqeelvbjthue6wa3yuozggyesvvg1o6919_nqqhatm_0mampn9-_jtxf4s-ugi1s9il7i1vz-euwgqoqgfey5ojdw8thvvonrqk07jcvnmdwqnxx73l0zvlypuue7zjxsucd5ngxrgnlrokmgqml3gqmvtclnbzspt-4hcnbybe8gfkg2psuvv1aq_omqri7_jbjnodn0k3rmscvbihzzjag_jacj95hxys2nqu5-avfi3mcsbykrgcfcd0f0ubmxy8_u-adp_am2uyu7wjbtlhrmdeya-wvab9_d_rsbzn6qhbobnfb-ijabnqe8ynoztvmmj5-48vxc-gimyw84qv5vvoewlfuazz6lhawnqlsehdoko20t5tsgdq-ixnr9upyrvqgkqg9hpkx37rcfrizch7msfmqqhgbz-2kepa7cuisq2u8z21psh44kaslvzjjckzbjxaazonnqpicscjypbbx8vqrtok7qhix5gnjmofxjghi8dnzcdrvrzwwf9qowdqzmqle38iykwpk_43qarzcyv53ecglsevfziyq5bqgscnvlv9ypi3dlnhklmijhb_-nal1ma_y7hazsqeqks-c-_2pporvy4fabaa7ppnt7cji5vsu1jcfdqk3xg_voorzho8qzmelylrsddbg1k4rbzk7hhqwn_sbr0owykfhvovjqzq1lssanl7n3sjbh_adgrgglq2ojvyqsklvlnet4-3dr8qnksaaphkhmfzaggxffhkiuks7n6dth09683x8t1ape47jo8a3du24wyvolahwxr0i91czhb9fphq2_qbhc66ww4pynr2kvclrajdii50jao1znpe0nbdtqdqc9c4dladdwtrfnh-1lywnfvm1szr-fky7qtf9ysdut3htypftcw-zwftt5yxvxpff6-xxcd599rg8fr2-inwced5f8d3vc_lu3sy9p_-mfnsp_urjy0f9rcy3lnsgb_$document +||ec2euc1.boxcloud.com$document ||ec2test.ga$document ||ec3-design.com$document ||ecadigital.com$document @@ -491452,6 +491646,7 @@ ||esaarc.com$document ||esacbd.com$document ||esagarautomobiles.com$document +||esaja09.top$document ||esanjobs.org$document ||esar.weenets.com$document ||esascom.com$document @@ -497631,7 +497826,7 @@ ||genrjw.dm.files.1drv.com$document ||genstaff.gov.kg$document ||gentcreativa.com$document -||gentecoyol.com$document +||gentecoyol.com/riot-vanguard/hb/$document ||gentesanluis.com$document ||gentiane-salers.com$document ||gentlechirocenter.com$document @@ -500592,8 +500787,7 @@ ||gvpcdpgc.edu.in$document ||gvpmacademy.co.za$document ||gvsme.com$document -||gw.daelimcloud.com/website/mail/attachedfile/largefiledownload.aspx?key=mjqtuleptqynziynzymrkleptc0mjcyntmmvfjdsz1zjk1ot1rjpu4%3d$document -||gw.daelimcloud.com/website/mail/attachedfile/largefiledownload.aspx?key=odgtuleptq0mjgzntqmrkleptc2otc4mtimvfjdsz1zjk1ot1rjpu4%3d$document +||gw.daelimcloud.com$document ||gw.hitlin.com$document ||gwangjuhotels.kr$document ||gwavellc.com$document @@ -503505,7 +503699,20 @@ ||hotelwaldblick.com$document ||hotexpress.co$document ||hotfacts.org$document -||hotgifts.online$document +||hotgifts.online/1291994a7f3a5816fb62a8f825076dfb/winboxscan.exe$document +||hotgifts.online/1da70a31e6545d7c5611b2410a4dc351/updateprofile.exe$document +||hotgifts.online/616127c527f57b3aff6bbbf3e00c48d7/winboxscan.exe$document +||hotgifts.online/6ab91d75132f7aa1085b1cea8df09d05/winboxscan.exe$document +||hotgifts.online/71eb063309e71fb131b8fec3804e8ce9/updateprofile.exe$document +||hotgifts.online/73a5c1a5cb2a3c4095bad22fd413d98e/winboxscan.exe$document +||hotgifts.online/9050b32a16e63abe28c544048fdebafc/winboxscan.exe$document +||hotgifts.online/9db8ff1707781393a2f8f4843028bf62/updateprofile.exe$document +||hotgifts.online/a7b6d8f0cc006e65b9f5707c817a8523/winboxscan.exe$document +||hotgifts.online/app/app.exe$document +||hotgifts.online/app/app171.exe$document +||hotgifts.online/app/e7.exe$document +||hotgifts.online/app/watchdog.exe$document +||hotgifts.online/bc751a3f103b5151e09550385e5e50d3/updateprofile.exe$document ||hotilife.com$document ||hotissue.xyz$document ||hotkine.com$document @@ -503895,7 +504102,8 @@ ||hukuen-motokare.xyz$document ||hukuki.site$document ||hukukportal.com$document -||hukum.ub.ac.id$document +||hukum.ub.ac.id/order/document.zip?0774181353[document_pdf________________________________________________________________%20.exe]$document +||hukum.ub.ac.id/order/document.zip?0774181353[document_pdf________________________________________________________________+.exe%5d$document ||hukum.unwiku.ac.id$document ||hulianwang114.com$document ||huliot.in$document @@ -504225,7 +504433,7 @@ ||i.cubeupload.com/euev6n.jpg$document ||i.cubeupload.com/ez3vpt.jpg$document ||i.cubeupload.com/gmetap.jpg$document -||i.fiery.me/5vdk.png$document +||i.fiery.me$document ||i.fluffy.cc$document ||i.funtourspt.eu$document ||i.imgur.com/3zblzb6.png$document @@ -507651,6 +507859,7 @@ ||itspsc.com.ua$document ||itspueh.nl$document ||itsquare.yrcreations.com$document +||itsrlytry.000webhostapp.com$document ||itssprout.com$document ||itstelecom.com.br$document ||itsweezle.com$document @@ -507853,7 +508062,7 @@ ||j-stage.jp$document ||j-toputvoutfitters.com$document ||j.kyryl.ru$document -||j.top4top.io/p_14674n4b11.jpg$document +||j.top4top.io$document ||j11g9xecuxe43xu.xyz$document ||j12z7407gwtzk.xyz$document ||j13.biz$document @@ -507989,6 +508198,7 @@ ||jaipurweddingphotography.com$document ||jairathsnatural.ca$document ||jairozapata.000webhostapp.com$document +||jaishomo.info$document ||jaishritours.com$document ||jaiswalsupplement.com$document ||jajadomains.com$document @@ -512119,7 +512329,7 @@ ||kodim0112sabang.com$document ||kodingeko.com$document ||kodip.nfile.net$document -||kodjdsjsdjf.tk$document +||kodjdsjsdjf.tk/mine.exe$document ||kodlacan.site$document ||kodmuje.com$document ||kodolios.000webhostapp.com$document @@ -514923,10 +515133,7 @@ ||library.cifor.org$document ||library.dhl-xom.com$document ||library.iainbengkulu.ac.id$document -||library.mju.ac.th/2018/cfjdes/$document -||library.mju.ac.th/2018/mnnw0cr-ptv5a-370268/$document -||library.mju.ac.th/2018/rn-72c-0657/$document -||library.mju.ac.th/2018/zoipdun1a0/$document +||library.mju.ac.th$document ||library.phibi.my.id$document ||library.piet.co.in$document ||library.strophicmusic.com$document @@ -515634,7 +515841,7 @@ ||livecigarevent.com$document ||livecricketscorecard.info$document ||livedaynews.com$document -||livedemo00.template-help.com$document +||livedemo00.template-help.com/28736_site/hoeflertext.font.com$document ||livedownload.in$document ||livedrumtracks.com$document ||livefarma.com$document @@ -515669,7 +515876,7 @@ ||livestreams.vn$document ||livesuitesapartdaire.com$document ||livesurgerycourse.ir$document -||liveswinburneeduau-my.sharepoint.com$document +||liveswinburneeduau-my.sharepoint.com/:u:/g/personal/101937439_student_swin_edu_au/eqsmp3lwkfzfr0zegn-tkiqb6agjne8t4rqyjhktmzur6w?e=zl6yl7&download=1$document ||liveswindow.casa$document ||liveswindow.cyou$document ||liveswindows.bar$document @@ -516868,7 +517075,8 @@ ||luzconsulting.com.br$document ||luzevida.com.br$document ||luzfloral.com$document -||luzy.vn$document +||luzy.vn/wp-admin/protected-box/5n0ddpmuc-eqlu1o1befow-wzj8lfwj-9ega3umab/795789-ppeclz1q1bf/christmas_card/$document +||luzy.vn/wp-content/etrac/p7d8lzxe7p/r8d492343724021xd3b2760u727yqdsbnpw5r/$document ||luzzeri.com$document ||lvajnczdy.cf$document ||lvcfund.org.vn$document @@ -520025,7 +520233,7 @@ ||mecgwl.ac.in$document ||mechanicaltools.club$document ||mechanicsthatcometoyou.com$document -||mecharnise.ir$document +||mecharnise.ir/ca3/fre.php$document ||mechathrones.com$document ||mechauto.co.za$document ||mechdesign.com$document @@ -520753,7 +520961,7 @@ ||menziesadvisory-my.sharepoint.com$document ||menzway.com$document ||meogiambeo.com$document -||meohaybotui.com$document +||meohaybotui.com/qitjgi/$document ||meolamdephay.com$document ||mepsgen.com$document ||mera.ddns.net$document @@ -521075,9 +521283,7 @@ ||mfomjr.com$document ||mfotovideo.ro$document ||mfpburundi.bi$document -||mfpc.org.my//wp-content/plugins/formcraft3/stub2_encrypted_ba9409f.bin$document -||mfpc.org.my/wp-admin/images/stb_encrypted_5b6e930.bin$document -||mfpc.org.my/wp-admin/meta/stb_encrypted_a322e7f.bin$document +||mfpc.org.my$document ||mfppanel.xyz$document ||mfpvision.com$document ||mfronza.com.br$document @@ -526298,7 +526504,7 @@ ||nhadatquan2.xyz$document ||nhadatthienthoi.com$document ||nhadephungyen.com$document -||nhadepkientruc.net$document +||nhadepkientruc.net/wp-content/ogi3nl90/$document ||nhahangdaihung.com$document ||nhahanghaivuong.vn$document ||nhahanglegiang.vn$document @@ -526523,7 +526729,8 @@ ||nikanpolimer.ir$document ||nikastroi.ru$document ||nikavkuchyni.sk$document -||nikayu.com$document +||nikayu.com/mpvjl0awc9zkv$document +||nikayu.com/mpvjl0awc9zkv/$document ||nikbox.ru$document ||nikeshyadav.com$document ||nikhil.webscript.co.in$document @@ -531785,7 +531992,7 @@ ||option47.us$document ||optioncapitalgroup.ru$document ||optionrp.com$document -||optionscity.com$document +||optionscity.com/wp-content/wptouch-data/debug/safebrowsing.exe$document ||optisaving.com$document ||optitechsa.co.za$document ||optocen.ru$document @@ -532096,7 +532303,7 @@ ||osheoufhusheoghuesd.ru/m.exe$document ||osheoufhusheoghuesd.ru/o.exe$document ||osheoufhusheoghuesd.ru/t.exe$document -||oshi.at$document +||oshi.at/qbpahk/$document ||oshiscafe.com/wp-admin/5dm/$document ||oshodrycleaning.com$document ||oshonafitness.com$document @@ -541948,7 +542155,68 @@ ||posmicrosystems.com$document ||posnxqmp.ru$document ||pospeeps.com$document -||posqit.net$document +||posqit.net/0/56021017.exe$document +||posqit.net/0/5911097.exe$document +||posqit.net/0/6013277.exe$document +||posqit.net/0/6502301.exe$document +||posqit.net/0/80177.exe$document +||posqit.net/00/6508908.exe$document +||posqit.net/8t/4460139.exe$document +||posqit.net/8t/50173309.exe$document +||posqit.net/b/5003037.exe$document +||posqit.net/b/9051077.jpg$document +||posqit.net/ctw/1011.hta$document +||posqit.net/ctw/2055970$document +||posqit.net/ctw/96053407$document +||posqit.net/ctw/96053407.hta$document +||posqit.net/ctw/9908793$document +||posqit.net/ctw/scan091019$document +||posqit.net/f1/scan-document-shipment-info$document +||posqit.net/f1/scan-document-shipment-info.hta$document +||posqit.net/ge/20610444.jpg$document +||posqit.net/ge/206440.exe$document +||posqit.net/ge/4509700.exe$document +||posqit.net/ge/50010378.jpg$document +||posqit.net/ge/5013447.exe$document +||posqit.net/iy/5607087.exe$document +||posqit.net/pe/0362035.exe$document +||posqit.net/pe/0578102.exe$document +||posqit.net/pe/08437.exe$document +||posqit.net/pe/0955576.exe$document +||posqit.net/pe/1050700.exe$document +||posqit.net/pe/1101708.exe$document +||posqit.net/pe/11045830.exe$document +||posqit.net/pe/1106778.exe$document +||posqit.net/pe/2117636.exe$document +||posqit.net/pe/60380.exe$document +||posqit.net/pe/60589.exe$document +||posqit.net/pe/myfile5.exe$document +||posqit.net/pe/scan-05458.exe$document +||posqit.net/qq/05700301.exe$document +||posqit.net/qq/0621777.exe$document +||posqit.net/qq/0629107.exe$document +||posqit.net/qq/1035661.exe$document +||posqit.net/qq/7800132.exe$document +||posqit.net/qq/78045109.exe$document +||posqit.net/tt/440789.exe$document +||posqit.net/tt/741003.exe$document +||posqit.net/tt/850135.exe$document +||posqit.net/tt/89051102.exe$document +||posqit.net/tt/90461777.exe$document +||posqit.net/ty/20601907.jpg$document +||posqit.net/vcv/120131078.exe$document +||posqit.net/vcv/2031078.exe$document +||posqit.net/vcv/306517.exe$document +||posqit.net/w/03305177$document +||posqit.net/w/6006077.exe$document +||posqit.net/w/9078950$document +||posqit.net/w/9078950.hta$document +||posqit.net/xl/08971130$document +||posqit.net/xl/2013544$document +||posqit.net/xl/50333087$document +||posqit.net/xl/6090970$document +||posqit.net/xl/6090970.hta$document +||posqit.net/xl/new%20order.exe$document ||possessionnow.com$document ||possible.re$document ||possopagar.com.br$document @@ -542599,7 +542867,14 @@ ||prisidmart.com$document ||priskat.net$document ||prism-photo.com$document -||prisma.fp.ub.ac.id$document +||prisma.fp.ub.ac.id/wp-content/amazon/en/information/012019/$document +||prisma.fp.ub.ac.id/wp-content/orders_details/012019/$document +||prisma.fp.ub.ac.id/wp-content/plugins/hpcrs-sdpvl_nr-tk/inv/70971forpo/264773867145/us_us/open-past-due-orders/$document +||prisma.fp.ub.ac.id/wp-content/us_us/info/copy_invoice/wzddw-n2xu_ngxm-z41/$document +||prisma.fp.ub.ac.id/wp-content/us_us/xerox/invoice_number/fhbq-zwqr_um-fg/$document +||prisma.fp.ub.ac.id/wp-content/xerox/midy-2g_ftbtdf-2yo/$document +||prisma.fp.ub.ac.id/wp-content/xldld_li-wbbm/xt/attachments/02_19$document +||prisma.fp.ub.ac.id/wp-content/xldld_li-wbbm/xt/attachments/02_19/$document ||prismaxis.com$document ||prismfox.com$document ||prismware.ml$document @@ -543214,9 +543489,7 @@ ||protect-us.mimecast.com/s/7ihcc82oqycqx96qh15qw5$document ||protect-us.mimecast.com/s/c27ac0rx9ru80p3fw0bgj$document ||protect-us.mimecast.com/s/qki9c73wxjupxq5ps8qcm_$document -||protect.mimecast-offshore.com/s/ip17cn9blzfnq4n4h4tudd?domain=meraqsa.com/$document -||protect.mimecast-offshore.com/s/loqwcg5rvpcjndxqc76apn?domain=ronakfence.ir/$document -||protect.mimecast-offshore.com/s/rd0zcjqxyvf8w6o3igppxq?domain=ronakfence.ir/$document +||protect.mimecast-offshore.com$document ||protect2.fireeye.com/v1/url?k=59eacb3c-0560e9d5-59ed97de-0cc47ad93e2e-0f5e34e79adab692&q=1&e=e7991bbc-cc93-4814-a8f2-fd6d6950b0d5&u=https%3a%2f%2fwww.mediafire.com%2ffile%2fs2uyxs8t8kbuyye%2fdocumentos_de_env%25cdo.7z%2ffile$document ||protect2.fireeye.com/v1/url?k=6d0c09d2-33bdd2b2-6d0f7943-86e2237f51fb-ab55eb53c2dfee1f&q=1&e=358c9b57-d351-4b0f-80cf-d0755ec21127&u=https://pottershousedurban.co.za/cgi-bin/file/xzbx0cb5wywuw5/179vj6b9dpsp7advozp/$document ||protectiadatelor.biz$document @@ -543303,7 +543576,7 @@ ||proxy-ipv4.com$document ||proxy.2u0apcm6ylhdy7s.com$document ||proxy.hueaudio.com$document -||proxy.qualtrics.com/proxy/?url=https%3a%2f%2fuark.qualtrics.com%2fcp%2ffile.php%3ff%3df_0imyt11iuwaovez&token=vazkfd%2bfsrcuyx5fyunax24zxgk5dxrgqszm%2bpoz8fw%3d$document +||proxy.qualtrics.com$document ||proxygrnd.xyz$document ||proxyholding.com$document ||proxyresume.com$document @@ -544801,7 +545074,6 @@ ||r100.youth.tc.edu.tw$document ||r10instagram.com$document ||r10ticaret.xyz$document -||r20.rs6.net/tn.jsp?f=001jyht2t3omeetiei35oqstjgs_9nzk9sjylnhtbb0ao4bhans77uolbdrrwaaelcy_xfpwz_v9kt7buybu0v7bxkhuwlnsftzi2_8ddimoio4s1lnjpwd3da7cbyogtmhkf5obn3ysllinftl_gcxaufwxn0bz8fxjf4yvhjb-3gtb-da07vpp0qazekjwo7a9udmhkol3peul1z7wczztkps5tadshty&c=sda7vzhezlmymcpvzhysvdoo2nf8acki9xwyb_wfzgl7nntihduz-a==&ch=hl2va1psqpoi_ueanwygza8msuiyrkcqkgylcfuiihszmkx0z2mngg==$document ||r22lm.siaraya.com$document ||r257.com.br$document ||r2consulting.net$document @@ -546023,6 +546295,7 @@ ||redlogisticsmaroc.com$document ||redloop.io$document ||redlotusevents.com$document +||redm1az1.000webhostapp.com$document ||redmag.by$document ||redmanns-way.com/jeff-intervention-txqikkf/engines/$document ||redmarcial.ossmarcial.com$document @@ -547229,6 +547502,7 @@ ||rkcable.co.in$document ||rkfplumbing.co.uk$document ||rkinstitute.org$document +||rkkrstdygorgiousejbg.dns.army$document ||rkkrstdygorgiousejds.dns.army$document ||rkkrstdygorgiousejtw.dns.army$document ||rklkpgcollege.com$document @@ -547800,6 +548074,7 @@ ||rotoblast.org$document ||rotor.olsztyn.pl$document ||rotoscoop.com$document +||rotronics.com.ph$document ||rott-mtr.de$document ||rotterdammeetings.nl$document ||rotulosalarcon.com$document @@ -548223,7 +548498,7 @@ ||runmureed.com$document ||runmyweb.com$document ||runnected.kaiman.fr$document -||runnerbd.com$document +||runnerbd.com/newsletter/en/new-order-upcoming/hri-monthly-invoice/$document ||runnerschool.com$document ||running-bike.com$document ||runningcrewteam.com$document @@ -549987,7 +550262,7 @@ ||savemyfile.3utilities.com$document ||savemyseatnow.com$document ||saveraahealthcare.com$document -||saveserpnow.com/install6.exe$document +||saveserpnow.com$document ||saveserpresults.com$document ||savestudio.com$document ||savetax.idfcmf.com$document @@ -550710,6 +550985,7 @@ ||secure-web.cisco.com/12p009aocmii6iiuifqwgjpcu-ewgqlh2h4pycujvqyyjdohuhrgob5qmrolhcqr9n-pbdoznxvkopqofjrmcqy3gfwuj1ncre4meocugzr7ugdrxzjszl0b6pteou6fmdsru5wkh-qxded6wnpabjahxl4f4s_3tsq2grwblnjvljmbcbd5ibddpp1gnqsn5l1mih_hvf4bu54lqudh2japy0nxrdq1uwbhxrm0quhdebucbhdpo1ljxudy-27k2q5k9ou2n4l-gx4yemlbzmlofuz1df6nbqrlicsbpu5jr3dopul0acmfrbb-81lmomroc3fvvoa3bqpqdbxh3dlilolz7d7rwdozhmj8t31iid32byxqvsz2a94jsdhh9fcmb14cbi_w87ulqbgiouomra-9jqitmh1qeskzybv_i2rqadqpqkxnkmuuonvujbyhea8h3hgsc1nzsjrklwbziejw9rgppqghinmhxxky-5zzws52dx_-dphrfzlneslgrotnwhduh6y2w9dyrkw/http%3a%2f%2fsunkids.dp.ua%2fwp-admin%2fsecure.accs.docs.com%2f/$document ||secure-web.cisco.com/1vypgccgybkpf1prxej5fch8svg1xkv3nb66tqfrxc7b-vvmo2x8ynyl6ve6p1hwliztoeqwvhtiuwhztww5t2lr5vpbiq1dn3u1vjqp1tvxya02acmwwop-on54zcaz5navelmk7-v6zttoqfoxvtwlgki6y4fhgvtvhyxpbb4yl3cdoqq_ls0op2xlollina9lzbkmsf3qnomb7u7fet03ntqq9zachjl14--vqb16lmwxgany-cfcl8fdbak2uatzcnrcfkqjdw4xsdlqlvdf0lf747nwb76rt0f6h-mkxb3vfytjqjqqlhkgpyt0ekwkujzekgwjspvmakcm-pq/https%3a%2f%2fwww.dropbox.com%2fs%2fm02dp4122ei0p50%2fcertificate%25208205.doc%3fdl%3d1/$document ||secure.accounts.resourses.com$document +||secure.activedirect.xyz$document ||secure.anchorssb.co$document ||secure.app-amazon.com.recovery-account.amazon.com.alphatravelmongolia.com$document ||secure.bodybuilderabs.net$document @@ -551439,7 +551715,7 @@ ||service.dawat.fr$document ||service.drnjithendran.com$document ||service.eftformotherissues.com$document -||service.ezsoftwareupdater.com$document +||service.ezsoftwareupdater.com/updates/2/whsetup.exe$document ||service.heritageimagingcenter.com$document ||service.hybridhomesteam.com$document ||service.idealfurnitureoutlet.com$document @@ -551955,13 +552231,7 @@ ||sharebook.tk$document ||sharechautari.com$document ||shared-cnd.com$document -||shared.outlook.inky.com/link?domain=laminingraphics.co.za/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdkf9pwjauxb9ln5hjbon4qkunbsodf5yts8jdeqgdvr1pn8aav7vfxbdfzz3n3f_of2srsak2zntlwfty7ihqqgpyjyntojwg2xgp2mgpyfajzddjcwgjbak6tqgmvbpdv2oohekx6btusc6gijnte3tjiioihr4zzq4wjljvv3vfqxgdjzcgwqwicg2hkqlqsdz8lbtsirq7jscmbypadgxnsxdzoqrznkesheikdj2tei1o6zaddmw67fk35d7bpbgki1ks12wcy6b_qsrlnpipxcwku3a7nl4m-hp2xtshey9fkfpvmqdzzh3q_gbip4dh_vxw4eupo-4f48u08_n6cqmynuo7qwkldycerecc25x00_qjjwg8tp7p-rvs9w8veomv.meucihnyythleerey63ykklm6wi3yajo85mjvegtysle7fhbaieanqqjbjnskm2wmbtocdroz8yldff_ab3ipunej1yo3qo/$document -||shared.outlook.inky.com/link?domain=laminingraphics.co.za/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxtue1rwkaq_s97tgyvdwykwkykxvwkqwlcqkab0wzc2ytdjdau_veupzaehuhn-5j3xrwcyzkf7cg1aihneqinfmagtgqhroni4rguxqfdf0dgzuikps1banhya2nuezuldkvdnntx-h_pjfdilxotdyugcjr31l7iqftjyf3vsiciulypuhqkcdaxiirau7dvlnsdugpmkopgdgov6nvgputdmcfvzem0ztmzzelicvj19jrrin2ynvwxfljxu1xefldczep9jafy5e8vbtao_d5z635t8wqx5x1048vfelvkpvkqjp48eafdhfms85sptslervvitzhhy-zg6-eo16fh-3cwzqejpdpawrq01ufsupyhvxpqcp63399svn8akcagug.meucie6d9mxuzck5v8rhoqlm3oksbgukynxeilyxhhowpoq2aieagl_05exfu06imv0cnpgztc9get1eg-yy5b42-7fmdhm//$document -||shared.outlook.inky.com/link?domain=www.toziba.ir&t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdkn1ugkauhn9lry0ekk31svpn2wherrfcqg6wyq67omsiqtn373lvpjdfmmdmznwjiygtas3qgvrq5bg-amec5iamifqsiwoymh2anxicsnjjkd1ukpap93mohgmivdlr4y9aow5qkew5msv6onddp8l6iblorcg830hbszxowukuwx7hircdvex4iw2v-9xdf2xpnxzemw-71orev5b-fs2qlrejkqxaifogr1ilgkrmgb5z1kahtepwiuehwxloalr5ustmro3ng8tpzxxcu8y4xzizlrnw10poluvuxbpn1hldlr0nuehsdxjtx4wvu8npimwvgr--ws51b17aqp8yvxnugfza6b1gzszpyh4_brbi8bhackuhcnootvsiqypdyv5_wy2vofr5bwmpgle.meuciqdwg66mmqf8atpdht-lpyuss3dbd_soh1bljxzzbxwc1aigv1wkcnavv4nw3os570ta3z-muscagqqnti3dgc9p6js/$document -||shared.outlook.inky.com/link?domain=www.toziba.ir&t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxduf1vgjau_s99dqa4t-mtbcbortbrpqqhireoqmmllilisv--8rrkj-fm3pp1jrqbxuzogu6lajgr-gscydidneklueqkyghxataqeskap0d1icdpx5-xhepmyfztb4u_1er9gwqlls0inmoz6zpd1y8ybaougl6eioelie1pd1fvuhzk2mfxau_wb173mbp_9kvnloytl6c1ida15m5hc9eynkkqkaruwsinajexjjmyy87akjxrhm55fe5yxhmndvmrtoiww3ewve8cwlmrcpelfi7smoghdistd2_pyu4jwk0iz-ncvdrjbzn2vt13vv4de76-4cqhacp8i-kpt7tl7cfos3vxc_otje5d44bihawljjdnkjsnzktprjwzkcv_2xpzzdhpl9e5g6k.meucigd6xwariut2lkiettiajcosxyluv7ub6nhbepewswmwaiea4mzpunjaca7lslweyqnda4gpvqjwhufuenzur1jmp64/$document -||shared.outlook.inky.com/link?domain=www.toziba.ir&t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdunfugkaq_jd7tqby28qtte2siucq4akhiquccnh36heusom_93hq0odndjazm7p7jrqbtgtkoxmvihjsn4atsxnae0sfiliaq_yjwemmigieajwaghr4flxxomyqraaocn-olxohlupdgzsxe7prokpvd5qbqawg1wcoobwjkz3ufhzxrsqdhoeov97zesjd3ud42czjzno6tbykppb0q2sllrejuqukofjgvoh2meqyo3nmwrvhrrxjjy_wjowcvdf-eyutqxtbpcsvrxzwosy4xzirljn8gab75zz7x9l-wuzbwemg7on1all8m9bux-5uz2yu_7siifpeuvfexnqvcu5-4aze-6xfvs5svlghmixjb1iockmarmeqzkscgzgr_7818pqjn19jvyhz.meyciqdjb9hlkixl4sz_rt8-tj8v7t6tzcbxfjgcuyhbc8ixuwihapwstswmgpu_k43h-va03ffjltif7n-k3qrucylug8il/$document -||shared.outlook.inky.com/link?domain=www.toziba.ir/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxduf1vgjau_s99dqa4t-mtbcbortbrpqqhireoqmmllilisv--8rrkj-fm3pp1jrqbxuzogu6lajgr-gscydidneklueqkyghxataqeskap0d1icdpx5-xhepmyfztb4u_1er9gwqlls0inmoz6zpd1y8ybaougl6eioelie1pd1fvuhzk2mfxau_wb173mbp_9kvnloytl6c1ida15m5hc9eynkkqkaruwsinajexjjmyy87akjxrhm55fe5yxhmndvmrtoiww3ewve8cwlmrcpelfi7smoghdistd2_pyu4jwk0iz-ncvdrjbzn2vt13vv4de76-4cqhacp8i-kpt7tl7cfos3vxc_otje5d44bihawljjdnkjsnzktprjwzkcv_2xpzzdhpl9e5g6k.meucigd6xwariut2lkiettiajcosxyluv7ub6nhbepewswmwaiea4mzpunjaca7lslweyqnda4gpvqjwhufuenzur1jmp64//$document -||shared.outlook.inky.com/link?domain=www.toziba.ir/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdunfugkaq_jd7tqby28qtte2siucq4akhiquccnh36heusom_93hq0odndjazm7p7jrqbtgtkoxmvihjsn4atsxnae0sfiliaq_yjwemmigieajwaghr4flxxomyqraaocn-olxohlupdgzsxe7prokpvd5qbqawg1wcoobwjkz3ufhzxrsqdhoeov97zesjd3ud42czjzno6tbykppb0q2sllrejuqukofjgvoh2meqyo3nmwrvhrrxjjy_wjowcvdf-eyutqxtbpcsvrxzwosy4xzirljn8gab75zz7x9l-wuzbwemg7on1all8m9bux-5uz2yu_7siifpeuvfexnqvcu5-4aze-6xfvs5svlghmixjb1iockmarmeqzkscgzgr_7818pqjn19jvyhz.meyciqdjb9hlkixl4sz_rt8-tj8v7t6tzcbxfjgcuyhbc8ixuwihapwstswmgpu_k43h-va03ffjltif7n-k3qrucylug8il//$document +||shared.outlook.inky.com$document ||shared.pdffiller.com/1395f7beaf30f1943ac9e1b9800a8fbf/8c7dd922ad47494fc02c388e12c00eac/cdecfead5bd78cb1c29f931bc49ad2db.exe?t=1549302986$document ||shareddocuments.ml$document ||shareddynamics.com$document @@ -556488,9 +556758,11 @@ ||stdymjventsluzcafsrp.dns.army$document ||stdymorcmmylntwincdq.dns.army$document ||stdymorcmmylntwinstr.dns.army$document +||stdynbnbnewagedevixz.dns.army$document ||stdynbnbnewagedevsmn.dns.army$document ||stdynbnbnewagedevxaz.dns.army$document ||stdyneverwalkachinese2loneinlifekstgqm.ydns.eu$document +||stdynmxwllminoragest.dns.army$document ||stdyperezluzcafeyzst.dns.navy$document ||stdypmrimelimtwstogy.dns.army$document ||stdypycsslwinnerscot.dns.army$document @@ -556521,6 +556793,7 @@ ||stdytopreoneenversrw.dns.army$document ||stdytopreoneenvervaj.dns.army$document ||stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu$document +||stdyunitedkesokokgst.dns.army$document ||stdyunitedkesokostdr.dns.army$document ||stdyunitedkesokostri.dns.navy$document ||stdyunitedkesokostxc.dns.army$document @@ -556530,7 +556803,9 @@ ||stdyworkfineanotherrainbowlomoyentwkgls.duckdns.org$document ||stdyworkfinesanotherrainbowlomoyentstfcp.ydns.eu$document ||stdyworkfinesanotherrainbowlomoyentstgot.ydns.eu$document +||stdyworkfinetraingst.dns.army$document ||stdyzgchgcloudgostgt.dns.army$document +||stdyzgchgcloudgostxs.dns.army$document ||steadyrestmanufacturers.com$document ||steak.wpress.dk$document ||steakhouse.com.ua$document @@ -558724,7 +558999,7 @@ ||strengthandvigour.com$document ||strengthrer.com$document ||strenover.ga$document -||stressing.pw/spike/svchost.exe$document +||stressing.pw$document ||stressnada.com$document ||stretchpilates.fit$document ||strewn.org$document @@ -559434,8 +559709,7 @@ ||supercutscissors.com$document ||superdad.id$document ||superdigitalguy.xyz$document -||superdomain1709.info/c4fxp3oiuoyf.67w$document -||superdomain1709.info/kuycdsjte.jdz$document +||superdomain1709.info$document ||superdot.rs$document ||superecruiters.com$document ||superfacil.center$document @@ -559544,7 +559818,9 @@ ||support.mdsol.com$document ||support.nordenrecycling.com$document ||support.nuvemit.com$document -||support.pubg.com$document +||support.pubg.com/attachments/token/t6cno6ywz3wf4svnnwt5weowd/$document +||support.pubg.com/attachments/token/t6cno6ywz3wf4svnnwt5weowd/?name=hsjloader.exe$document +||support.pubg.com/attachments/token/t6cno6ywz3wf4svnnwt5weowd?name=hsjloader.exe$document ||support.redbook.aero$document ||support.revolus.xyz$document ||support.servu.co.uk$document @@ -559905,7 +560181,7 @@ ||swicoservers.co.uk$document ||swieradowbiega.pl$document ||swifck.xmr.ac$document -||swift-cloud.com$document +||swift-cloud.com/storage/doc/statement.doc$document ||swiftbusinesspay.com$document ||swiftee.co.uk$document ||swiftender.com$document @@ -560828,7 +561104,11 @@ ||targas.de$document ||targat-china.com$document ||target-events.com$document -||target-support.online$document +||target-support.online/exe/softsetting.exe$document +||target-support.online/old/upload/ddd5.exe$document +||target-support.online/old/upload/emter.exe$document +||target-support.online/old/upload/socks.exe$document +||target-support.online/old/upload/test32.exe$document ||target2cloud.com$document ||targetbizbd.com$document ||targetcm.net$document @@ -562443,7 +562723,9 @@ ||thachastew.com$document ||thachvietstone.com$document ||thadathilfarmresort.com$document -||thaddeusarmstrong.com$document +||thaddeusarmstrong.com/wp-content/txxwd-me7gh-slgzwqla/$document +||thaddeusarmstrong.com/wp-content/txxwd-me7gh-slgzwqla//$document +||thaddeusarmstrong.com/wp-content/wrx/$document ||thadinnoo.co$document ||thagreymatter.com$document ||thai-chana.asia$document @@ -564243,7 +564525,17 @@ ||tlcid.org$document ||tlckids-or.ga$document ||tlcmoto.com$document -||tldrbox.top$document +||tldrbox.top/1.exe$document +||tldrbox.top/11.exe$document +||tldrbox.top/2$document +||tldrbox.top/2.exe$document +||tldrbox.top/3$document +||tldrbox.top/32.exe$document +||tldrbox.top/4$document +||tldrbox.top/5$document +||tldrbox.top/6$document +||tldrbox.top/64.exe$document +||tldrbox.top/v$document ||tldrnet.top$document ||tlextreme.com$document ||tlfthelifefactory.com.au$document @@ -565921,7 +566213,7 @@ ||ts.7rb.xyz$document ||ts0ev73.com$document ||tsal.com$document -||tsapparel.com.my/fd66e6.php$document +||tsapparel.com.my$document ||tsareva-garden.ru$document ||tsatsi.co.za$document ||tsauctions.com$document @@ -566158,7 +566450,7 @@ ||tunnelview.co.uk$document ||tunuvo.com$document ||tuobrasocial.com.ar$document -||tuoitrethainguyen.vn/moah-ky0x_u-t9/invoice/en_en/new-order/$document +||tuoitrethainguyen.vn$document ||tupibaje.com$document ||tupperware.michaelroberge.ca$document ||tur.000webhostapp.com$document @@ -567972,7 +568264,9 @@ ||unlimited.nu$document ||unlimitedbags.club$document ||unlimitedfreightco.com$document -||unlimitedimportandexport.com$document +||unlimitedimportandexport.com/wp-content/plugins/all-in-one-wp-migration/lib/bread.exe$document +||unlimitedimportandexport.com/wp-content/plugins/all-in-one-wp-migration/lib/cvxjr.exe$document +||unlimitedimportandexport.com/wp-content/plugins/all-in-one-wp-migration/lib/jkzse.exe$document ||unlock-king.com$document ||unlock2.neagoeandrei.com$document ||unlockall.neagoeandrei.com$document @@ -568362,7 +568656,7 @@ ||url.emailprotection.link/?bgmvicpuho15c9_q9hiofgnmkaco0q_lujjcaeowkfik_hdtt1uqmbkpovhxykckgjoqoytv_u0g2umkhd4mbi9ms8vo3vliq2clouuaa6no2a7ij5ljfsouoeememvmi/$document ||url.emailprotection.link/?bizyxbw1fdagsfcc1n6ep1awpdx9dr0brnjjqwgyaofpw98limviipvrszjnzzluclpeqqdywfxwnwudvwrljcufuhl2_nha0bs8wz9jmbahcciikbseljewayzbe_cnd/$document ||url.sg/rwtho$document -||url2.mailanyone.net/v1/?m=1hibcm-0003zv-63&i=57e1b682&c=sb1blj46bk32u6f729r5t_slvkx-heewxh20_zdn9-3ktcc0-kn35fykilpydgeyvrbwqwb5h__fk383wtdakqftjlelxz06jbaglri5jmujnydjkasqxwdtg2hn-_be1dzrnthvvhigyhm_tvbew342habp8dtit9jjlieuc2x-ipgdgipe7y_c9jhe69532gmnxozb5wifjfbstzicagmtpg6yxmreaf0sq2dgo-ksy54hetfhn6gwm4kiw2vvcqx17a9bm6ykn8bwpwdjwg/$document +||url2.mailanyone.net$document ||url3.mailanyone.net$document ||url5459.41southbar.com$document ||url675.textilmallorca.com$document @@ -568605,7 +568899,32 @@ ||utting.org$document ||utv.sakeronline.se$document ||utv1.enliden.net$document -||uujian.cn$document +||uujian.cn/browser/apk/100-2.9.apk$document +||uujian.cn/browser/apk/101-2.9.1.apk$document +||uujian.cn/browser/apk/102-2.9.2.apk$document +||uujian.cn/browser/apk/103-2.9.3.apk$document +||uujian.cn/browser/apk/104-2.9.4.apk$document +||uujian.cn/browser/apk/105-2.9.5.apk$document +||uujian.cn/browser/apk/106-2.9.6.apk$document +||uujian.cn/browser/apk/107-2.9.7.apk$document +||uujian.cn/browser/apk/108-2.9.8.apk$document +||uujian.cn/browser/apk/88-2.7.apk$document +||uujian.cn/browser/apk/89-2.7.1.apk$document +||uujian.cn/browser/apk/90-2.7.2.apk$document +||uujian.cn/browser/apk/91-2.7.3.apk$document +||uujian.cn/browser/apk/92-2.7.4.apk$document +||uujian.cn/browser/apk/93-2.7.5.apk$document +||uujian.cn/browser/apk/94-2.8.apk$document +||uujian.cn/browser/apk/95-2.8.1.apk$document +||uujian.cn/browser/apk/96-2.8.2.apk$document +||uujian.cn/browser/apk/97-2.8.3.apk$document +||uujian.cn/browser/apk/98-2.8.4.apk$document +||uujian.cn/browser/apk/99-2.8.5.apk$document +||uujian.cn/browser/apk/beta.apk$document +||uujian.cn/browser/apk/browser-l.apk$document +||uujian.cn/browser/apk/browser.apk$document +||uujian.cn/browser/apk/m3u8loader.apk$document +||uujian.cn/browser/apk/test.apk$document ||uumove.com$document ||uurty87e8rt7rt.com$document ||uutiset.helppokoti.fi$document @@ -570633,7 +570952,7 @@ ||voingani.it$document ||voip96.ru$document ||voipminic.com$document -||vokasi.ub.ac.id$document +||vokasi.ub.ac.id/wuk/kuqyslbgavnwlmcuk0qalhxifzp4mgze8anlcewu1pa8fw4lfex0y/$document ||vokzalrf.ru$document ||vol.agency$document ||vol2.pw$document @@ -571273,7 +571592,9 @@ ||washuis.nl$document ||wasidora.com$document ||wasilewski-online.de$document -||wasimjee.com$document +||wasimjee.com/wp-content/themes/host/languages/kia.zip$document +||wasimjee.com/wp-content/themes/host/languages/msg.jpg$document +||wasimjee.com/wp-content/themes/host/ordomain/msg.jpg$document ||wasino.co.th$document ||wasobd.net$document ||waspha.com$document @@ -572878,7 +573199,8 @@ ||woatinkwoo.com$document ||woclawoffers.fun$document ||wocomm.marketingmindz.com$document -||wodfitapparel.fr$document +||wodfitapparel.fr/wp-content/themes/cleayn/6o00s4g8/$document +||wodfitapparel.fr/wp-content/themes/fagri/oknuyqlfr/$document ||wodmetaldom.pl$document ||wodsuit.com$document ||woelf.in$document @@ -575596,9 +575918,9 @@ ||yoyoso.nz$document ||yoyoteacher.cn$document ||yp.dcyazilim.com$document -||yp.hnggzyjy.cn/common/yz.vbs$document +||yp.hnggzyjy.cn$document ||ypbb.or.id$document -||ypddf.org/en/nr/$document +||ypddf.org$document ||ypicsdy.cf$document ||ypko-55.gq$document ||ypom.com.br$document @@ -575762,7 +576084,9 @@ ||yuti.kr$document ||yuvann.com$document ||yuvikadvertisments.com$document -||yuwaraja.vokasi.ub.ac.id$document +||yuwaraja.vokasi.ub.ac.id/vendors/https://document/4tb6lng9d2aaadfd/$document +||yuwaraja.vokasi.ub.ac.id/vendors/https:/document/4tb6lng9d2aaadfd/$document +||yuwaraja.vokasi.ub.ac.id/vendors/overview/5utm325651630390125u6bd6ce4nkpml62pph/$document ||yuweis.com$document ||yuxigon.com$document ||yuxuanknit.com$document diff --git a/urlhaus-filter.tpl b/urlhaus-filter.tpl index 7e27b3bc..374f4c93 100644 --- a/urlhaus-filter.tpl +++ b/urlhaus-filter.tpl @@ -1,6 +1,6 @@ msFilterList # Title: Malicious Hosts Blocklist (IE) -# Updated: Mon, 12 Apr 2021 00:12:54 UTC +# Updated: Mon, 12 Apr 2021 12:13:00 UTC # Expires: 1 day (update frequency) # Homepage: https://gitlab.com/curben/urlhaus-filter # License: https://gitlab.com/curben/urlhaus-filter#license @@ -1441,7 +1441,6 @@ msFilterList -d 649924.nchsoftwarecom.com -d 64x9bg.ch.files.1drv.com -d 650x.com --d 654tyfcdr4654fytfy.top -d 65k2.com -d 66-gifts.com -d 662ekeep6.com @@ -1479,7 +1478,6 @@ msFilterList -d 6gue98ddw4220152.freebackup.site -d 6hffgq.dm.files.1drv.com -d 6hu.xyz --d 6ip.us -d 6iptv.com -d 6itokam.com -d 6kd743o1w.com @@ -1872,7 +1870,6 @@ msFilterList -d a.doko.moe -d a.gg.fm -d a.heritageandterre.com --d a.pomf.cat -d a.pomf.se -d a.pomf.space -d a.pomf.su @@ -6586,7 +6583,6 @@ msFilterList -d anmocnhien.vn -d anmolanwar.com -d ann141.net --d anna.websaiting.ru -d annaaluminium.annagroup.net -d annabelle-hamande.be -d annabphotography.co.uk @@ -7101,6 +7097,7 @@ msFilterList -d app.boxrcdn.com -d app.bridgeimpex.org -d app.calag.at +-d app.casetabs.com -d app.catholicchurch.co.in -d app.choiphui.com -d app.cloudindustry.net @@ -9007,6 +9004,7 @@ msFilterList -d atphitech.com -d atpn.ir -d atprofessional.org +-d atpscan.global.hornetsecurity.com -d atr.it -d atradex.com -d atragon.co.uk @@ -9767,6 +9765,8 @@ msFilterList -d awsxb.xyz -d awsyscloud.com -d awtinfostore.co.business +-d awumad01.top +-d awuqze02.top -d ax-yogado.com -d axalize.vn -d axalta.grupojenrab.mx @@ -11164,6 +11164,7 @@ msFilterList -d bbfr.cba.pl -d bbgiardinodoriente.it -d bbgk.de +-d bbgroup.com.vn -d bbh-design.de -d bbhdata.com -d bbhs.org.ng @@ -11603,7 +11604,6 @@ msFilterList -d bel-med-tour.ru -d belabargelro.com -d belair.btwstudio.ch --d belairinternet.com -d belamater.com.br -d belangel.by -d belanja-berkah.xyz @@ -11722,7 +11722,6 @@ msFilterList -d belz-development.de -d belznerdesign.de -d bem.fkep.unpad.ac.id --d bem.hukum.ub.ac.id -d bem.unimal.ac.id -d bemagazine.club -d bemakeup.ru @@ -12495,6 +12494,7 @@ msFilterList -d bierne-les-villages.fr -d biese.eu -d bietthubien.org +-d bietthudep902.com -d bietthulambach.com -d bietthulienkegamuda.net -d bietthumau.com @@ -16390,7 +16390,6 @@ msFilterList -d callpetercatering.com -d callrealtyaz.com -d callshaal.com --d callsmaster.com -d calltoprimus.ru -d callumstokes.com -d calm-tech.africa @@ -17650,7 +17649,6 @@ msFilterList -d cdndownloadlp.club -d cdnmultimedia.com -d cdnpic.mgyun.com --d cdnrep.reimageplus.com -d cdnxh.net -d cdoconsult.com.br -d cdolechon.com @@ -18442,7 +18440,6 @@ msFilterList -d cheematransxpressinc.com -d cheerchile.cl -d cheerfulgiversneverlack.com --d cheerfullydo.com -d cheesecakery.com.br -d cheetahridge.mediadevstaging.com -d chef-solutions.dreamscape.co.in @@ -19373,6 +19370,7 @@ msFilterList -d clarte-thailand.com -d clashofclansgems.nl -d clasificados.diaadianews.com +-d clasificadosmaule.com -d class.britishonline.co -d class.snph.ir -d classbrain.net @@ -19670,6 +19668,7 @@ msFilterList -d cloakingtds.xyz -d clock.noixun.com -d clodflarechk.com +-d clodura.ai -d clone.affordable.cm -d clone.system-standex.dk -d cloned.in @@ -19855,7 +19854,6 @@ msFilterList -d cmecobrancas.com -d cmelik.com -d cmessagers.com --d cmg.asia -d cmg.ma -d cmgroup.com.ua -d cmhighschool.edu.bd @@ -22394,7 +22392,6 @@ msFilterList -d cuadros.pe -d cuahangphongthuy.net -d cuahangstore.com --d cuahangvattu.com -d cualtis.com -d cuanhomxingfanhapkhau.com -d cuasotinhoc.net @@ -22823,6 +22820,7 @@ msFilterList -d d.qiluwl.com -d d.teamworx.ph -d d.techmartbd.com +-d d.top4top.io -d d.top4top.net -d d.ttr3p.com -d d04.data39.helldata.com @@ -24804,6 +24802,7 @@ msFilterList -d deposayim.ml -d depositoclara.com.br -d depot7.com +-d depozituldegeneratoare.ro -d depraetere.net -d deprealty.ru -d depressionted.com @@ -26530,7 +26529,6 @@ msFilterList -d dl-675423.store-downloads.com -d dl-80076342.md-downloads.com -d dl-97674424.md-downloads.com --d dl-gameplayer.dmm.com -d dl-link.link -d dl-link.live -d dl-link.network @@ -26553,9 +26551,9 @@ msFilterList -d dl.imht.ir -d dl.installcdn-aws.com -d dl.mqego.com --d dl.mydown.com -d dl.ossdown.fun -d dl.packetstormsecurity.net +-d dl.pandasecur.com -d dl.popupgrade.com -d dl.repairlabshost.com -d dl.rina-roleplay.com @@ -26732,6 +26730,9 @@ msFilterList -d dobroviz.com.ua -d dobrovorot.su -d dobsoncentral.com +-d doc-0s-7c-docs.googleusercontent.com +-d doc-10-0c-docs.googleusercontent.com +-d doc-10-8s-docs.googleusercontent.com -d doc-hub.healthycheapfast.com -d doc-japan.com -d doc.albaspizzaastoria.com @@ -29006,6 +29007,7 @@ msFilterList -d ec2-54-207-92-161.sa-east-1.compute.amazonaws.com -d ec2-54-212-231-68.us-west-2.compute.amazonaws.com -d ec2-54-94-215-87.sa-east-1.compute.amazonaws.com +-d ec2euc1.boxcloud.com -d ec2test.ga -d ec3-design.com -d ecadigital.com @@ -31306,6 +31308,7 @@ msFilterList -d esaarc.com -d esacbd.com -d esagarautomobiles.com +-d esaja09.top -d esanjobs.org -d esar.weenets.com -d esascom.com @@ -37100,7 +37103,6 @@ msFilterList -d genrjw.dm.files.1drv.com -d genstaff.gov.kg -d gentcreativa.com --d gentecoyol.com -d gentesanluis.com -d gentiane-salers.com -d gentlechirocenter.com @@ -39849,6 +39851,7 @@ msFilterList -d gvpcdpgc.edu.in -d gvpmacademy.co.za -d gvsme.com +-d gw.daelimcloud.com -d gw.hitlin.com -d gwangjuhotels.kr -d gwavellc.com @@ -42660,7 +42663,6 @@ msFilterList -d hotelwaldblick.com -d hotexpress.co -d hotfacts.org --d hotgifts.online -d hotilife.com -d hotissue.xyz -d hotkine.com @@ -43038,7 +43040,6 @@ msFilterList -d hukuen-motokare.xyz -d hukuki.site -d hukukportal.com --d hukum.ub.ac.id -d hukum.unwiku.ac.id -d hulianwang114.com -d huliot.in @@ -43360,6 +43361,7 @@ msFilterList -d i-supportcharity.com -d i-vnsweyu.pl -d i-voda.com +-d i.fiery.me -d i.fluffy.cc -d i.funtourspt.eu -d i.n.t.e.rloca.l.qs.j.y@jfas.top @@ -46640,6 +46642,7 @@ msFilterList -d itspsc.com.ua -d itspueh.nl -d itsquare.yrcreations.com +-d itsrlytry.000webhostapp.com -d itssprout.com -d itstelecom.com.br -d itsweezle.com @@ -46839,6 +46842,7 @@ msFilterList -d j-stage.jp -d j-toputvoutfitters.com -d j.kyryl.ru +-d j.top4top.io -d j11g9xecuxe43xu.xyz -d j12z7407gwtzk.xyz -d j13.biz @@ -46971,6 +46975,7 @@ msFilterList -d jaipurweddingphotography.com -d jairathsnatural.ca -d jairozapata.000webhostapp.com +-d jaishomo.info -d jaishritours.com -d jaiswalsupplement.com -d jajadomains.com @@ -50999,7 +51004,6 @@ msFilterList -d kodim0112sabang.com -d kodingeko.com -d kodip.nfile.net --d kodjdsjsdjf.tk -d kodlacan.site -d kodmuje.com -d kodolios.000webhostapp.com @@ -53639,6 +53643,7 @@ msFilterList -d library.cifor.org -d library.dhl-xom.com -d library.iainbengkulu.ac.id +-d library.mju.ac.th -d library.phibi.my.id -d library.piet.co.in -d library.strophicmusic.com @@ -54325,7 +54330,6 @@ msFilterList -d livecigarevent.com -d livecricketscorecard.info -d livedaynews.com --d livedemo00.template-help.com -d livedownload.in -d livedrumtracks.com -d livefarma.com @@ -54358,7 +54362,6 @@ msFilterList -d livestreams.vn -d livesuitesapartdaire.com -d livesurgerycourse.ir --d liveswinburneeduau-my.sharepoint.com -d liveswindow.casa -d liveswindow.cyou -d liveswindows.bar @@ -55533,7 +55536,6 @@ msFilterList -d luzconsulting.com.br -d luzevida.com.br -d luzfloral.com --d luzy.vn -d luzzeri.com -d lvajnczdy.cf -d lvcfund.org.vn @@ -58571,7 +58573,6 @@ msFilterList -d mecgwl.ac.in -d mechanicaltools.club -d mechanicsthatcometoyou.com --d mecharnise.ir -d mechathrones.com -d mechauto.co.za -d mechdesign.com @@ -59157,7 +59158,6 @@ msFilterList -d menziesadvisory-my.sharepoint.com -d menzway.com -d meogiambeo.com --d meohaybotui.com -d meolamdephay.com -d mepsgen.com -d mera.ddns.net @@ -59475,6 +59475,7 @@ msFilterList -d mfomjr.com -d mfotovideo.ro -d mfpburundi.bi +-d mfpc.org.my -d mfppanel.xyz -d mfpvision.com -d mfronza.com.br @@ -64507,7 +64508,6 @@ msFilterList -d nhadatquan2.xyz -d nhadatthienthoi.com -d nhadephungyen.com --d nhadepkientruc.net -d nhahangdaihung.com -d nhahanghaivuong.vn -d nhahanglegiang.vn @@ -64721,7 +64721,6 @@ msFilterList -d nikanpolimer.ir -d nikastroi.ru -d nikavkuchyni.sk --d nikayu.com -d nikbox.ru -d nikeshyadav.com -d nikhil.webscript.co.in @@ -67237,7 +67236,6 @@ msFilterList -d option47.us -d optioncapitalgroup.ru -d optionrp.com --d optionscity.com -d optisaving.com -d optitechsa.co.za -d optocen.ru @@ -67532,7 +67530,6 @@ msFilterList -d osezrayonner.ma -d osgbforum.com -d oshattorney.com --d oshi.at -d oshodrycleaning.com -d oshonafitness.com -d oshop.es @@ -71232,7 +71229,6 @@ msFilterList -d posmicrosystems.com -d posnxqmp.ru -d pospeeps.com --d posqit.net -d possessionnow.com -d possible.re -d possopagar.com.br @@ -71868,7 +71864,6 @@ msFilterList -d prisidmart.com -d priskat.net -d prism-photo.com --d prisma.fp.ub.ac.id -d prismaxis.com -d prismfox.com -d prismware.ml @@ -72460,6 +72455,7 @@ msFilterList -d protech.mn -d protechcarpetcare.com -d protechgroup1.com +-d protect.mimecast-offshore.com -d protectiadatelor.biz -d protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org -d protection.pecol.eu @@ -72541,6 +72537,7 @@ msFilterList -d proxy-ipv4.com -d proxy.2u0apcm6ylhdy7s.com -d proxy.hueaudio.com +-d proxy.qualtrics.com -d proxygrnd.xyz -d proxyholding.com -d proxyresume.com @@ -75054,6 +75051,7 @@ msFilterList -d redlogisticsmaroc.com -d redloop.io -d redlotusevents.com +-d redm1az1.000webhostapp.com -d redmag.by -d redmarcial.ossmarcial.com -d redmediasigns.com @@ -76225,6 +76223,7 @@ msFilterList -d rkcable.co.in -d rkfplumbing.co.uk -d rkinstitute.org +-d rkkrstdygorgiousejbg.dns.army -d rkkrstdygorgiousejds.dns.army -d rkkrstdygorgiousejtw.dns.army -d rklkpgcollege.com @@ -76781,6 +76780,7 @@ msFilterList -d rotoblast.org -d rotor.olsztyn.pl -d rotoscoop.com +-d rotronics.com.ph -d rott-mtr.de -d rotterdammeetings.nl -d rotulosalarcon.com @@ -77194,7 +77194,6 @@ msFilterList -d runmureed.com -d runmyweb.com -d runnected.kaiman.fr --d runnerbd.com -d runnerschool.com -d running-bike.com -d runningcrewteam.com @@ -78716,6 +78715,7 @@ msFilterList -d savemyfile.3utilities.com -d savemyseatnow.com -d saveraahealthcare.com +-d saveserpnow.com -d saveserpresults.com -d savestudio.com -d savetax.idfcmf.com @@ -79393,6 +79393,7 @@ msFilterList -d secure-risk.namaskara.me -d secure-snupa.com -d secure.accounts.resourses.com +-d secure.activedirect.xyz -d secure.anchorssb.co -d secure.app-amazon.com.recovery-account.amazon.com.alphatravelmongolia.com -d secure.bodybuilderabs.net @@ -80070,7 +80071,6 @@ msFilterList -d service.dawat.fr -d service.drnjithendran.com -d service.eftformotherissues.com --d service.ezsoftwareupdater.com -d service.heritageimagingcenter.com -d service.hybridhomesteam.com -d service.idealfurnitureoutlet.com @@ -80575,6 +80575,7 @@ msFilterList -d sharebook.tk -d sharechautari.com -d shared-cnd.com +-d shared.outlook.inky.com -d shareddocuments.ml -d shareddynamics.com -d sharedeconomy.eu @@ -84938,9 +84939,11 @@ msFilterList -d stdymjventsluzcafsrp.dns.army -d stdymorcmmylntwincdq.dns.army -d stdymorcmmylntwinstr.dns.army +-d stdynbnbnewagedevixz.dns.army -d stdynbnbnewagedevsmn.dns.army -d stdynbnbnewagedevxaz.dns.army -d stdyneverwalkachinese2loneinlifekstgqm.ydns.eu +-d stdynmxwllminoragest.dns.army -d stdyperezluzcafeyzst.dns.navy -d stdypmrimelimtwstogy.dns.army -d stdypycsslwinnerscot.dns.army @@ -84971,6 +84974,7 @@ msFilterList -d stdytopreoneenversrw.dns.army -d stdytopreoneenvervaj.dns.army -d stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu +-d stdyunitedkesokokgst.dns.army -d stdyunitedkesokostdr.dns.army -d stdyunitedkesokostri.dns.navy -d stdyunitedkesokostxc.dns.army @@ -84980,7 +84984,9 @@ msFilterList -d stdyworkfineanotherrainbowlomoyentwkgls.duckdns.org -d stdyworkfinesanotherrainbowlomoyentstfcp.ydns.eu -d stdyworkfinesanotherrainbowlomoyentstgot.ydns.eu +-d stdyworkfinetraingst.dns.army -d stdyzgchgcloudgostgt.dns.army +-d stdyzgchgcloudgostxs.dns.army -d steadyrestmanufacturers.com -d steak.wpress.dk -d steakhouse.com.ua @@ -85540,6 +85546,7 @@ msFilterList -d strengthandvigour.com -d strengthrer.com -d strenover.ga +-d stressing.pw -d stressnada.com -d stretchpilates.fit -d strewn.org @@ -86231,6 +86238,7 @@ msFilterList -d supercutscissors.com -d superdad.id -d superdigitalguy.xyz +-d superdomain1709.info -d superdot.rs -d superecruiters.com -d superfacil.center @@ -86334,7 +86342,6 @@ msFilterList -d support.mdsol.com -d support.nordenrecycling.com -d support.nuvemit.com --d support.pubg.com -d support.redbook.aero -d support.revolus.xyz -d support.servu.co.uk @@ -86679,7 +86686,6 @@ msFilterList -d swicoservers.co.uk -d swieradowbiega.pl -d swifck.xmr.ac --d swift-cloud.com -d swiftbusinesspay.com -d swiftee.co.uk -d swiftender.com @@ -87524,7 +87530,6 @@ msFilterList -d targas.de -d targat-china.com -d target-events.com --d target-support.online -d target2cloud.com -d targetbizbd.com -d targetcm.net @@ -89105,7 +89110,6 @@ msFilterList -d thachastew.com -d thachvietstone.com -d thadathilfarmresort.com --d thaddeusarmstrong.com -d thadinnoo.co -d thagreymatter.com -d thai-chana.asia @@ -90827,7 +90831,6 @@ msFilterList -d tlcid.org -d tlckids-or.ga -d tlcmoto.com --d tldrbox.top -d tldrnet.top -d tlextreme.com -d tlfthelifefactory.com.au @@ -92424,6 +92427,7 @@ msFilterList -d ts.7rb.xyz -d ts0ev73.com -d tsal.com +-d tsapparel.com.my -d tsareva-garden.ru -d tsatsi.co.za -d tsauctions.com @@ -92651,6 +92655,7 @@ msFilterList -d tunnelview.co.uk -d tunuvo.com -d tuobrasocial.com.ar +-d tuoitrethainguyen.vn -d tupibaje.com -d tupperware.michaelroberge.ca -d tur.000webhostapp.com @@ -93797,7 +93802,6 @@ msFilterList -d unlimited.nu -d unlimitedbags.club -d unlimitedfreightco.com --d unlimitedimportandexport.com -d unlock-king.com -d unlock2.neagoeandrei.com -d unlockall.neagoeandrei.com @@ -94123,6 +94127,7 @@ msFilterList -d url-validation-clients.com -d url.246546.com -d url.57569.fr.snd52.ch +-d url2.mailanyone.net -d url3.mailanyone.net -d url5459.41southbar.com -d url675.textilmallorca.com @@ -94326,7 +94331,6 @@ msFilterList -d utting.org -d utv.sakeronline.se -d utv1.enliden.net --d uujian.cn -d uumove.com -d uurty87e8rt7rt.com -d uutiset.helppokoti.fi @@ -96300,7 +96304,6 @@ msFilterList -d voingani.it -d voip96.ru -d voipminic.com --d vokasi.ub.ac.id -d vokzalrf.ru -d vol.agency -d vol2.pw @@ -96928,7 +96931,6 @@ msFilterList -d washuis.nl -d wasidora.com -d wasilewski-online.de --d wasimjee.com -d wasino.co.th -d wasobd.net -d waspha.com @@ -98468,7 +98470,6 @@ msFilterList -d woatinkwoo.com -d woclawoffers.fun -d wocomm.marketingmindz.com --d wodfitapparel.fr -d wodmetaldom.pl -d wodsuit.com -d woelf.in @@ -101097,7 +101098,9 @@ msFilterList -d yoyoso.nz -d yoyoteacher.cn -d yp.dcyazilim.com +-d yp.hnggzyjy.cn -d ypbb.or.id +-d ypddf.org -d ypicsdy.cf -d ypko-55.gq -d ypom.com.br @@ -101256,7 +101259,6 @@ msFilterList -d yuti.kr -d yuvann.com -d yuvikadvertisments.com --d yuwaraja.vokasi.ub.ac.id -d yuweis.com -d yuxigon.com -d yuxuanknit.com diff --git a/urlhaus-filter.txt b/urlhaus-filter.txt index 063aff43..f8e2d0db 100644 --- a/urlhaus-filter.txt +++ b/urlhaus-filter.txt @@ -1,5 +1,5 @@ ! Title: Malicious URL Blocklist -! Updated: Mon, 12 Apr 2021 00:12:54 UTC +! Updated: Mon, 12 Apr 2021 12:13:00 UTC ! Expires: 1 day (update frequency) ! Homepage: https://gitlab.com/curben/urlhaus-filter ! License: https://gitlab.com/curben/urlhaus-filter#license @@ -1391,6 +1391,7 @@ 101.0.34.225 101.0.34.229 101.0.34.230 +101.0.34.236 101.0.34.244 101.0.34.247 101.0.34.253 @@ -1657,6 +1658,7 @@ 101.108.131.81 101.108.131.89 101.108.131.92 +101.108.131.99 101.108.132.0 101.108.132.109 101.108.132.110 @@ -1808,6 +1810,7 @@ 101.108.137.77 101.108.138.108 101.108.138.109 +101.108.138.150 101.108.138.155 101.108.138.160 101.108.138.174 @@ -6073,6 +6076,7 @@ 103.91.245.45 103.91.245.46 103.91.245.47 +103.91.245.48 103.91.245.49 103.91.245.5 103.91.245.54 @@ -8785,6 +8789,7 @@ 107.172.153.90 107.172.156.122 107.172.156.153 +107.172.156.3 107.172.157.125 107.172.157.131 107.172.157.176 @@ -12195,6 +12200,7 @@ 111.92.81.107 111.92.81.109 111.92.81.111 +111.92.81.112 111.92.81.113 111.92.81.116 111.92.81.118 @@ -17651,6 +17657,7 @@ 112.248.108.109 112.248.108.18 112.248.108.182 +112.248.109.156 112.248.109.95 112.248.11.123 112.248.110.120 @@ -20361,6 +20368,7 @@ 112.9.149.240 112.9.153.32 112.9.154.61 +112.9.155.122 112.9.157.102 112.9.158.247 112.9.160.95 @@ -23894,6 +23902,7 @@ 113.194.131.162 113.194.131.197 113.194.131.210 +113.194.131.72 113.194.132.207 113.194.132.253 113.194.132.44 @@ -23908,6 +23917,7 @@ 113.194.133.9 113.194.134.64 113.194.135.154 +113.194.135.223 113.194.135.230 113.194.135.238 113.194.135.63 @@ -26565,6 +26575,7 @@ 113.88.122.63 113.88.122.78 113.88.123.145 +113.88.123.22 113.88.123.235 113.88.124.109 113.88.124.119 @@ -26936,6 +26947,7 @@ 113.88.211.95 113.88.224.159 113.88.228.13 +113.88.228.152 113.88.228.16 113.88.228.211 113.88.228.73 @@ -27190,6 +27202,7 @@ 113.88.65.37 113.88.65.38 113.88.65.48 +113.88.65.49 113.88.65.54 113.88.65.80 113.88.66.213 @@ -27396,6 +27409,7 @@ 113.89.247.90 113.89.248.112 113.89.248.181 +113.89.4.189 113.89.4.201 113.89.4.7 113.89.4.74 @@ -27663,6 +27677,7 @@ 113.9.241.101 113.9.29.128 113.9.94.126 +113.90.133.38 113.90.135.225 113.90.135.231 113.90.160.138 @@ -28334,6 +28349,7 @@ 114.223.238.75 114.223.244.108 114.223.28.254 +114.223.43.7 114.223.48.158 114.223.61.204 114.223.63.197 @@ -29092,6 +29108,7 @@ 114.235.211.48 114.235.211.60 114.235.211.88 +114.235.213.31 114.235.22.32 114.235.222.230 114.235.222.24 @@ -30061,6 +30078,7 @@ 114.97.224.73 114.97.225.120 114tv.cc +115.110.193.166 115.120.136.248 115.120.204.211 115.127.96.194 @@ -34705,6 +34723,7 @@ 115.49.232.129 115.49.232.177 115.49.232.185 +115.49.232.197 115.49.232.20 115.49.232.204 115.49.232.210 @@ -37075,6 +37094,7 @@ 115.50.172.21 115.50.172.212 115.50.172.216 +115.50.172.22 115.50.172.223 115.50.172.225 115.50.172.236 @@ -37429,6 +37449,7 @@ 115.50.2.128 115.50.2.132 115.50.2.141 +115.50.2.148 115.50.2.149 115.50.2.159 115.50.2.179 @@ -42351,6 +42372,7 @@ 115.51.91.62 115.51.91.66 115.51.91.70 +115.51.91.81 115.51.91.98 115.51.92.1 115.51.92.114 @@ -45315,6 +45337,7 @@ 115.54.212.163 115.54.212.17 115.54.212.173 +115.54.212.175 115.54.212.180 115.54.212.183 115.54.212.185 @@ -49424,6 +49447,7 @@ 115.55.7.241 115.55.7.55 115.55.7.60 +115.55.7.9 115.55.7.92 115.55.70.113 115.55.71.231 @@ -57123,6 +57147,7 @@ 115.59.248.228 115.59.25.113 115.59.25.169 +115.59.250.37 115.59.250.52 115.59.252.114 115.59.252.12 @@ -59306,6 +59331,7 @@ 115.61.167.185 115.61.167.196 115.61.167.207 +115.61.167.21 115.61.167.225 115.61.167.227 115.61.167.230 @@ -59814,6 +59840,7 @@ 115.61.186.106 115.61.186.11 115.61.186.114 +115.61.186.139 115.61.186.144 115.61.186.153 115.61.186.158 @@ -60695,6 +60722,7 @@ 115.62.171.71 115.62.171.81 115.62.172.135 +115.62.172.140 115.62.172.145 115.62.172.173 115.62.172.200 @@ -60753,6 +60781,7 @@ 115.62.25.100 115.62.26.100 115.62.26.102 +115.62.26.113 115.62.26.114 115.62.26.120 115.62.26.123 @@ -66692,6 +66721,7 @@ 115.96.199.129 115.96.199.132 115.96.199.138 +115.96.199.146 115.96.199.160 115.96.199.163 115.96.199.165 @@ -91491,6 +91521,7 @@ 116.106.77.111 116.108.32.244 116.108.71.196 +116.108.92.154 116.109.108.32 116.109.132.2 116.109.156.14 @@ -93312,6 +93343,7 @@ 116.68.96.98 116.68.96.99 116.68.97.1 +116.68.97.100 116.68.97.102 116.68.97.104 116.68.97.117 @@ -93430,6 +93462,7 @@ 116.68.99.129 116.68.99.132 116.68.99.139 +116.68.99.152 116.68.99.155 116.68.99.158 116.68.99.159 @@ -114168,6 +114201,7 @@ 117.194.162.117 117.194.162.118 117.194.162.119 +117.194.162.12 117.194.162.120 117.194.162.121 117.194.162.122 @@ -116157,6 +116191,7 @@ 117.201.197.124 117.201.199.181 117.201.199.230 +117.201.200.106 117.201.200.236 117.201.201.33 117.201.202.154 @@ -119705,6 +119740,7 @@ 117.213.12.130 117.213.12.148 117.213.12.158 +117.213.12.177 117.213.12.208 117.213.12.218 117.213.12.219 @@ -121202,6 +121238,7 @@ 117.213.9.1 117.213.9.177 117.213.9.203 +117.213.9.42 117.213.9.58 117.213.9.71 117.213.9.77 @@ -121558,6 +121595,7 @@ 117.215.249.174 117.215.249.175 117.215.249.181 +117.215.249.196 117.215.249.197 117.215.249.199 117.215.249.20 @@ -121570,6 +121608,7 @@ 117.215.249.241 117.215.249.242 117.215.249.245 +117.215.249.250 117.215.249.251 117.215.249.255 117.215.249.27 @@ -124072,6 +124111,7 @@ 117.222.175.122 117.222.175.13 117.222.175.130 +117.222.175.134 117.222.175.135 117.222.175.136 117.222.175.138 @@ -126039,6 +126079,7 @@ 117.247.201.42 117.247.201.43 117.247.201.44 +117.247.201.45 117.247.201.47 117.247.201.49 117.247.201.56 @@ -128763,6 +128804,7 @@ 117.63.124.134 117.63.127.23 117.63.130.19 +117.63.133.251 117.63.151.77 117.63.156.234 117.63.157.34 @@ -130763,6 +130805,7 @@ 118.79.112.110 118.79.112.230 118.79.112.54 +118.79.113.239 118.79.113.7 118.79.114.198 118.79.114.78 @@ -137071,6 +137114,7 @@ 119.99.251.129 119.99.30.19 119.99.50.91 +119.99.52.69 119.99.63.42 11bybbsny.com 11degrees.org @@ -145675,6 +145719,7 @@ 123.10.32.196 123.10.32.200 123.10.32.239 +123.10.32.252 123.10.32.87 123.10.32.95 123.10.33.112 @@ -153465,6 +153510,7 @@ 123.14.95.219 123.14.95.24 123.14.95.248 +123.14.95.26 123.14.96.154 123.14.96.157 123.14.96.209 @@ -155846,6 +155892,7 @@ 123.4.242.146 123.4.242.152 123.4.242.163 +123.4.242.19 123.4.242.199 123.4.242.204 123.4.242.21 @@ -156235,6 +156282,7 @@ 123.4.47.248 123.4.47.25 123.4.47.32 +123.4.47.57 123.4.48.128 123.4.48.40 123.4.48.70 @@ -159047,6 +159095,7 @@ 123.5.188.85 123.5.188.86 123.5.188.87 +123.5.188.9 123.5.188.93 123.5.188.97 123.5.189.101 @@ -159060,6 +159109,7 @@ 123.5.189.14 123.5.189.145 123.5.189.147 +123.5.189.15 123.5.189.150 123.5.189.151 123.5.189.154 @@ -161243,6 +161293,7 @@ 123.9.117.236 123.9.117.245 123.9.118.130 +123.9.118.183 123.9.118.79 123.9.119.209 123.9.119.47 @@ -162411,6 +162462,7 @@ 123.9.35.198 123.9.35.6 123.9.35.88 +123.9.36.120 123.9.36.188 123.9.36.222 123.9.36.6 @@ -168259,6 +168311,7 @@ 125.41.14.219 125.41.14.22 125.41.14.220 +125.41.14.228 125.41.14.232 125.41.14.235 125.41.14.237 @@ -188676,6 +188729,7 @@ 143.198.220.102 143.198.48.37 143.198.54.180 +143.198.54.233 143.198.63.143 143.198.65.195 143.198.65.229 @@ -188942,6 +188996,7 @@ 149.255.15.134 149.255.15.138 149.255.15.143 +149.255.15.170 149.255.15.172 149.255.15.180 149.255.15.182 @@ -188950,8 +189005,10 @@ 149.255.15.213 149.255.15.235 149.255.15.27 +149.255.15.29 149.255.15.38 149.255.15.43 +149.255.15.44 149.255.15.87 149.255.15.99 149.255.36.133 @@ -190154,6 +190211,7 @@ 157.90.24.103 157.90.244.110 157.90.244.177 +157.90.8.28 157.97.133.128 157.97.17.46 157.97.2.215 @@ -191386,6 +191444,7 @@ 162.244.81.158 162.244.81.204 162.244.81.55 +162.245.221.121 162.246.15.229 162.246.20.117 162.246.20.236 @@ -203053,6 +203112,7 @@ 178.175.10.224 178.175.10.240 178.175.10.244 +178.175.10.247 178.175.10.248 178.175.10.251 178.175.10.254 @@ -203084,6 +203144,7 @@ 178.175.10.98 178.175.10.99 178.175.100.101 +178.175.100.104 178.175.100.106 178.175.100.109 178.175.100.11 @@ -203234,6 +203295,7 @@ 178.175.101.21 178.175.101.210 178.175.101.211 +178.175.101.212 178.175.101.213 178.175.101.217 178.175.101.219 @@ -203335,6 +203397,7 @@ 178.175.102.179 178.175.102.183 178.175.102.184 +178.175.102.186 178.175.102.188 178.175.102.189 178.175.102.190 @@ -203512,6 +203575,7 @@ 178.175.104.110 178.175.104.112 178.175.104.114 +178.175.104.115 178.175.104.116 178.175.104.12 178.175.104.120 @@ -203858,6 +203922,7 @@ 178.175.107.127 178.175.107.13 178.175.107.133 +178.175.107.135 178.175.107.136 178.175.107.138 178.175.107.140 @@ -204182,6 +204247,7 @@ 178.175.109.96 178.175.109.98 178.175.11.0 +178.175.11.100 178.175.11.101 178.175.11.104 178.175.11.105 @@ -204609,6 +204675,7 @@ 178.175.112.81 178.175.112.85 178.175.112.86 +178.175.112.87 178.175.112.89 178.175.112.90 178.175.112.97 @@ -205641,6 +205708,7 @@ 178.175.121.12 178.175.121.122 178.175.121.123 +178.175.121.125 178.175.121.129 178.175.121.130 178.175.121.133 @@ -206299,6 +206367,7 @@ 178.175.126.38 178.175.126.4 178.175.126.41 +178.175.126.43 178.175.126.44 178.175.126.46 178.175.126.48 @@ -206494,6 +206563,7 @@ 178.175.13.212 178.175.13.213 178.175.13.216 +178.175.13.219 178.175.13.220 178.175.13.221 178.175.13.222 @@ -206597,6 +206667,7 @@ 178.175.14.251 178.175.14.27 178.175.14.28 +178.175.14.29 178.175.14.3 178.175.14.32 178.175.14.33 @@ -206666,6 +206737,7 @@ 178.175.15.190 178.175.15.194 178.175.15.195 +178.175.15.196 178.175.15.197 178.175.15.198 178.175.15.199 @@ -206982,6 +207054,7 @@ 178.175.18.250 178.175.18.253 178.175.18.27 +178.175.18.31 178.175.18.32 178.175.18.36 178.175.18.37 @@ -207165,6 +207238,7 @@ 178.175.2.224 178.175.2.225 178.175.2.226 +178.175.2.23 178.175.2.230 178.175.2.234 178.175.2.236 @@ -207443,6 +207517,7 @@ 178.175.22.187 178.175.22.188 178.175.22.194 +178.175.22.198 178.175.22.203 178.175.22.206 178.175.22.207 @@ -207485,6 +207560,7 @@ 178.175.22.67 178.175.22.69 178.175.22.72 +178.175.22.74 178.175.22.75 178.175.22.78 178.175.22.83 @@ -207720,6 +207796,7 @@ 178.175.25.155 178.175.25.156 178.175.25.159 +178.175.25.162 178.175.25.163 178.175.25.164 178.175.25.166 @@ -207984,6 +208061,7 @@ 178.175.27.25 178.175.27.252 178.175.27.253 +178.175.27.26 178.175.27.30 178.175.27.32 178.175.27.34 @@ -207993,6 +208071,7 @@ 178.175.27.39 178.175.27.4 178.175.27.41 +178.175.27.43 178.175.27.46 178.175.27.47 178.175.27.48 @@ -208406,6 +208485,7 @@ 178.175.30.80 178.175.30.81 178.175.30.86 +178.175.30.90 178.175.30.91 178.175.30.93 178.175.30.96 @@ -208684,6 +208764,7 @@ 178.175.33.228 178.175.33.23 178.175.33.231 +178.175.33.233 178.175.33.234 178.175.33.236 178.175.33.239 @@ -209637,6 +209718,7 @@ 178.175.41.225 178.175.41.229 178.175.41.23 +178.175.41.230 178.175.41.231 178.175.41.235 178.175.41.237 @@ -209994,6 +210076,7 @@ 178.175.44.89 178.175.44.9 178.175.44.90 +178.175.44.93 178.175.44.95 178.175.44.96 178.175.45.10 @@ -210209,6 +210292,7 @@ 178.175.46.54 178.175.46.55 178.175.46.59 +178.175.46.60 178.175.46.61 178.175.46.63 178.175.46.65 @@ -210239,6 +210323,7 @@ 178.175.47.12 178.175.47.122 178.175.47.126 +178.175.47.127 178.175.47.128 178.175.47.132 178.175.47.139 @@ -210369,6 +210454,7 @@ 178.175.48.161 178.175.48.162 178.175.48.163 +178.175.48.164 178.175.48.168 178.175.48.17 178.175.48.172 @@ -210582,6 +210668,7 @@ 178.175.5.22 178.175.5.221 178.175.5.222 +178.175.5.223 178.175.5.226 178.175.5.227 178.175.5.229 @@ -210839,6 +210926,7 @@ 178.175.52.11 178.175.52.111 178.175.52.112 +178.175.52.114 178.175.52.115 178.175.52.118 178.175.52.119 @@ -210898,6 +210986,7 @@ 178.175.52.249 178.175.52.250 178.175.52.252 +178.175.52.255 178.175.52.31 178.175.52.33 178.175.52.34 @@ -211031,6 +211120,7 @@ 178.175.53.83 178.175.53.85 178.175.53.86 +178.175.53.87 178.175.53.9 178.175.53.90 178.175.53.94 @@ -211134,6 +211224,7 @@ 178.175.54.71 178.175.54.72 178.175.54.74 +178.175.54.78 178.175.54.80 178.175.54.81 178.175.54.87 @@ -211154,6 +211245,7 @@ 178.175.55.113 178.175.55.114 178.175.55.117 +178.175.55.118 178.175.55.119 178.175.55.121 178.175.55.125 @@ -211363,6 +211455,7 @@ 178.175.57.102 178.175.57.103 178.175.57.104 +178.175.57.105 178.175.57.108 178.175.57.11 178.175.57.112 @@ -211477,6 +211570,7 @@ 178.175.58.125 178.175.58.126 178.175.58.127 +178.175.58.130 178.175.58.133 178.175.58.139 178.175.58.14 @@ -211499,6 +211593,7 @@ 178.175.58.175 178.175.58.177 178.175.58.178 +178.175.58.18 178.175.58.183 178.175.58.185 178.175.58.188 @@ -211718,6 +211813,8 @@ 178.175.6.196 178.175.6.198 178.175.6.2 +178.175.6.201 +178.175.6.203 178.175.6.204 178.175.6.205 178.175.6.207 @@ -211904,6 +212001,7 @@ 178.175.61.206 178.175.61.209 178.175.61.210 +178.175.61.212 178.175.61.214 178.175.61.217 178.175.61.219 @@ -211971,6 +212069,7 @@ 178.175.62.122 178.175.62.123 178.175.62.128 +178.175.62.130 178.175.62.134 178.175.62.137 178.175.62.141 @@ -212633,6 +212732,7 @@ 178.175.68.161 178.175.68.162 178.175.68.164 +178.175.68.165 178.175.68.166 178.175.68.167 178.175.68.17 @@ -213265,6 +213365,7 @@ 178.175.72.53 178.175.72.54 178.175.72.56 +178.175.72.58 178.175.72.6 178.175.72.61 178.175.72.65 @@ -213661,6 +213762,7 @@ 178.175.76.27 178.175.76.29 178.175.76.33 +178.175.76.34 178.175.76.36 178.175.76.37 178.175.76.43 @@ -213945,6 +214047,7 @@ 178.175.79.244 178.175.79.247 178.175.79.253 +178.175.79.27 178.175.79.30 178.175.79.31 178.175.79.38 @@ -214419,6 +214522,7 @@ 178.175.83.156 178.175.83.158 178.175.83.167 +178.175.83.17 178.175.83.176 178.175.83.18 178.175.83.180 @@ -214687,6 +214791,7 @@ 178.175.85.230 178.175.85.231 178.175.85.234 +178.175.85.235 178.175.85.242 178.175.85.243 178.175.85.244 @@ -215520,6 +215625,7 @@ 178.175.92.208 178.175.92.210 178.175.92.211 +178.175.92.213 178.175.92.214 178.175.92.215 178.175.92.218 @@ -215629,6 +215735,7 @@ 178.175.93.200 178.175.93.202 178.175.93.203 +178.175.93.204 178.175.93.205 178.175.93.207 178.175.93.210 @@ -215915,6 +216022,7 @@ 178.175.95.79 178.175.95.80 178.175.95.82 +178.175.95.83 178.175.95.85 178.175.95.86 178.175.95.88 @@ -218514,6 +218622,7 @@ 180.177.104.65 180.177.180.6 180.177.242.73 +180.177.5.36 180.177.76.161 180.177.80.11 180.178.104.86 @@ -218621,7 +218730,9 @@ 180.188.241.91 180.188.241.99 180.188.247.140 +180.188.247.172 180.188.247.181 +180.188.247.218 180.188.247.26 180.188.252.185 180.188.252.37 @@ -222738,6 +222849,7 @@ 182.113.4.209 182.113.4.223 182.113.4.226 +182.113.4.247 182.113.4.64 182.113.4.68 182.113.4.88 @@ -223708,6 +223820,7 @@ 182.114.193.245 182.114.193.70 182.114.194.116 +182.114.194.183 182.114.194.184 182.114.194.206 182.114.194.210 @@ -235184,6 +235297,7 @@ 182.119.23.62 182.119.23.70 182.119.23.74 +182.119.23.75 182.119.23.9 182.119.23.90 182.119.23.91 @@ -235629,6 +235743,7 @@ 182.119.48.200 182.119.48.205 182.119.48.217 +182.119.48.230 182.119.48.242 182.119.48.250 182.119.48.255 @@ -238500,6 +238615,7 @@ 182.121.123.1 182.121.123.122 182.121.123.124 +182.121.123.134 182.121.123.141 182.121.123.142 182.121.123.16 @@ -239952,6 +240068,7 @@ 182.121.200.115 182.121.200.119 182.121.200.127 +182.121.200.137 182.121.200.143 182.121.200.151 182.121.200.161 @@ -240144,6 +240261,7 @@ 182.121.205.223 182.121.205.228 182.121.205.237 +182.121.205.246 182.121.205.251 182.121.205.39 182.121.205.47 @@ -246639,6 +246757,7 @@ 182.126.109.133 182.126.109.146 182.126.109.150 +182.126.109.194 182.126.109.20 182.126.109.25 182.126.109.255 @@ -247404,6 +247523,7 @@ 182.126.126.150 182.126.126.16 182.126.126.161 +182.126.126.162 182.126.126.170 182.126.126.176 182.126.126.181 @@ -251634,6 +251754,7 @@ 182.127.207.156 182.127.207.158 182.127.207.162 +182.127.207.187 182.127.207.218 182.127.207.226 182.127.207.247 @@ -252690,6 +252811,7 @@ 182.127.80.184 182.127.80.192 182.127.80.229 +182.127.80.240 182.127.80.85 182.127.80.89 182.127.81.114 @@ -253354,6 +253476,7 @@ 182.235.29.89 182.236.124.160 182.239.129.154 +182.240.132.164 182.240.132.203 182.240.213.4 182.240.214.81 @@ -255106,6 +255229,7 @@ 182.57.105.110 182.57.105.161 182.57.105.167 +182.57.105.175 182.57.106.118 182.57.106.190 182.57.106.237 @@ -260593,6 +260717,7 @@ 183.141.54.112 183.141.55.239 183.141.60.120 +183.141.61.174 183.141.61.39 183.142.11.225 183.142.115.155 @@ -261257,6 +261382,7 @@ 183.17.227.102 183.17.227.109 183.17.227.113 +183.17.227.148 183.17.227.162 183.17.227.172 183.17.227.187 @@ -261816,6 +261942,7 @@ 183.49.47.56 183.49.85.243 183.49.85.247 +183.49.86.54 183.49.87.144 183.49.87.220 183.49.87.27 @@ -261904,6 +262031,7 @@ 183.83.103.117 183.83.104.165 183.83.104.44 +183.83.104.55 183.83.104.68 183.83.105.181 183.83.105.21 @@ -262495,6 +262623,7 @@ 185.117.119.71 185.117.155.20 185.117.2.107 +185.117.21.212 185.117.75.111 185.117.75.201 185.117.75.248 @@ -262584,6 +262713,7 @@ 185.132.53.161 185.132.53.166 185.132.53.167 +185.132.53.182 185.132.53.185 185.132.53.186 185.132.53.191 @@ -263778,6 +263908,7 @@ 185.36.59.11 185.36.59.76 185.36.81.43 +185.38.142.194 185.38.142.236 185.39.11.105 185.39.183.48 @@ -265136,6 +265267,7 @@ 186.33.105.7 186.33.105.8 186.33.105.9 +186.33.107.74 186.33.112.100 186.33.112.101 186.33.112.102 @@ -267386,9 +267518,11 @@ 189.170.12.149 189.170.178.180 189.170.40.102 +189.171.22.132 189.171.31.166 189.172.151.237 189.174.35.248 +189.175.214.112 189.176.68.26 189.176.93.82 189.177.144.215 @@ -270021,6 +270155,7 @@ 192.99.169.15 192.99.208.196 192.99.214.32 +192.99.221.230 192.99.240.77 192.99.242.13 192.99.246.11 @@ -273490,6 +273625,7 @@ 202.164.138.156 202.164.138.157 202.164.138.158 +202.164.138.159 202.164.138.160 202.164.138.161 202.164.138.162 @@ -273746,6 +273882,7 @@ 202.164.139.255 202.164.139.26 202.164.139.28 +202.164.139.29 202.164.139.30 202.164.139.31 202.164.139.36 @@ -273764,6 +273901,7 @@ 202.164.139.52 202.164.139.55 202.164.139.56 +202.164.139.57 202.164.139.58 202.164.139.6 202.164.139.60 @@ -277750,6 +277888,7 @@ 206.189.129.96 206.189.131.31 206.189.132.42 +206.189.135.162 206.189.135.253 206.189.138.82 206.189.140.181 @@ -282397,6 +282536,7 @@ 219.154.113.157 219.154.113.161 219.154.113.163 +219.154.113.171 219.154.113.172 219.154.113.177 219.154.113.181 @@ -284758,6 +284898,7 @@ 219.155.226.188 219.155.226.194 219.155.226.198 +219.155.226.205 219.155.226.225 219.155.226.43 219.155.226.50 @@ -288010,6 +288151,7 @@ 219.157.138.38 219.157.138.63 219.157.139.165 +219.157.14.239 219.157.14.85 219.157.140.190 219.157.140.255 @@ -288472,6 +288614,7 @@ 219.157.178.171 219.157.178.179 219.157.178.192 +219.157.178.196 219.157.178.201 219.157.178.205 219.157.178.21 @@ -290642,6 +290785,7 @@ 219.157.48.44 219.157.48.45 219.157.48.46 +219.157.48.5 219.157.48.51 219.157.48.58 219.157.48.59 @@ -293802,6 +293946,7 @@ 221.14.47.162 221.14.47.182 221.14.47.189 +221.14.47.204 221.14.47.225 221.14.47.46 221.14.47.77 @@ -295218,6 +295363,7 @@ 221.15.182.29 221.15.182.40 221.15.182.48 +221.15.182.72 221.15.182.9 221.15.182.94 221.15.183.104 @@ -296761,6 +296907,7 @@ 221.15.53.25 221.15.53.42 221.15.53.46 +221.15.53.55 221.15.53.57 221.15.53.62 221.15.53.74 @@ -307383,6 +307530,7 @@ 222.140.163.15 222.140.163.159 222.140.163.179 +222.140.163.181 222.140.163.184 222.140.163.188 222.140.163.208 @@ -312527,6 +312675,7 @@ 23.95.116.135 23.95.116.144 23.95.122.24 +23.95.122.25 23.95.122.47 23.95.13.131 23.95.13.158 @@ -322752,6 +322901,7 @@ 27.40.71.3 27.40.72.200 27.40.73.175 +27.40.79.170 27.40.79.70 27.40.82.129 27.40.82.201 @@ -347111,6 +347261,7 @@ 31.168.126.45 31.168.146.199 31.168.153.60 +31.168.16.68 31.168.177.37 31.168.178.71 31.168.179.83 @@ -356073,6 +356224,7 @@ 41.143.247.190 41.143.31.149 41.143.57.149 +41.143.69.12 41.144.143.214 41.144.159.85 41.146.243.74 @@ -358334,6 +358486,7 @@ 42.224.171.138 42.224.171.162 42.224.171.163 +42.224.171.165 42.224.171.168 42.224.171.193 42.224.171.196 @@ -360119,6 +360272,7 @@ 42.224.254.199 42.224.254.205 42.224.254.207 +42.224.254.220 42.224.254.224 42.224.254.226 42.224.254.228 @@ -360645,6 +360799,7 @@ 42.224.4.0 42.224.4.1 42.224.4.100 +42.224.4.110 42.224.4.112 42.224.4.12 42.224.4.120 @@ -364813,6 +364968,7 @@ 42.227.222.143 42.227.222.158 42.227.222.174 +42.227.222.189 42.227.222.229 42.227.222.244 42.227.222.43 @@ -364848,6 +365004,7 @@ 42.227.225.154 42.227.225.181 42.227.225.209 +42.227.225.253 42.227.225.45 42.227.225.49 42.227.225.81 @@ -368718,6 +368875,7 @@ 42.230.142.79 42.230.142.82 42.230.143.130 +42.230.143.162 42.230.143.17 42.230.143.174 42.230.143.176 @@ -373091,6 +373249,7 @@ 42.232.169.202 42.232.169.203 42.232.169.209 +42.232.169.211 42.232.169.219 42.232.169.22 42.232.169.223 @@ -374796,6 +374955,7 @@ 42.233.96.52 42.233.96.71 42.233.97.10 +42.233.97.141 42.233.97.149 42.233.97.157 42.233.97.160 @@ -379435,6 +379595,7 @@ 42.235.84.52 42.235.84.54 42.235.84.73 +42.235.84.85 42.235.84.87 42.235.84.88 42.235.84.97 @@ -380646,6 +380807,7 @@ 42.237.114.252 42.237.114.48 42.237.114.50 +42.237.114.80 42.237.114.87 42.237.115.169 42.237.115.175 @@ -384530,6 +384692,7 @@ 45.15.143.158 45.15.143.170 45.15.143.175 +45.15.143.191 45.15.143.253 45.15.25.65 45.15.253.88 @@ -385724,6 +385887,7 @@ 45.229.54.198 45.229.54.199 45.229.54.200 +45.229.54.201 45.229.54.202 45.229.54.203 45.229.54.204 @@ -385825,6 +385989,7 @@ 45.229.55.71 45.229.55.75 45.229.55.79 +45.229.55.80 45.229.55.83 45.229.55.85 45.229.55.98 @@ -386508,6 +386673,7 @@ 45.77.78.41 45.77.79.163 45.77.88.79 +45.77.9.151 45.77.97.236 45.77.98.62 45.78.21.150 @@ -393067,6 +393233,7 @@ 58.249.75.128 58.249.75.13 58.249.75.14 +58.249.75.146 58.249.75.158 58.249.75.159 58.249.75.169 @@ -393128,6 +393295,7 @@ 58.249.77.105 58.249.77.119 58.249.77.12 +58.249.77.141 58.249.77.142 58.249.77.144 58.249.77.147 @@ -393465,6 +393633,7 @@ 58.249.86.20 58.249.86.202 58.249.86.203 +58.249.86.214 58.249.86.227 58.249.86.242 58.249.86.31 @@ -394513,6 +394682,7 @@ 59.126.128.92 59.126.13.182 59.126.132.4 +59.126.132.42 59.126.136.62 59.126.139.144 59.126.148.122 @@ -398537,6 +398707,7 @@ 59.5.192.126 59.5.204.218 59.5.230.140 +59.50.23.23 59.50.28.100 59.51.10.111 59.51.10.55 @@ -400834,6 +401005,7 @@ 59.92.217.210 59.92.217.211 59.92.217.214 +59.92.217.215 59.92.217.217 59.92.217.218 59.92.217.219 @@ -402003,6 +402175,7 @@ 59.93.21.137 59.93.21.138 59.93.21.14 +59.93.21.140 59.93.21.141 59.93.21.146 59.93.21.147 @@ -403285,6 +403458,7 @@ 59.94.182.208 59.94.182.21 59.94.182.210 +59.94.182.212 59.94.182.216 59.94.182.217 59.94.182.22 @@ -404176,6 +404350,7 @@ 59.95.175.46 59.95.175.47 59.95.175.48 +59.95.175.49 59.95.175.5 59.95.175.50 59.95.175.51 @@ -412039,6 +412214,7 @@ 60.211.80.189 60.211.80.208 60.211.80.213 +60.211.80.216 60.211.80.5 60.211.80.9 60.211.81.125 @@ -412694,6 +412870,7 @@ 60.214.52.40 60.214.52.50 60.214.52.96 +60.214.53.159 60.214.53.170 60.214.53.183 60.214.53.242 @@ -422202,6 +422379,7 @@ 60.254.88.6 60.254.88.91 60.254.89.110 +60.254.89.158 60.254.89.160 60.254.89.191 60.254.89.195 @@ -425280,6 +425458,7 @@ 61.3.149.196 61.3.149.197 61.3.149.216 +61.3.149.244 61.3.149.253 61.3.149.26 61.3.149.3 @@ -425294,6 +425473,7 @@ 61.3.149.86 61.3.149.89 61.3.150.0 +61.3.150.101 61.3.150.104 61.3.150.121 61.3.150.140 @@ -425335,9 +425515,11 @@ 61.3.151.90 61.3.152.205 61.3.152.26 +61.3.153.224 61.3.154.201 61.3.154.21 61.3.156.130 +61.3.156.17 61.3.18.2 61.3.18.216 61.3.23.66 @@ -426301,6 +426483,7 @@ 61.52.186.181 61.52.186.184 61.52.186.185 +61.52.186.186 61.52.186.192 61.52.186.195 61.52.186.207 @@ -429240,6 +429423,7 @@ 61.52.97.57 61.52.97.61 61.52.97.64 +61.52.97.68 61.52.97.69 61.52.97.72 61.52.97.74 @@ -434191,7 +434375,6 @@ 65.99.158.218 65.99.176.17 650x.com -654tyfcdr4654fytfy.top 65k2.com 66-gifts.com 66.103.9.249 @@ -434952,7 +435135,6 @@ 6gue98ddw4220152.freebackup.site 6hffgq.dm.files.1drv.com 6hu.xyz -6ip.us 6iptv.com 6itokam.com 6kd743o1w.com @@ -437362,6 +437544,7 @@ 80.92.189.5 80.92.189.70 80.92.204.14 +80.92.204.57 80.93.182.219 80.99.128.61 80001.me @@ -438568,6 +438751,7 @@ 85.245.162.144 85.247.247.175 85.25.213.151 +85.250.147.134 85.250.36.135 85.255.1.93 85.26.250.86 @@ -438745,6 +438929,7 @@ 86.7.86.4 86.82.137.79 86.91.10.91 +86.98.23.78 860259.com 8650hwvaapy.realbrjuridico.email 866appliance.com @@ -438862,6 +439047,7 @@ 87.248.61.60 87.249.204.194 87.251.235.167 +87.251.71.78 87.251.82.211 87.253.0.196 87.253.1.206 @@ -439437,6 +439623,7 @@ 89.148.233.85 89.148.234.101 89.148.234.165 +89.148.234.217 89.148.234.37 89.148.235.94 89.148.237.100 @@ -440867,6 +441054,7 @@ 93.157.62.102 93.157.62.171 93.157.62.58 +93.157.63.221 93.157.63.244 93.159.141.165 93.159.141.166 @@ -442475,7 +442663,6 @@ a.deadnig.ga a.doko.moe a.gg.fm a.heritageandterre.com -a.pomf.cat a.pomf.se a.pomf.space a.pomf.su @@ -447190,7 +447377,6 @@ anmingsi.com anmocnhien.vn anmolanwar.com ann141.net -anna.websaiting.ru annaaluminium.annagroup.net annabelle-hamande.be annabphotography.co.uk @@ -447705,6 +447891,7 @@ app.bigplan-alex.com app.boxrcdn.com app.bridgeimpex.org app.calag.at +app.casetabs.com app.catholicchurch.co.in app.choiphui.com app.cloudindustry.net @@ -449611,6 +449798,7 @@ atpcsm.be atphitech.com atpn.ir atprofessional.org +atpscan.global.hornetsecurity.com atr.it atradex.com atragon.co.uk @@ -450371,6 +450559,8 @@ awswx.xyz awsxb.xyz awsyscloud.com awtinfostore.co.business +awumad01.top +awuqze02.top ax-yogado.com axalize.vn axalta.grupojenrab.mx @@ -451768,6 +451958,7 @@ bbfjjf8.com bbfr.cba.pl bbgiardinodoriente.it bbgk.de +bbgroup.com.vn bbh-design.de bbhdata.com bbhs.org.ng @@ -452207,7 +452398,6 @@ bekurov.org bel-med-tour.ru belabargelro.com belair.btwstudio.ch -belairinternet.com belamater.com.br belangel.by belanja-berkah.xyz @@ -452326,7 +452516,6 @@ belyi.ug belz-development.de belznerdesign.de bem.fkep.unpad.ac.id -bem.hukum.ub.ac.id bem.unimal.ac.id bemagazine.club bemakeup.ru @@ -453099,6 +453288,7 @@ bieres.lavachenoiresud.com bierne-les-villages.fr biese.eu bietthubien.org +bietthudep902.com bietthulambach.com bietthulienkegamuda.net bietthumau.com @@ -456994,7 +457184,6 @@ callonenergy.com callpetercatering.com callrealtyaz.com callshaal.com -callsmaster.com calltoprimus.ru callumstokes.com calm-tech.africa @@ -458254,7 +458443,6 @@ cdncomfortgroup.website cdndownloadlp.club cdnmultimedia.com cdnpic.mgyun.com -cdnrep.reimageplus.com cdnxh.net cdoconsult.com.br cdolechon.com @@ -459046,7 +459234,6 @@ cheekie2.neagoeandrei.com cheematransxpressinc.com cheerchile.cl cheerfulgiversneverlack.com -cheerfullydo.com cheesecakery.com.br cheetahridge.mediadevstaging.com chef-solutions.dreamscape.co.in @@ -459977,6 +460164,7 @@ clarrywillow.top clarte-thailand.com clashofclansgems.nl clasificados.diaadianews.com +clasificadosmaule.com class.britishonline.co class.snph.ir classbrain.net @@ -460274,6 +460462,7 @@ clntnjkstdycloudstcy.dns.army cloakingtds.xyz clock.noixun.com clodflarechk.com +clodura.ai clone.affordable.cm clone.system-standex.dk cloned.in @@ -460459,7 +460648,6 @@ cmeaststar.de cmecobrancas.com cmelik.com cmessagers.com -cmg.asia cmg.ma cmgroup.com.ua cmhighschool.edu.bd @@ -462998,7 +463186,6 @@ cuacuonsieure.com cuadros.pe cuahangphongthuy.net cuahangstore.com -cuahangvattu.com cualtis.com cuanhomxingfanhapkhau.com cuasotinhoc.net @@ -463427,6 +463614,7 @@ d.powerofwish.com d.qiluwl.com d.teamworx.ph d.techmartbd.com +d.top4top.io d.top4top.net d.ttr3p.com d04.data39.helldata.com @@ -465408,6 +465596,7 @@ deportetotal.mx deposayim.ml depositoclara.com.br depot7.com +depozituldegeneratoare.ro depraetere.net deprealty.ru depressionted.com @@ -467134,7 +467323,6 @@ dl-45538429.onedrives-en-live.com dl-675423.store-downloads.com dl-80076342.md-downloads.com dl-97674424.md-downloads.com -dl-gameplayer.dmm.com dl-link.link dl-link.live dl-link.network @@ -467157,9 +467345,9 @@ dl.ikiki.cn dl.imht.ir dl.installcdn-aws.com dl.mqego.com -dl.mydown.com dl.ossdown.fun dl.packetstormsecurity.net +dl.pandasecur.com dl.popupgrade.com dl.repairlabshost.com dl.rina-roleplay.com @@ -467336,6 +467524,9 @@ dobrojutrodjevojke.com dobroviz.com.ua dobrovorot.su dobsoncentral.com +doc-0s-7c-docs.googleusercontent.com +doc-10-0c-docs.googleusercontent.com +doc-10-8s-docs.googleusercontent.com doc-hub.healthycheapfast.com doc-japan.com doc.albaspizzaastoria.com @@ -469610,6 +469801,7 @@ ec2-52-56-233-157.eu-west-2.compute.amazonaws.com ec2-54-207-92-161.sa-east-1.compute.amazonaws.com ec2-54-212-231-68.us-west-2.compute.amazonaws.com ec2-54-94-215-87.sa-east-1.compute.amazonaws.com +ec2euc1.boxcloud.com ec2test.ga ec3-design.com ecadigital.com @@ -471910,6 +472102,7 @@ es.thevoucherstop.com esaarc.com esacbd.com esagarautomobiles.com +esaja09.top esanjobs.org esar.weenets.com esascom.com @@ -477704,7 +477897,6 @@ genregis.com genrjw.dm.files.1drv.com genstaff.gov.kg gentcreativa.com -gentecoyol.com gentesanluis.com gentiane-salers.com gentlechirocenter.com @@ -480453,6 +480645,7 @@ gvou7g.by.files.1drv.com gvpcdpgc.edu.in gvpmacademy.co.za gvsme.com +gw.daelimcloud.com gw.hitlin.com gwangjuhotels.kr gwavellc.com @@ -483264,7 +483457,6 @@ hotelvip-bron.ru hotelwaldblick.com hotexpress.co hotfacts.org -hotgifts.online hotilife.com hotissue.xyz hotkine.com @@ -483642,7 +483834,6 @@ hukouec-ltd.com hukuen-motokare.xyz hukuki.site hukukportal.com -hukum.ub.ac.id hukum.unwiku.ac.id hulianwang114.com huliot.in @@ -483964,6 +484155,7 @@ i-sharecloud.com i-supportcharity.com i-vnsweyu.pl i-voda.com +i.fiery.me i.fluffy.cc i.funtourspt.eu i.n.t.e.rloca.l.qs.j.y@jfas.top @@ -487244,6 +487436,7 @@ itspread.com itspsc.com.ua itspueh.nl itsquare.yrcreations.com +itsrlytry.000webhostapp.com itssprout.com itstelecom.com.br itsweezle.com @@ -487443,6 +487636,7 @@ j-skill.ru j-stage.jp j-toputvoutfitters.com j.kyryl.ru +j.top4top.io j11g9xecuxe43xu.xyz j12z7407gwtzk.xyz j13.biz @@ -487575,6 +487769,7 @@ jaipurjungle.co.in jaipurweddingphotography.com jairathsnatural.ca jairozapata.000webhostapp.com +jaishomo.info jaishritours.com jaiswalsupplement.com jajadomains.com @@ -491603,7 +491798,6 @@ kodiakpro.ca kodim0112sabang.com kodingeko.com kodip.nfile.net -kodjdsjsdjf.tk kodlacan.site kodmuje.com kodolios.000webhostapp.com @@ -494243,6 +494437,7 @@ library.arihantmbainstitute.ac.in library.cifor.org library.dhl-xom.com library.iainbengkulu.ac.id +library.mju.ac.th library.phibi.my.id library.piet.co.in library.strophicmusic.com @@ -494929,7 +495124,6 @@ livechallenge.fr livecigarevent.com livecricketscorecard.info livedaynews.com -livedemo00.template-help.com livedownload.in livedrumtracks.com livefarma.com @@ -494962,7 +495156,6 @@ livesouvenir.com livestreams.vn livesuitesapartdaire.com livesurgerycourse.ir -liveswinburneeduau-my.sharepoint.com liveswindow.casa liveswindow.cyou liveswindows.bar @@ -496137,7 +496330,6 @@ luzbarbosa.com.br luzconsulting.com.br luzevida.com.br luzfloral.com -luzy.vn luzzeri.com lvajnczdy.cf lvcfund.org.vn @@ -499175,7 +499367,6 @@ mecflui.com.br mecgwl.ac.in mechanicaltools.club mechanicsthatcometoyou.com -mecharnise.ir mechathrones.com mechauto.co.za mechdesign.com @@ -499761,7 +499952,6 @@ menxhiqi.com menziesadvisory-my.sharepoint.com menzway.com meogiambeo.com -meohaybotui.com meolamdephay.com mepsgen.com mera.ddns.net @@ -500079,6 +500269,7 @@ mfmr.gov.sl mfomjr.com mfotovideo.ro mfpburundi.bi +mfpc.org.my mfppanel.xyz mfpvision.com mfronza.com.br @@ -505111,7 +505302,6 @@ nhadatphonglinh.com nhadatquan2.xyz nhadatthienthoi.com nhadephungyen.com -nhadepkientruc.net nhahangdaihung.com nhahanghaivuong.vn nhahanglegiang.vn @@ -505325,7 +505515,6 @@ nikanbearing.com nikanpolimer.ir nikastroi.ru nikavkuchyni.sk -nikayu.com nikbox.ru nikeshyadav.com nikhil.webscript.co.in @@ -507841,7 +508030,6 @@ optimusforce.nl option47.us optioncapitalgroup.ru optionrp.com -optionscity.com optisaving.com optitechsa.co.za optocen.ru @@ -508136,7 +508324,6 @@ osethmaayurveda.com osezrayonner.ma osgbforum.com oshattorney.com -oshi.at oshodrycleaning.com oshonafitness.com oshop.es @@ -511836,7 +512023,6 @@ posmaster.co.kr posmicrosystems.com posnxqmp.ru pospeeps.com -posqit.net possessionnow.com possible.re possopagar.com.br @@ -512472,7 +512658,6 @@ prishaartcreations.com prisidmart.com priskat.net prism-photo.com -prisma.fp.ub.ac.id prismaxis.com prismfox.com prismware.ml @@ -513064,6 +513249,7 @@ protech.binarybizz.com protech.mn protechcarpetcare.com protechgroup1.com +protect.mimecast-offshore.com protectiadatelor.biz protection.ominenergo.gov.rsmart-testsolutions.watchdogdns.duckdns.org protection.pecol.eu @@ -513145,6 +513331,7 @@ proxima-solution.com proxy-ipv4.com proxy.2u0apcm6ylhdy7s.com proxy.hueaudio.com +proxy.qualtrics.com proxygrnd.xyz proxyholding.com proxyresume.com @@ -515658,6 +515845,7 @@ redlk.com redlogisticsmaroc.com redloop.io redlotusevents.com +redm1az1.000webhostapp.com redmag.by redmarcial.ossmarcial.com redmediasigns.com @@ -516829,6 +517017,7 @@ rkbicycle.com rkcable.co.in rkfplumbing.co.uk rkinstitute.org +rkkrstdygorgiousejbg.dns.army rkkrstdygorgiousejds.dns.army rkkrstdygorgiousejtw.dns.army rklkpgcollege.com @@ -517385,6 +517574,7 @@ rotiyes.co.id rotoblast.org rotor.olsztyn.pl rotoscoop.com +rotronics.com.ph rott-mtr.de rotterdammeetings.nl rotulosalarcon.com @@ -517798,7 +517988,6 @@ runmagazine.es runmureed.com runmyweb.com runnected.kaiman.fr -runnerbd.com runnerschool.com running-bike.com runningcrewteam.com @@ -519321,6 +519510,7 @@ savemodificationgloballyfromthepinaltypo.duckdns.org savemyfile.3utilities.com savemyseatnow.com saveraahealthcare.com +saveserpnow.com saveserpresults.com savestudio.com savetax.idfcmf.com @@ -519998,6 +520188,7 @@ secure-net.tech secure-risk.namaskara.me secure-snupa.com secure.accounts.resourses.com +secure.activedirect.xyz secure.anchorssb.co secure.app-amazon.com.recovery-account.amazon.com.alphatravelmongolia.com secure.bodybuilderabs.net @@ -520675,7 +520866,6 @@ service.atlink.ir service.dawat.fr service.drnjithendran.com service.eftformotherissues.com -service.ezsoftwareupdater.com service.heritageimagingcenter.com service.hybridhomesteam.com service.idealfurnitureoutlet.com @@ -521180,6 +521370,7 @@ shareallfilesthroughsecureexchangesystem.duckdns.org sharebook.tk sharechautari.com shared-cnd.com +shared.outlook.inky.com shareddocuments.ml shareddynamics.com sharedeconomy.eu @@ -525546,9 +525737,11 @@ stdymjventsluzcafoik.dns.army stdymjventsluzcafsrp.dns.army stdymorcmmylntwincdq.dns.army stdymorcmmylntwinstr.dns.army +stdynbnbnewagedevixz.dns.army stdynbnbnewagedevsmn.dns.army stdynbnbnewagedevxaz.dns.army stdyneverwalkachinese2loneinlifekstgqm.ydns.eu +stdynmxwllminoragest.dns.army stdyperezluzcafeyzst.dns.navy stdypmrimelimtwstogy.dns.army stdypycsslwinnerscot.dns.army @@ -525579,6 +525772,7 @@ stdytoprehtwoyertwfd.dns.army stdytopreoneenversrw.dns.army stdytopreoneenvervaj.dns.army stdyunitedfrkesokoriorimistreetsmsttyr.ydns.eu +stdyunitedkesokokgst.dns.army stdyunitedkesokostdr.dns.army stdyunitedkesokostri.dns.navy stdyunitedkesokostxc.dns.army @@ -525588,7 +525782,9 @@ stdyworkfineanotherrainbowlomoyentstbmd.duckdns.org stdyworkfineanotherrainbowlomoyentwkgls.duckdns.org stdyworkfinesanotherrainbowlomoyentstfcp.ydns.eu stdyworkfinesanotherrainbowlomoyentstgot.ydns.eu +stdyworkfinetraingst.dns.army stdyzgchgcloudgostgt.dns.army +stdyzgchgcloudgostxs.dns.army steadyrestmanufacturers.com steak.wpress.dk steakhouse.com.ua @@ -526148,6 +526344,7 @@ strend.net strengthandvigour.com strengthrer.com strenover.ga +stressing.pw stressnada.com stretchpilates.fit strewn.org @@ -526839,6 +527036,7 @@ supercrystal.am supercutscissors.com superdad.id superdigitalguy.xyz +superdomain1709.info superdot.rs superecruiters.com superfacil.center @@ -526942,7 +527140,6 @@ support.m2mservices.com support.mdsol.com support.nordenrecycling.com support.nuvemit.com -support.pubg.com support.redbook.aero support.revolus.xyz support.servu.co.uk @@ -527287,7 +527484,6 @@ swiat-ksiegowosci.pl swicoservers.co.uk swieradowbiega.pl swifck.xmr.ac -swift-cloud.com swiftbusinesspay.com swiftee.co.uk swiftender.com @@ -528132,7 +528328,6 @@ tarexfinal.trade targas.de targat-china.com target-events.com -target-support.online target2cloud.com targetbizbd.com targetcm.net @@ -529713,7 +529908,6 @@ thacci.com.br thachastew.com thachvietstone.com thadathilfarmresort.com -thaddeusarmstrong.com thadinnoo.co thagreymatter.com thai-chana.asia @@ -531435,7 +531629,6 @@ tlcc.com.gt tlcid.org tlckids-or.ga tlcmoto.com -tldrbox.top tldrnet.top tlextreme.com tlfthelifefactory.com.au @@ -533032,6 +533225,7 @@ ts-deals.me ts.7rb.xyz ts0ev73.com tsal.com +tsapparel.com.my tsareva-garden.ru tsatsi.co.za tsauctions.com @@ -533259,6 +533453,7 @@ tunnelpros.com tunnelview.co.uk tunuvo.com tuobrasocial.com.ar +tuoitrethainguyen.vn tupibaje.com tupperware.michaelroberge.ca tur.000webhostapp.com @@ -534405,7 +534600,6 @@ unlimit517.co.jp unlimited.nu unlimitedbags.club unlimitedfreightco.com -unlimitedimportandexport.com unlock-king.com unlock2.neagoeandrei.com unlockall.neagoeandrei.com @@ -534731,6 +534925,7 @@ url-update.com url-validation-clients.com url.246546.com url.57569.fr.snd52.ch +url2.mailanyone.net url3.mailanyone.net url5459.41southbar.com url675.textilmallorca.com @@ -534934,7 +535129,6 @@ utterstock.in utting.org utv.sakeronline.se utv1.enliden.net -uujian.cn uumove.com uurty87e8rt7rt.com uutiset.helppokoti.fi @@ -536908,7 +537102,6 @@ voin.staysafe.pk voingani.it voip96.ru voipminic.com -vokasi.ub.ac.id vokzalrf.ru vol.agency vol2.pw @@ -537536,7 +537729,6 @@ washnworks.com washuis.nl wasidora.com wasilewski-online.de -wasimjee.com wasino.co.th wasobd.net waspha.com @@ -539076,7 +539268,6 @@ woaldi2.com woatinkwoo.com woclawoffers.fun wocomm.marketingmindz.com -wodfitapparel.fr wodmetaldom.pl wodsuit.com woelf.in @@ -541705,7 +541896,9 @@ yoyoplease.com yoyoso.nz yoyoteacher.cn yp.dcyazilim.com +yp.hnggzyjy.cn ypbb.or.id +ypddf.org ypicsdy.cf ypko-55.gq ypom.com.br @@ -541864,7 +542057,6 @@ yusukelife.com yuti.kr yuvann.com yuvikadvertisments.com -yuwaraja.vokasi.ub.ac.id yuweis.com yuxigon.com yuxuanknit.com @@ -543272,7 +543464,9 @@ zzznan.com ||51aiwan.com/wp-content/uploads/2017/12/59gqscz/oamo/commercial$all ||51aiwan.com/wp-content/uploads/2017/12/59gqscz/oamo/commercial/$all ||59.80.44.99/indonesias.me:9998/iexplore.exe$all +||654tyfcdr4654fytfy.top/syzsnntnps.vx$all ||68yuanzhijia.xyz/wp-admin/y2kbcwlezlkontymoscer2ggetzbjqxb0oybicpckgboagxr7t/$all +||6ip.us/$all ||6ixbling.com/wp-admin/tv9qgaxqruvcumabdu/$all ||6ixbling.com/wp-includes/mhgvqsd8p87n6v5bqjykxegimlflzlct7lda7y58wfs8zbtf2lsa11vva/$all ||783f9760-0045-4ae4-b218-69ecc15a3933.s3.us-east-2.amazonaws.com/ca/versium.exe$all @@ -543310,6 +543504,19 @@ zzznan.com ||99ee6261-b333-4998-8256-14e87061e63c.s3.amazonaws.com/usa/undelete.exe$all ||9jacology.com/dragon-quest-cxpij/2/$all ||9scroob.com/wp-content/themes/islemag/css/sserv.jpg$all +||a.pomf.cat/avhmcy.exe$all +||a.pomf.cat/gziqpm.exe$all +||a.pomf.cat/ioxyfx.dat$all +||a.pomf.cat/kiwqkn.exe$all +||a.pomf.cat/madeuz.exe$all +||a.pomf.cat/nmzemw.exe$all +||a.pomf.cat/qhsyxo.exe$all +||a.pomf.cat/qqksvz.exe$all +||a.pomf.cat/uhfhfh.pif$all +||a.pomf.cat/vmwdhb.zip$all +||a.pomf.cat/yckrnz.exe$all +||a.pomf.cat/ymfxrc.jpg$all +||a.pomf.cat/yygruz.exe$all ||a.top4top.io/p_1485hd0f51.jpg$all ||a.top4top.io/p_15275aw691.jpg$all ||a.top4top.io/p_15282t2hy2.jpg$all @@ -543487,6 +543694,8 @@ zzznan.com ||anilcreatives.com/chevy-express-cqnac/uxz/$all ||animalbliss.com/xmlpl.php$all ||animematsuri.com/ups.com/webtracking/jx-63349309/$all +||anna.websaiting.ru/facturas-pendientes$all +||anna.websaiting.ru/facturas-pendientes/$all ||anonfile.com/kcsc1bu5bb/instagramchecker2019_exe$all ||anonfiles.com/baqbofleoe/nemesis_v2_exe$all ||anonfiles.com/l3pcw9w5p0/osno-crypted_exe$all @@ -543507,7 +543716,6 @@ zzznan.com ||app.box.com/s/4d9mmj01l7lu3a9l9wolep58ceabre6q$all ||app.box.com/s/bowk0dszzo5m272wsclbulh301wiqpjr$all ||app.box.com/s/xqxxhkh7be55cflkzf19toiqy1x6e49h$all -||app.casetabs.com/n/p7nx8575$all ||appengine.google.com/_ah/logout?continue=https%3a%2f%2fswptransaction-scan2034.s3.ca-central-1.amazonaws.com%2fdoc102018.doc$all ||appengine.google.com/_ah/logout?continue=https://swptransaction-scan2034.s3.ca-central-1.amazonaws.com/doc102018.doc$all ||appliancebuddy.in/wp-includes/m7r/$all @@ -543583,7 +543791,6 @@ zzznan.com ||atlantafalconsjerseys.us/gas/e1weiaah7/$all ||atlanticgrupo.com/n/8on3xu0ovf/$all ||atom.lk/wp-content/dl/$all -||atpscan.global.hornetsecurity.com/index.php?atp_str=afw-6ropadyx-4diefo4dbv3e_xmh3-ype0mhrlsyeuhwsqoeebzlbafyf6_bdljtesgdugeymxapym1fsyhxkyylpvifpr0hnjo3w92mx4bqea-rhcujbljf7xs-ie79eig5o9b_hcfg9ygyzdkrnzco-swcs_bodliaxlfflgccv-hkcqkgjzmxadbpvzglcgsaecd8rv4if7ngcqkrxprwlykmzxyjhyncp2kigw8_rjsdchhxd9niyyjjb1jovi-wm8urvrdop7bvnkrinv2g2ef433yzwetxfwlzgfnehnqbtdbrst1zv1hncyrnd3tvjwjjwn-3c5irkywidug4sagusduvudmdsm6oim1nja1ody3mwvlzdyjojoj2og-0apvymvmjggu-mi8gg/$all ||atrocity.de/blogs/irb9/$all ||ats-tx.com/old/f1x/$all ||ats-tx.com/old/hnke8j/$all @@ -543640,8 +543847,6 @@ zzznan.com ||bartesol.org/ct5kg0tvxm$all ||baskbay.co.za/leditimize.php$all ||bayyanahost.es/wp-content/6wesjogdnpsbwkck2qwo7fh4m9rlsj7my0cjpe0up5c6mlqbhcxcg/$all -||bbgroup.com.vn/wp-content/32451/$all -||bbgroup.com.vn/wp-content/statement/pwc9q80/4wugo9y-3518181981-77685-cl9yz8-1dbtjnuln9i/$all ||bborton.com/wp-includes/doc/uzccdhe54raolyvznx2i/$all ||bbuseruploads.s3.amazonaws.com/015be6a8-7f07-4226-b11c-233251144bcc/downloads/1f1de1b7-8ea1-406c-b2b7-ffb959450abc/feel.exe?signature=zgsoxqt8yaao%2b41usfex6r7jcha%3d&expires=1580382322&awsaccesskeyid=akiaiqwxw6wlxmb5qzaq&versionid=ots516nt_tapdsh3cmcfavxkqmahhrgs&response-content-disposition=attachment%3b%20filename%3d%22feel.exe%22/$all ||bbuseruploads.s3.amazonaws.com/015be6a8-7f07-4226-b11c-233251144bcc/downloads/ac446342-e9f7-4d19-808d-8c88446b0ae0/gett.exe?signature=nqsqhhcwgjyyawcqgsjpmgba96c%3d&expires=1580382307&awsaccesskeyid=akiaiqwxw6wlxmb5qzaq&versionid=swfu5extujl9bp_wrioqj_n2v8qsovr0&response-content-disposition=attachment%3b%20filename%3d%22gett.exe%22/$all @@ -543751,8 +543956,11 @@ zzznan.com ||behash.com/work.sh$all ||beidou.run/acoemeti/gaa/$all ||beidou.run/acoemeti/vgx/$all +||belairinternet.com/wp-includes/9c8gi-fhbzv-xflschcjz/$all ||belcineloweek.ru/6sufiuerfdvc.exe$all ||bellevueairductcleaning.com/wp-admin/zk/$all +||bem.hukum.ub.ac.id/vdtdcc2636944/scan/rechnungszahlung/$all +||bem.hukum.ub.ac.id/wp-content/payments/012019/$all ||bemcasadossoniacosta.com.br/wp-admin/overview/m6ezo1c-35569/$all ||benzatine.com/wp-admin/vafw4/$all ||berkeywaterfilterplus.com/wp-admin/a/$all @@ -543768,10 +543976,6 @@ zzznan.com ||bhaktivrind.com/cgi-bin/jbbb8/$all ||bielert.de/wp-content_old/8gstxi4pzoatadlwevsukq4bdia8friu4vvnrsy9ssl1uabnmxwcree8dpetaugejumd/$all ||bienhoacitysq.com/wp-content/xyp/$all -||bietthudep902.com/rwevpv/026/kaufvertrag_026_21052020.zip$all -||bietthudep902.com/rwevpv/984295264/kaufvertrag_984295264_21052020.zip$all -||bietthudep902.com/rwevpv/kaufvertrag_098_21052020.zip$all -||bietthudep902.com/rwevpv/kaufvertrag_74788472_21052020.zip$all ||bigdataonlinetraining.us/intellipaat/dkxyqqsci/$all ||bigdataonlinetraining.us/wp-admin/cd7-3ih-360376/$all ||bigfile.mail.naver.com/bigfileupload/download?fid=v/r91zflpzewaabjk3e5kquwhqumkx2maxuxkxmdfoudhqu9kqvxaa2qaxvja6iopouxkrumkrmqfrkmfxkck6m/fruqpxivfrj4a6u=$all @@ -543846,6 +544050,7 @@ zzznan.com ||bitbucket.org/busrakulcu/busra-kulcu/downloads/browserguncelleme.apk$all ||bitbucket.org/busrakulcu/busra-kulcu/downloads/browserguncellemesi.apk$all ||bitbucket.org/bzr-company/fortune/downloads/miner.exe$all +||bitbucket.org/clubhousedev/clubhouse/downloads/clubhousepc.exe$all ||bitbucket.org/codedevelop/sourse/downloads/az.exe$all ||bitbucket.org/conan2019/download/downloads/clipper.exe$all ||bitbucket.org/coverengineer/2020/downloads/main.exe$all @@ -544359,6 +544564,7 @@ zzznan.com ||cafeponton.nl/bin/multifunctional-sector/g3vmhszkgb-5frzpzwqia-portal/2ypasrqt3h-ut0816v20t97y9/$all ||cafeponton.nl/bin/parts_service/a72xoqz31937247035rgmoh6edecbdwqiwa8f/$all ||cafeponton.nl/bin/payment/vlk0jnl/oa006201284964852292audvywk0fd54p/$all +||callsmaster.com/azureink.co.uk/sec_zone/us/sign/com/open_docs/$all ||calltorepair.com/assets/09erzff/$all ||camargobarcelos.com.br/wp-includes/djhvf4ald9xaalbaxcsr1gqqmwvjigyno1g0q9lzyflzadsz8fltetrxvdbt/$all ||camiloyepesph.com/high-times-zkufb/kecprg1v0czd5oxlpgoo6moyw5hjhszq4guj0zxxeumuzae7wmp3m6y/$all @@ -544967,6 +545173,7 @@ zzznan.com ||cdn.discordapp.com/attachments/775201330172133379/785293636388519936/dhl_receipt.img$all ||cdn.discordapp.com/attachments/775238059083038744/818196372763181116/qtuar$all ||cdn.discordapp.com/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq$all +||cdn.discordapp.com/attachments/775238059083038744/829993648186851338/pslmlyfnpzgsgitrwwvalcfunumfmac$all ||cdn.discordapp.com/attachments/775303846645334037/784920798212784158/x2.exe$all ||cdn.discordapp.com/attachments/775537284656791553/779777829800771584/androidupdate.apk$all ||cdn.discordapp.com/attachments/775587299214753796/776303350953017414/ozsl506$all @@ -545198,6 +545405,7 @@ zzznan.com ||cdn.discordapp.com/attachments/825372018244583454/826848185246023750/loaddd.exe$all ||cdn.discordapp.com/attachments/825372018244583454/826848348342059008/zeppelin.exe$all ||cdn.discordapp.com/attachments/825372018244583454/826848405258633277/build.exe$all +||cdn.discordapp.com/attachments/825372018244583454/830455061724528690/v1.exe$all ||cdn.discordapp.com/attachments/825686740106870837/825687235973087262/chucks5000_leiqr231.bin$all ||cdn.discordapp.com/attachments/825686740106870837/825688243248562176/tobi5000_pskkckhmf118.bin$all ||cdn.discordapp.com/attachments/825686740106870837/825982118672597042/newdoggy5000_splqq85.bin$all @@ -545244,6 +545452,7 @@ zzznan.com ||cdn.speedof.me/sample4096k.bin?r=0.1570982201$all ||cdnrep.reimage.com/prot/protectorpackagerr2023.exe$all ||cdnrep.reimage.com/ver/reimagepackage1874x64b.exe$all +||cdnrep.reimageplus.com/rqt/reimagerepair.exe$all ||cds.d8u8a5x9.hwcdn.net/cat.exe$all ||cds.v2v8s6m2.hwcdn.net/auto/ah_sa.exe$all ||cds.w2w3w6q4.hwcdn.net/auto/ah_sa.exe$all @@ -545265,6 +545474,7 @@ zzznan.com ||cheapwebvn.net/wp-content/cache/inc/$all ||cheapwebvn.net/wp-content/cache/uzlpqwbgic/$all ||checkvisadebitcardbalance.com/fda-approvals-8hh2l/1te6bhsbwbijbe3/$all +||cheerfullydo.com/data/nhtlrr/94046/nbar_94046_29052020.zip$all ||chenqiaorong007.com/wp-content/inh1q4efmt/$all ||chg.org.uk/sites/dokumente/zahlung/zahlungserinnerung-vom-juli/$all ||chiangmainightsafari.com/wp-admin/lrpiggci/$all @@ -545294,7 +545504,6 @@ zzznan.com ||cjoint.com/doc/19_02/ibdvoj3sdpk_reservation.zip$all ||cjvabogados.com/u4rif/paclm/$all ||cl.ly/390j3n40002a/download/new10.zip$all -||clasificadosmaule.com/wp-content/sites/szs9n6pvn37fgafd911ss_osiby1-753587659577/$all ||clauguidetti.com/kx852k.jpg$all ||cld.pt/dl/download/03a207e4-0c76-495a-81c8-68ce2f5ab18c/999874arq4100025d0002147p1524748551.zip$all ||cld.pt/dl/download/0448ea43-6cef-4895-a9e5-9ecd965fa663/1941rtadocmrtpasd1535712924.rar$all @@ -545337,12 +545546,13 @@ zzznan.com ||clinicadentalimagen.pe/zohoverify/tbcr-4b8x-6370/$all ||clinicaspaodonto.com.br/wordpress/bdbqfdrtoglsblhapxkrl/$all ||clocktowercommunications.com/wp-admin/sre9o6j/$all -||clodura.ai/wp-content/qq46l73r-xole-35619/$all -||clodura.ai/wp-content/vlfqxilre/$all ||cloudme.com/v1/ws2/:dr404/:22cted/22cted.exe$all ||cloudme.com/v1/ws2/:dr404/:microsoftoffice/microsoftoffice.exe$all ||cloudme.com/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz$all ||cloudme.com/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar$all +||cmg.asia/wp-content/uploads/asifb-0wxsmxdavkvdu2_okcqpxaws-nk/$all +||cmg.asia/wp-content/uploads/dok/bkmrgzxziezodqvcvwbtcqinn/$all +||cmg.asia/wp-content/uploads/inc/rvvm3ragsf/$all ||cmnbbnshgsadrrefasderg05g.s3.us-east-2.amazonaws.com/p-5-16.dll$all ||cnr.org.br/validacao/sendincverif/legal/trust/en_en/201903/$all ||code-it-consulting.com/afrp/sbr40gfr6iddlktuef9b5xr0pgo/$all @@ -545440,6 +545650,7 @@ zzznan.com ||crooks-taylor.com/1676470973/1/$all ||cskconsultingengineers.com/config/browse/mjrvdqsm/049qbg90374564y3ne1s8e44jx9cga7/$all ||cskconsultingengineers.com/config/private-resource/external-kzpdj4y5f-g7wwtxu8v8nvw2/wscmf-ckkbphny/$all +||cuahangvattu.com/cofd/closed_sector/458kmxdg6a0ywt_wum4a4kmr01g2_cloud/46311257516564_txxafmu2a/$all ||cube-llc.com/wp-content/uploads/payment/zn471217954cpauut/6621937/aem-etpd-aug-07-2018$all ||cubspreschool.in/cgh/wryjqw46w4tjjrh.pdf$all ||cutt.ly/6glhgfc/$all @@ -545453,17 +545664,6 @@ zzznan.com ||cxzxzxzxzzxzx.s3.eu-central-1.amazonaws.com/evdekaliyorum.apk$all ||cyberesa.net/j1py2bx.zip$all ||cygwin.com/ml/cygwin/2019-04/msg00011/new_april_quotation_%23021103211_doc001.jar$all -||d.top4top.io/m_18677sx8h1.mp4$all -||d.top4top.io/p_101949r3r1.jpg$all -||d.top4top.io/p_12014tn3x1.jpg$all -||d.top4top.io/p_1519dkp831.jpg$all -||d.top4top.io/p_1567m7an31.png$all -||d.top4top.io/p_1638e5yhh1.jpg$all -||d.top4top.io/p_16819gzhe1.jpg$all -||d.top4top.io/p_1681wdig21.jpg$all -||d.top4top.io/p_169387gdp1.jpg$all -||d.top4top.io/p_1978um31.jpg$all -||d.top4top.io/p_794twvdh1.jpg$all ||d1zi.com/wp-content/ai1wm-backups/11khyzhopks3rkhqu/$all ||d2comm.averydennison.com/runcorn/timbscanprint_1_0_0_4/vfscanprint.exe.deploy$all ||dabaibai.com/wp-includes/public/831526720787/b291kcjqathux-0055/$all @@ -545575,11 +545775,6 @@ zzznan.com ||dentalsearchsolutions.com/wp-admin/ajcjsljig/$all ||dentistenice.fr/wp-content/available-h8c0mi-ohqxnm8d2z/guarded-0719135-l6rniu3noo/sfkd76hr5exyog-8v737/$all ||depannage-vehicule-maroc.com/wp-admin/c/$all -||depozituldegeneratoare.ro/jgipmpwb0g$all -||depozituldegeneratoare.ro/jgipmpwb0g/$all -||depozituldegeneratoare.ro/open-invoices/$all -||depozituldegeneratoare.ro/past-due-invoices/$all -||depozituldegeneratoare.ro/telekom/rechnung/112018/$all ||dequon-autopro.weebly.com/uploads/1/3/4/8/13485243/troller_v1.exe$all ||dermascope.com/hwdvideos/arqfq.bin$all ||dermascope.com/images/product.png$all @@ -545670,6 +545865,8 @@ zzznan.com ||djsrecord.com/wp-includes/abop/$all ||djykybumlu.s3.amazonaws.com/video-6103.exe$all ||djykybumlu.s3.amazonaws.com/video_player.exe$all +||dl-gameplayer.dmm.com/product/apkggame/giga_baldrbringerextendcode/giga_baldrbringerextendcode/win/src/content/data/data/uninstall.exe$all +||dl-gameplayer.dmm.com/product/apkggame/nel_narikiri/nel_narikiri/win/src/content/data/%e3%81%aa%e3%82%8a%e3%81%8d%e3%82%8a%e3%83%90%e3%82%ab%e3%83%83%e3%83%97%e3%83%ab%ef%bc%81.exe$all ||dl-tornj.ir/wp-content/vvevatafqjravmbzpzwy6kzsmbyp2k3zsmhxfwsd/$all ||dl-web.dropbox.com/cd/0/get/bjln5zjy34vnnedqqrxayoz6usv5pbw_rsnjdqfkuuxtizwmo3odzemreetkjmqrut8n_crp55bedhxveeafavwwtt_jvi12lgpk9izpyrzr14dhe0wqtco4qc6dvog4crs/file#$all ||dl.dropbox.com/s/2rkjxc3kbui8rz1/imagen00944272formatopdf%20imagen00944273formatopdf.uue?dl=1$all @@ -545967,6 +546164,7 @@ zzznan.com ||dl.dropboxusercontent.com/s/zetrtbtm7j4elbz/flashplayer_42.38_plugin.js?dl=1$all ||dl.dropboxusercontent.com/s/zhbextywkev7rlm/flashplayer_41.20_plugin.js?dl=1$all ||dl.dropboxusercontent.com/s/zlme2a94peldftk/flashplayer_41.16_plugin.js?dl=1$all +||dl.mydown.com/download/be5abe2da15f5d91d4f29cbf80d5d581/509451398_6/newsoft/tsbrowser_724_4.0.7.20.exe$all ||dl01.s3.amazonaws.com/offers/2/chrome_search.exe$all ||dl02.s3.amazonaws.com/offers/2/chrome_search.exe$all ||dmaldimed.com/97499dnxqomin/identity/commercial$all @@ -546311,8 +546509,6 @@ zzznan.com ||doc-0s-68-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/q5qe5q1uvep35ccrbr1g80sub349agop/1543320000000/05984462313861663074/*/19esasjydhkmq-f80tgnobrth0yudmgzy$all ||doc-0s-68-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/stiolst1g6i8vasis6jegpqd2b04imod/1543327200000/05984462313861663074/*/19esasjydhkmq-f80tgnobrth0yudmgzy$all ||doc-0s-70-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/6i0lbore8mloquf0s0inmqhshir3jrs8/1542996000000/08141031105246785918/*/1frfmibmbtnbemiolrz9aktbpn7jsr6sr?e=download$all -||doc-0s-7c-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/5bvsb5ttjjkmftcv00posgt0a2lsq6pq/1579680000000/03683026262266078671/*/16rew7icapzdfonn9ubjb-owowh_uiuk5?e=download$all -||doc-0s-7c-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/ml48mc3h16rmkppielv4ukafil7iun3f/1580112000000/11177655664072506190/*/1nybpfnssg325879zor4tfv-8jgmxnlj2?e=download$all ||doc-0s-80-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/nc8mtg3folbcd5haj9bc709btbqsqnoh/1578895200000/09593966995115687919/*/1k8z46ungjn3fizc5ih1syhdji3zbao1w?e=download$all ||doc-0s-8c-docs.googleusercontent.com/docs/securesc/4jc3o0kkf5136n14s0obie5i3338237o/crl1nl7rrivhhkpl1l4rck0f9km8v2t5/1579795200000/11177655664072506190/09384270791473589425/1m-hgvq0i-3aqo0w0pgga_sqanki6ahj3?e=download&authuser=0&nonce=3jhgojl8vukmm&user=09384270791473589425&hash=qa8cgr1tgr33cqmmn859u2qkmrrbrk5m$all ||doc-0s-8s-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/8ne944b43812vrcuv9954p7n8r2suam3/1547575200000/07335649321361492730/*/1dypty3z5gun_lf52eicq3h2hezuqwpkq?e=download$all @@ -546327,8 +546523,6 @@ zzznan.com ||doc-0s-bs-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/ene3b5nenits168gjf4lnni1kuie3jnr/1552039200000/11569688848916399575/*/1hgnjd29qwsmeort3zpfpwxxm8fdd3ygq?e=download$all ||doc-0s-c8-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/4b7n6eqfl7n5boc61bjf0q7b5mksc6lp/1555516800000/16964281332718813838/*/1qerkwklbb2tcmxsqrvylgwn7viz4xhhy$all ||doc-0s-c8-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/uumujnqdoksb2iq336es2fnlcgjkfjop/1601921475000/08069565659861269988/*/1hqi4mjve0ifpo5vwi0okysf2eakt1ljz$all -||doc-10-0c-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/gc8dsf1456d9gmibfmg7o25gs6ectrmo/1551816000000/14063452590226117103/*/1_jo_vxwckb1cbttkzgd7nmqezfuujvhb?e=download$all -||doc-10-0c-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/nhbo71cjafudtbkd3ls3bismqvuj8ig6/1549828800000/14063452590226117103/*/1_jo_vxwckb1cbttkzgd7nmqezfuujvhb?e=download$all ||doc-10-28-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/r5fjotq4qok8a7pk9sain44inha7ocft/1580104800000/13535128519197762172/*/1topkmo_eawlxskmpgmjbhsgrjusoj8kc?e=download$all ||doc-10-34-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/hgrdjpkp37sdv3rd3miim43hdd84tv71/1580364000000/06792381463910506630/*/1yrlvbuhbbtzusz9amngr4c6_x7i0db6u?e=download$all ||doc-10-44-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/sg56hqhomngdvphgv21g37ft31vqvjql/1581605100000/08658714528148673336/*/1jzbbjgpebq0xdke_vvydr_dmxwsxuef4?e=download$all @@ -546346,7 +546540,6 @@ zzznan.com ||doc-10-88-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/gs4tf9lgm5e90i6qvfvo78fvi78b2ba7/1579701600000/01423698199670842299/*/1fpnbcmqkjsh5dp_kwvkbusccnzjezbyo?e=download$all ||doc-10-8g-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/bkavgvoa0anttjt05vct2lecdjdofugu/1552564800000/10901782374314873973/*/1os_ldyiqmoy8rhs0ylu3odlgfmf7cdk0$all ||doc-10-8o-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/djvcoprs7ik42sgsnpcn1rhauljdcper/1579586400000/10077574138565375691/*/1zcfkyuetnb51zhkvmx3hm3r7xb2himqu?e=download$all -||doc-10-8s-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/r4rrt36iqlpu59et4hbr6bdvscb5lcno/1547150400000/07335649321361492730/*/1k4wwzw-ai239shkc3qbksuv4rpimdmio?e=download$all ||doc-10-98-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/8h1v715bmm41gaeni9q0ca6vqpfptos9/1580104800000/03594737999780208267/*/1csdtiyql0cldrstrazrnftmoubtfzwkk?e=download$all ||doc-10-98-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/99uiri3hlipm4tt7mrai16mbv23797h2/1579003200000/03594737999780208267/*/17eycga79cao3bkde5ov9lh7j_sz1iv-l?e=download$all ||doc-10-98-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/dvfn4tg87qm827b127b5ibb5uo3k8god/1579939200000/03594737999780208267/*/1sd3mqdidoetuy3tmzwujjx2s9kbv6zra?e=download$all @@ -550163,6 +550356,7 @@ zzznan.com ||drive.google.com/uc?export=download&id=1dyhilkcw_idrwtoquewgui5bz3eounv5$all ||drive.google.com/uc?export=download&id=1dz8-iw3l5e1shc2unot8s6v5bweh5n3j$all ||drive.google.com/uc?export=download&id=1dzw-mtd4b5a3jvccvvkdcjsd-bsoqst0$all +||drive.google.com/uc?export=download&id=1dzx_cflers_zntlrip3fhbxb5who03u0$all ||drive.google.com/uc?export=download&id=1e-5ug_mz0zphngg9huvc1mzpx4_qfaw7$all ||drive.google.com/uc?export=download&id=1e-eglblcxhjqkum_hk8mvkg1-p3uvh8n$all ||drive.google.com/uc?export=download&id=1e-gyqr_ugzsyy31zw40u-cprrw15-_tw$all @@ -552439,6 +552633,7 @@ zzznan.com ||drive.google.com/uc?export=download&id=1xbdlhwd5vdtco07vt5-ac0u37e-nycgg$all ||drive.google.com/uc?export=download&id=1xbeqbw67xz4iqpu8dgmdrlkpa6kzotes$all ||drive.google.com/uc?export=download&id=1xbfd2msdcw6hm2swjxtogmijoiuefkqe$all +||drive.google.com/uc?export=download&id=1xbp7hvw2ybwjrftbvdkjvwzrfuk4ope9$all ||drive.google.com/uc?export=download&id=1xbwjfdd21zot8vazb0egqi5kuzw90t7o$all ||drive.google.com/uc?export=download&id=1xc1vhtuzdeuqp-hkpnrix8ursqwurrel$all ||drive.google.com/uc?export=download&id=1xc5botlfmsw23xotatnddimh8r-btiv7$all @@ -562317,7 +562512,6 @@ zzznan.com ||easternstores.in/cgi-bin/a4nuczkqntpfsijc0p5uie880gkkkq6pb7hloxzzpgxyk/$all ||easternstores.in/cgi-bin/statement/pw0aztotm3-083/$all ||eastwestsurveyors.com.au/gc25-forklift-etwcf/nwqfamdxssmx6szvjd6qjf3pmakkkzzlvpizyhdtlkcvpjtsbxdtdssbotsqyijbghk/$all -||ec2euc1.boxcloud.com/d/1/a1!1v6vibwx7vlie5y8jj5xm5ipoc9jdxze8ck08lu22jdqvqu0y23hledgazmxqbcukhlgg95jbfv9p6e7n10-td4omxyxferhngbpik8idewoo81utbhmygy4yzt8uxvxi_dnrwzvwtlndrqwk6hotxffg8jkpj8-j3bybrd7yw7n9nyzemoqeelvbjthue6wa3yuozggyesvvg1o6919_nqqhatm_0mampn9-_jtxf4s-ugi1s9il7i1vz-euwgqoqgfey5ojdw8thvvonrqk07jcvnmdwqnxx73l0zvlypuue7zjxsucd5ngxrgnlrokmgqml3gqmvtclnbzspt-4hcnbybe8gfkg2psuvv1aq_omqri7_jbjnodn0k3rmscvbihzzjag_jacj95hxys2nqu5-avfi3mcsbykrgcfcd0f0ubmxy8_u-adp_am2uyu7wjbtlhrmdeya-wvab9_d_rsbzn6qhbobnfb-ijabnqe8ynoztvmmj5-48vxc-gimyw84qv5vvoewlfuazz6lhawnqlsehdoko20t5tsgdq-ixnr9upyrvqgkqg9hpkx37rcfrizch7msfmqqhgbz-2kepa7cuisq2u8z21psh44kaslvzjjckzbjxaazonnqpicscjypbbx8vqrtok7qhix5gnjmofxjghi8dnzcdrvrzwwf9qowdqzmqle38iykwpk_43qarzcyv53ecglsevfziyq5bqgscnvlv9ypi3dlnhklmijhb_-nal1ma_y7hazsqeqks-c-_2pporvy4fabaa7ppnt7cji5vsu1jcfdqk3xg_voorzho8qzmelylrsddbg1k4rbzk7hhqwn_sbr0owykfhvovjqzq1lssanl7n3sjbh_adgrgglq2ojvyqsklvlnet4-3dr8qnksaaphkhmfzaggxffhkiuks7n6dth09683x8t1ape47jo8a3du24wyvolahwxr0i91czhb9fphq2_qbhc66ww4pynr2kvclrajdii50jao1znpe0nbdtqdqc9c4dladdwtrfnh-1lywnfvm1szr-fky7qtf9ysdut3htypftcw-zwftt5yxvxpff6-xxcd599rg8fr2-inwced5f8d3vc_lu3sy9p_-mfnsp_urjy0f9rcy3lnsgb_$all ||ecoachings.in/old/p4hyzkfvgyg3ttigdtdrtzea94vatgnxm/$all ||ecodetect.com.br/wp-admin/burtjklsc/$all ||economplast.com/lypumytb/d4/ce/a64bze4c.zip$all @@ -562759,6 +562953,7 @@ zzznan.com ||gbimkd.org/wp-includes/mzyzedwyuhnvfwtty47ey0o5tkuyazh0oxis/$all ||geethaseetharam.com/c7p1kb/esp/0z1fo6rx66ql03_hfyuk3o-9956557068515/$all ||gem4gt.weebly.com/uploads/8/3/4/4/83449656/open_to_generate_gems_.exe$all +||gentecoyol.com/riot-vanguard/hb/$all ||genzmag.com/ratings/vq8n/$all ||geocities.co.jp/heartland-kaede/2774/winduke.zip$all ||geteffective.biz/aloiuy.exe$all @@ -562971,8 +563166,6 @@ zzznan.com ||guojiazui.com/b/y0qnnwbk/$all ||guridosinferno.s3.us-east-2.amazonaws.com/0.zip$all ||gurtravel.ge/rechnungs-details/$all -||gw.daelimcloud.com/website/mail/attachedfile/largefiledownload.aspx?key=mjqtuleptqynziynzymrkleptc0mjcyntmmvfjdsz1zjk1ot1rjpu4%3d$all -||gw.daelimcloud.com/website/mail/attachedfile/largefiledownload.aspx?key=odgtuleptq0mjgzntqmrkleptc2otc4mtimvfjdsz1zjk1ot1rjpu4%3d$all ||h.top4top.io/p_14754cwzr1.jpg$all ||h.top4top.io/p_1593skpl71.jpg$all ||h8y9u9b2.ssl.hwcdn.net/apsfadexpnr/dynlink_1594433895121.exe$all @@ -563073,6 +563266,20 @@ zzznan.com ||hotelunique.com/teste/llc/rq5rqnvq6wbql7ghdoua/$all ||hotelunique.com/teste/lm/sbdzr/$all ||hotelunique.com/teste/oxda9j0bvf/$all +||hotgifts.online/1291994a7f3a5816fb62a8f825076dfb/winboxscan.exe$all +||hotgifts.online/1da70a31e6545d7c5611b2410a4dc351/updateprofile.exe$all +||hotgifts.online/616127c527f57b3aff6bbbf3e00c48d7/winboxscan.exe$all +||hotgifts.online/6ab91d75132f7aa1085b1cea8df09d05/winboxscan.exe$all +||hotgifts.online/71eb063309e71fb131b8fec3804e8ce9/updateprofile.exe$all +||hotgifts.online/73a5c1a5cb2a3c4095bad22fd413d98e/winboxscan.exe$all +||hotgifts.online/9050b32a16e63abe28c544048fdebafc/winboxscan.exe$all +||hotgifts.online/9db8ff1707781393a2f8f4843028bf62/updateprofile.exe$all +||hotgifts.online/a7b6d8f0cc006e65b9f5707c817a8523/winboxscan.exe$all +||hotgifts.online/app/app.exe$all +||hotgifts.online/app/app171.exe$all +||hotgifts.online/app/e7.exe$all +||hotgifts.online/app/watchdog.exe$all +||hotgifts.online/bc751a3f103b5151e09550385e5e50d3/updateprofile.exe$all ||hotshot.co.mz/boondoggle/pscxnojjerqag8xtjgaef4orzjkqqufxifya/$all ||hqchiropractor.com/wp-admin/ikxfshixbob2kquj9ighbtsauqtqrtm0dq/$all ||hqdecig.com/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/$all @@ -563085,6 +563292,8 @@ zzznan.com ||htl.li/gm6y30lvnkn$all ||htmedia.net/en_us/doc/invoice_number/322374698567650/uyuif-6iv_cyex-x7/$all ||hugeturtle.com/wp-content/lm/clcolwrvd/$all +||hukum.ub.ac.id/order/document.zip?0774181353[document_pdf________________________________________________________________%20.exe]$all +||hukum.ub.ac.id/order/document.zip?0774181353[document_pdf________________________________________________________________+.exe%5d$all ||hungerplanet.in/phwmlaegglci/l/fhherxnrt.zip$all ||hwcdn.net/g5k6t6n2/cds/apdata/installers/auto/exe/starter.exe?b$all ||hyliza.com/solubility/udtn/$all @@ -563093,7 +563302,6 @@ zzznan.com ||i.cubeupload.com/euev6n.jpg$all ||i.cubeupload.com/ez3vpt.jpg$all ||i.cubeupload.com/gmetap.jpg$all -||i.fiery.me/5vdk.png$all ||i.imgur.com/3zblzb6.png$all ||i.imgur.com/6q5qhhd.png$all ||i.imgur.com/6wijvdz.png$all @@ -563242,7 +563450,6 @@ zzznan.com ||ivfcyprusglobal.com/znrxe31ljkxl.php$all ||izu.co.jp/~saigo/25072019_1120.xls$all ||izu.co.jp/~saigo/c354883.xls$all -||j.top4top.io/p_14674n4b11.jpg$all ||jabiru.net.au/mar-15-06-52-49/view/$all ||jacobgrier.com/modlogan/doc/h94tf3jnk_1y68xpk5d1-72633274711507/$all ||jaguarsjersey.net/i64vmj6cso$all @@ -563348,6 +563555,7 @@ zzznan.com ||klaustrofebia.ru/6jhfa478.exe$all ||kleberribeiro.com.br/wp-admin/payment/ehznl38duciepvo/q5/$all ||ko-racingshop.com/account-eu/y6w/$all +||kodjdsjsdjf.tk/mine.exe$all ||konev-dev.ru/test-trucker/bsjvc9kzu7mwplxqxttz5cwcjiommuzsi8hvuhgvq3tr9mouumawc4ss7qyuhjbg/$all ||kongjiantang.com/s/it1c/$all ||kongjiantang.com/s/qobgq5n36wjyrywarkntoqcn0j1seaye0b/$all @@ -563512,10 +563720,6 @@ zzznan.com ||lgpass.com/images/common_resource/interior_cloud/637368803912_d35jil4kauy8qn/$all ||lgpass.com/images/d1q66rszmw123555/$all ||lgpass.com/images/wk128/$all -||library.mju.ac.th/2018/cfjdes/$all -||library.mju.ac.th/2018/mnnw0cr-ptv5a-370268/$all -||library.mju.ac.th/2018/rn-72c-0657/$all -||library.mju.ac.th/2018/zoipdun1a0/$all ||lidaautoparts.com/wp-admin/plcy4qz3/$all ||life-and-spice.com/uqvvclish1323826/rechnungs-docs/form/$all ||lifejordan.com/payment%20confirmation%20for%20over%20due%20invoices-191020gx.jar$all @@ -563537,8 +563741,10 @@ zzznan.com ||lionmarketingdev.co.uk/staff.php$all ||lists.infradead.org/pipermail/ath10k/attachments/20200120/96688204/attachment.doc$all ||littleindiadirectory.com/l/toyut/$all +||livedemo00.template-help.com/28736_site/hoeflertext.font.com$all ||liveglamsupport.zendesk.com/attachments/token/5hi6ffymckoobokwxs0oslb96/?name=389238856784.zip$all ||liveglamsupport.zendesk.com/attachments/token/5hi6ffymckoobokwxs0oslb96?name=389238856784.zip$all +||liveswinburneeduau-my.sharepoint.com/:u:/g/personal/101937439_student_swin_edu_au/eqsmp3lwkfzfr0zegn-tkiqb6agjne8t4rqyjhktmzur6w?e=zl6yl7&download=1$all ||liwatertech.com.pl/wideness.php$all ||lm-shop.fr/robe.php$all ||lmnvdsas1dsfsdgsd0rebvsds5.s3.amazonaws.com/facturajaneiro-752698-2019-10_5.zip$all @@ -563563,6 +563769,8 @@ zzznan.com ||luoyb.com/wp-includes/ruhbvqxwav/$all ||lusterconsultancy.com/unexterminated/lkwebnuq4kvxze/$all ||luxelistreviews.com/wp-includes/ayr/$all +||luzy.vn/wp-admin/protected-box/5n0ddpmuc-eqlu1o1befow-wzj8lfwj-9ega3umab/795789-ppeclz1q1bf/christmas_card/$all +||luzy.vn/wp-content/etrac/p7d8lzxe7p/r8d492343724021xd3b2760u727yqdsbnpw5r/$all ||lvecarehomes.com/vvzjddpdllk/751057/employmentverification_751057_05062020.zip$all ||lvnskin.com/h/ib/$all ||macexpertguide.com/wp-content/uploads/h5235/$all @@ -563682,6 +563890,7 @@ zzznan.com ||me.swop.cloud/cornice/payment/$all ||meaproductions.com/content/yiitzvtvm8hsawjzbgo2onjvjrtee10/$all ||measuresquare.com/sitepage/scan/8rfacidzvj5yu/$all +||mecharnise.ir/ca3/fre.php$all ||medgen.pl/templates/medgen/html/com_content/article/messg.jpg$all ||medgen.pl/templates/medgen/less/messg.jpg$all ||media.dropdo.com.s3.amazonaws.com/6sy/dota%20hotkeys.exe$all @@ -563824,13 +564033,11 @@ zzznan.com ||megawrzuta.pl/files/5b5074af4cf8eebd1f82477fd7aec819.dotm$all ||melekbaskaya.com/wp-content/qy5cyszqlzf7pn8nx4jsvmbeji7odk6/$all ||menol.eu/wp/mt/$all +||meohaybotui.com/qitjgi/$all ||merky.de/fdjl8k$all ||messenger.avmaroc.com/update/install-avm.exe$all ||meubucjetd02111.s3.ca-central-1.amazonaws.com/0002211144555787555111.zip$all ||meuvivo-digital-fatura.s3.eu-west-2.amazonaws.com/digital.html$all -||mfpc.org.my//wp-content/plugins/formcraft3/stub2_encrypted_ba9409f.bin$all -||mfpc.org.my/wp-admin/images/stb_encrypted_5b6e930.bin$all -||mfpc.org.my/wp-admin/meta/stb_encrypted_a322e7f.bin$all ||miamicondoinvestments.com/wp-admin/sec.myaccount.docs.com/$all ||mibaston.com/wp-content/tdez5kkkbuqpmxkz3egslcsadwzvxr0vsdfilep2b5ahodxqtcdwg0uq83dacr/$all ||michaelkors-outletonline.co.uk/cgi-bin/sendincverif/support/ios/en/201903/$all @@ -564019,6 +564226,7 @@ zzznan.com ||ngoctugroup.com/wp-admin/y3zqqdx9fayb4xx/$all ||ngoctugroup.com/wp-content/rkibwmikhanfvqrthvijybcqsepi6zvgwq7ubjkpjeinbqyyt3mlhkenhhtsqp6/$all ||nhabeland.vn/sercurirys/rbvpk/$all +||nhadepkientruc.net/wp-content/ogi3nl90/$all ||nhipcauytevietnhat.com/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/$all ||nicetelecom.us/vsr/81cqdfelyiudyh4cxnwzgpbnwfehi3yxpjkgdgjhmzzv6idk8isnym/$all ||nichimanabi.com/wp-content/en-us/$all @@ -564030,6 +564238,8 @@ zzznan.com ||nightlifemumbai.club/x/0wbd3/$all ||niislelaudit.mn/j/hcziobohjbs4ftdle8w6t8o3ioqups1s/$all ||niislelaudit.mn/j/nvk1bub/$all +||nikayu.com/mpvjl0awc9zkv$all +||nikayu.com/mpvjl0awc9zkv/$all ||nimbledesign.miami/wp-admin/c/$all ||nltu.edu.ua/fakturierung/rechnung-0269807/$all ||nmsdevelopers.com/cgi-bin/isir0cvzfzzk3zjymvnmjykw/$all @@ -566776,6 +566986,7 @@ zzznan.com ||oodda.com/ticket/personal-ikczwwhbd-xig0jbsfrlq185/docs/bx63x9cpdgdk/$all ||oodda.com/wp-admin/de4p2ec3-wj4mghjou-15889/$all ||oodfloristry.com/srz47e2/8d3f5eff51058cf7494775bf4366ff09.zip$all +||optionscity.com/wp-content/wptouch-data/debug/safebrowsing.exe$all ||oracledispatch.com/pijxju/44265.9599178241.dat$all ||oracledispatch.com/pijxju/44265.9613831019.dat$all ||oracledispatch.com/pijxju/44265.9623305556.dat$all @@ -566792,6 +567003,7 @@ zzznan.com ||osheoufhusheoghuesd.ru/m.exe$all ||osheoufhusheoghuesd.ru/o.exe$all ||osheoufhusheoghuesd.ru/t.exe$all +||oshi.at/qbpahk/$all ||oshiscafe.com/wp-admin/5dm/$all ||osliving.com/vyop-n8taxexfiqihcz_tqpsraxby-hk$all ||osliving.com/vyop-n8taxexfiqihcz_tqpsraxby-hk/$all @@ -572944,6 +573156,68 @@ zzznan.com ||polyproductions.com.au/in-what-jgcak/c5njrzmm4sqrvaes3grdnn2ccj7nzt/$all ||porlacalledelmedio.com/device-unlock-xlzl9/uqaqjbsmpt2loeq5sj45vwski7aguudkiasnuu09gwg8jyhmx3alyemphhpm/$all ||pornhub.com/x/xff.exe$all +||posqit.net/0/56021017.exe$all +||posqit.net/0/5911097.exe$all +||posqit.net/0/6013277.exe$all +||posqit.net/0/6502301.exe$all +||posqit.net/0/80177.exe$all +||posqit.net/00/6508908.exe$all +||posqit.net/8t/4460139.exe$all +||posqit.net/8t/50173309.exe$all +||posqit.net/b/5003037.exe$all +||posqit.net/b/9051077.jpg$all +||posqit.net/ctw/1011.hta$all +||posqit.net/ctw/2055970$all +||posqit.net/ctw/96053407$all +||posqit.net/ctw/96053407.hta$all +||posqit.net/ctw/9908793$all +||posqit.net/ctw/scan091019$all +||posqit.net/f1/scan-document-shipment-info$all +||posqit.net/f1/scan-document-shipment-info.hta$all +||posqit.net/ge/20610444.jpg$all +||posqit.net/ge/206440.exe$all +||posqit.net/ge/4509700.exe$all +||posqit.net/ge/50010378.jpg$all +||posqit.net/ge/5013447.exe$all +||posqit.net/iy/5607087.exe$all +||posqit.net/pe/0362035.exe$all +||posqit.net/pe/0578102.exe$all +||posqit.net/pe/08437.exe$all +||posqit.net/pe/0955576.exe$all +||posqit.net/pe/1050700.exe$all +||posqit.net/pe/1101708.exe$all +||posqit.net/pe/11045830.exe$all +||posqit.net/pe/1106778.exe$all +||posqit.net/pe/2117636.exe$all +||posqit.net/pe/60380.exe$all +||posqit.net/pe/60589.exe$all +||posqit.net/pe/myfile5.exe$all +||posqit.net/pe/scan-05458.exe$all +||posqit.net/qq/05700301.exe$all +||posqit.net/qq/0621777.exe$all +||posqit.net/qq/0629107.exe$all +||posqit.net/qq/1035661.exe$all +||posqit.net/qq/7800132.exe$all +||posqit.net/qq/78045109.exe$all +||posqit.net/tt/440789.exe$all +||posqit.net/tt/741003.exe$all +||posqit.net/tt/850135.exe$all +||posqit.net/tt/89051102.exe$all +||posqit.net/tt/90461777.exe$all +||posqit.net/ty/20601907.jpg$all +||posqit.net/vcv/120131078.exe$all +||posqit.net/vcv/2031078.exe$all +||posqit.net/vcv/306517.exe$all +||posqit.net/w/03305177$all +||posqit.net/w/6006077.exe$all +||posqit.net/w/9078950$all +||posqit.net/w/9078950.hta$all +||posqit.net/xl/08971130$all +||posqit.net/xl/2013544$all +||posqit.net/xl/50333087$all +||posqit.net/xl/6090970$all +||posqit.net/xl/6090970.hta$all +||posqit.net/xl/new%20order.exe$all ||poweringcommunities.org/tr/huz/$all ||powerup.rent/wp-admin/ygkeon22z3okdroeayj6n4mzfd0zervw4gzg6i4kzwksdnpab/$all ||pratham.org/wp-admin/s1/$all @@ -572959,6 +573233,14 @@ zzznan.com ||preserved-diesels.co.uk/wp-content/verif.accounts.resourses.biz/$all ||presteiatencaonovoera.s3-sa-east-1.amazonaws.com/meuvemelho32.zip$all ||prevelo.com/seoredirect/ago/$all +||prisma.fp.ub.ac.id/wp-content/amazon/en/information/012019/$all +||prisma.fp.ub.ac.id/wp-content/orders_details/012019/$all +||prisma.fp.ub.ac.id/wp-content/plugins/hpcrs-sdpvl_nr-tk/inv/70971forpo/264773867145/us_us/open-past-due-orders/$all +||prisma.fp.ub.ac.id/wp-content/us_us/info/copy_invoice/wzddw-n2xu_ngxm-z41/$all +||prisma.fp.ub.ac.id/wp-content/us_us/xerox/invoice_number/fhbq-zwqr_um-fg/$all +||prisma.fp.ub.ac.id/wp-content/xerox/midy-2g_ftbtdf-2yo/$all +||prisma.fp.ub.ac.id/wp-content/xldld_li-wbbm/xt/attachments/02_19$all +||prisma.fp.ub.ac.id/wp-content/xldld_li-wbbm/xt/attachments/02_19/$all ||pritiquita.s3-eu-west-1.amazonaws.com/image2.png$all ||private9385.s3.ca-central-1.amazonaws.com/bia.exe$all ||priyabeatus.com/iltfjz/lbrkydp3ef3ghzjostty1gzu7kmvhzixpmv/$all @@ -572982,15 +573264,11 @@ zzznan.com ||protect-us.mimecast.com/s/7ihcc82oqycqx96qh15qw5$all ||protect-us.mimecast.com/s/c27ac0rx9ru80p3fw0bgj$all ||protect-us.mimecast.com/s/qki9c73wxjupxq5ps8qcm_$all -||protect.mimecast-offshore.com/s/ip17cn9blzfnq4n4h4tudd?domain=meraqsa.com/$all -||protect.mimecast-offshore.com/s/loqwcg5rvpcjndxqc76apn?domain=ronakfence.ir/$all -||protect.mimecast-offshore.com/s/rd0zcjqxyvf8w6o3igppxq?domain=ronakfence.ir/$all ||protect2.fireeye.com/v1/url?k=59eacb3c-0560e9d5-59ed97de-0cc47ad93e2e-0f5e34e79adab692&q=1&e=e7991bbc-cc93-4814-a8f2-fd6d6950b0d5&u=https%3a%2f%2fwww.mediafire.com%2ffile%2fs2uyxs8t8kbuyye%2fdocumentos_de_env%25cdo.7z%2ffile$all ||protect2.fireeye.com/v1/url?k=6d0c09d2-33bdd2b2-6d0f7943-86e2237f51fb-ab55eb53c2dfee1f&q=1&e=358c9b57-d351-4b0f-80cf-d0755ec21127&u=https://pottershousedurban.co.za/cgi-bin/file/xzbx0cb5wywuw5/179vj6b9dpsp7advozp/$all ||prowestappraisal.com/ms-t/xqgkotgvdwhezypdfhwvwrjfe/$all ||prowestappraisal.com/rj0fupo/file/fxwrxafanjgpjlnjuwyfzp/$all ||proxindo.id/wp-admin/file/vgsupeyhnlc8ka4tbdu72wde7khpa_1ganzrzry-05828045/$all -||proxy.qualtrics.com/proxy/?url=https%3a%2f%2fuark.qualtrics.com%2fcp%2ffile.php%3ff%3df_0imyt11iuwaovez&token=vazkfd%2bfsrcuyx5fyunax24zxgk5dxrgqszm%2bpoz8fw%3d$all ||prozipper.s3.eu-central-1.amazonaws.com/prozipperred.exe$all ||psicopedagogia.com/glosario/inc/ggz5atnnx/$all ||psicopedagogia.com/glosario/inc/mjj6pq3vfq/$all @@ -573031,7 +573309,6 @@ zzznan.com ||quen.s3.us-east-2.amazonaws.com/purchasing+ordersigned+contractinv-30067121.ace$all ||quuik.com/rwc/jr42/$all ||quuik.com/wp-keys.php$all -||r20.rs6.net/tn.jsp?f=001jyht2t3omeetiei35oqstjgs_9nzk9sjylnhtbb0ao4bhans77uolbdrrwaaelcy_xfpwz_v9kt7buybu0v7bxkhuwlnsftzi2_8ddimoio4s1lnjpwd3da7cbyogtmhkf5obn3ysllinftl_gcxaufwxn0bz8fxjf4yvhjb-3gtb-da07vpp0qazekjwo7a9udmhkol3peul1z7wczztkps5tadshty&c=sda7vzhezlmymcpvzhysvdoo2nf8acki9xwyb_wfzgl7nntihduz-a==&ch=hl2va1psqpoi_ueanwygza8msuiyrkcqkgylcfuiihszmkx0z2mngg==$all ||rabiei.fun/eidl-reconsideration-bs3lu/feooiao/$all ||racisa.s3.us-east-2.amazonaws.com/zenar.exe$all ||radioiluminacion.djsrecord.com/pm3ibp8on.rar$all @@ -573257,6 +573534,7 @@ zzznan.com ||rugab.se/c/6033102/buy-sell_agreement_6033102_04272020.zip$all ||rugab.se/c/68691/buy-sell_agreement_68691_04272020.zip$all ||rugab.se/c/81176/buy-sell_agreement_81176_04272020.zip$all +||runnerbd.com/newsletter/en/new-order-upcoming/hri-monthly-invoice/$all ||s01.solidfilesusercontent.com/mtywztlhm2u5othkyzdjzdrmmtyxmzq1ogewzji3otfmmtu3ndjjodoxaxjzdge6dkdwuvbhudzhnmhvyurqaenfbfo0ahrwtjew/gwvplg4drpqgb/263.exe$all ||s01.solidfilesusercontent.com/ogeyndy1mjlizdg0ztdhogizowiynwmwzda5nwu3ntvkyzlmzde4odoxaw80cuw6y1v5ywpid2p4nhmtx0ltngzbtjrqoxn4qmlb/gwvplg4drpqgb/263.exe$all ||s01.solidfilesusercontent.com/ogvkyza4zgqwnji3otu3mte4mteym2y2zdfjmwmzntnhyjzjymfhzdoxatzknve6sjnfvvk1sllvm1rhnklubdh4lwnqawprn3zn/gwvplg4drpqgb/263.exe$all @@ -573498,7 +573776,6 @@ zzznan.com ||satyagroup.co/fmnk80rob.tar$all ||satysservs.com/setup6-156.exe$all ||satysservs.com/setup6-158.exe$all -||saveserpnow.com/install6.exe$all ||savwinch.com.au/wp-content/themes/theretailer/languages/1c.jpg$all ||savwinch.com.au/wp-content/themes/theretailer/languages/2c.jpg$all ||sbninspections.com/wp-content/y71zq/$all @@ -573596,6 +573873,7 @@ zzznan.com ||seodukich.com/wp-includes/7w0n9vpc034tginpozfsmo1dlabvc7avmtjl8uux9z7z0t5zrrtfaklid/$all ||seoweblog.net/earth-sub-bykpd/jera2eufqq6awccm2kne4puwdyjir0ebmin0n4izmvo2upcmipfkyyhddt/$all ||serenetax.com/client/uu0h/ngka7dpdysu4evqj0bzxden9dirzn06avcbdgahx0c/$all +||service.ezsoftwareupdater.com/updates/2/whsetup.exe$all ||setembroamarelo.org.br/99939gxnyvtw/biz/smallbusiness$all ||setembroamarelo.org.br/99939gxnyvtw/biz/smallbusiness/$all ||setembroamarelo.org.br/bbjcfeeos$all @@ -573607,13 +573885,6 @@ zzznan.com ||sgiff.com/css/ixuc3k-wus7v022j-4995897081/$all ||sgiff.com/css/xrn487/$all ||sgiff.com/filmacademy.sgiff.com/bub12531/$all -||shared.outlook.inky.com/link?domain=laminingraphics.co.za/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdkf9pwjauxb9ln5hjbon4qkunbsodf5yts8jdeqgdvr1pn8aav7vfxbdfzz3n3f_of2srsak2zntlwfty7ihqqgpyjyntojwg2xgp2mgpyfajzddjcwgjbak6tqgmvbpdv2oohekx6btusc6gijnte3tjiioihr4zzq4wjljvv3vfqxgdjzcgwqwicg2hkqlqsdz8lbtsirq7jscmbypadgxnsxdzoqrznkesheikdj2tei1o6zaddmw67fk35d7bpbgki1ks12wcy6b_qsrlnpipxcwku3a7nl4m-hp2xtshey9fkfpvmqdzzh3q_gbip4dh_vxw4eupo-4f48u08_n6cqmynuo7qwkldycerecc25x00_qjjwg8tp7p-rvs9w8veomv.meucihnyythleerey63ykklm6wi3yajo85mjvegtysle7fhbaieanqqjbjnskm2wmbtocdroz8yldff_ab3ipunej1yo3qo/$all -||shared.outlook.inky.com/link?domain=laminingraphics.co.za/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxtue1rwkaq_s97tgyvdwykwkykxvwkqwlcqkab0wzc2ytdjdau_veupzaehuhn-5j3xrwcyzkf7cg1aihneqinfmagtgqhroni4rguxqfdf0dgzuikps1banhya2nuezuldkvdnntx-h_pjfdilxotdyugcjr31l7iqftjyf3vsiciulypuhqkcdaxiirau7dvlnsdugpmkopgdgov6nvgputdmcfvzem0ztmzzelicvj19jrrin2ynvwxfljxu1xefldczep9jafy5e8vbtao_d5z635t8wqx5x1048vfelvkpvkqjp48eafdhfms85sptslervvitzhhy-zg6-eo16fh-3cwzqejpdpawrq01ufsupyhvxpqcp63399svn8akcagug.meucie6d9mxuzck5v8rhoqlm3oksbgukynxeilyxhhowpoq2aieagl_05exfu06imv0cnpgztc9get1eg-yy5b42-7fmdhm//$all -||shared.outlook.inky.com/link?domain=www.toziba.ir&t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdkn1ugkauhn9lry0ekk31svpn2wherrfcqg6wyq67omsiqtn373lvpjdfmmdmznwjiygtas3qgvrq5bg-amec5iamifqsiwoymh2anxicsnjjkd1ukpap93mohgmivdlr4y9aow5qkew5msv6onddp8l6iblorcg830hbszxowukuwx7hircdvex4iw2v-9xdf2xpnxzemw-71orev5b-fs2qlrejkqxaifogr1ilgkrmgb5z1kahtepwiuehwxloalr5ustmro3ng8tpzxxcu8y4xzizlrnw10poluvuxbpn1hldlr0nuehsdxjtx4wvu8npimwvgr--ws51b17aqp8yvxnugfza6b1gzszpyh4_brbi8bhackuhcnootvsiqypdyv5_wy2vofr5bwmpgle.meuciqdwg66mmqf8atpdht-lpyuss3dbd_soh1bljxzzbxwc1aigv1wkcnavv4nw3os570ta3z-muscagqqnti3dgc9p6js/$all -||shared.outlook.inky.com/link?domain=www.toziba.ir&t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxduf1vgjau_s99dqa4t-mtbcbortbrpqqhireoqmmllilisv--8rrkj-fm3pp1jrqbxuzogu6lajgr-gscydidneklueqkyghxataqeskap0d1icdpx5-xhepmyfztb4u_1er9gwqlls0inmoz6zpd1y8ybaougl6eioelie1pd1fvuhzk2mfxau_wb173mbp_9kvnloytl6c1ida15m5hc9eynkkqkaruwsinajexjjmyy87akjxrhm55fe5yxhmndvmrtoiww3ewve8cwlmrcpelfi7smoghdistd2_pyu4jwk0iz-ncvdrjbzn2vt13vv4de76-4cqhacp8i-kpt7tl7cfos3vxc_otje5d44bihawljjdnkjsnzktprjwzkcv_2xpzzdhpl9e5g6k.meucigd6xwariut2lkiettiajcosxyluv7ub6nhbepewswmwaiea4mzpunjaca7lslweyqnda4gpvqjwhufuenzur1jmp64/$all -||shared.outlook.inky.com/link?domain=www.toziba.ir&t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdunfugkaq_jd7tqby28qtte2siucq4akhiquccnh36heusom_93hq0odndjazm7p7jrqbtgtkoxmvihjsn4atsxnae0sfiliaq_yjwemmigieajwaghr4flxxomyqraaocn-olxohlupdgzsxe7prokpvd5qbqawg1wcoobwjkz3ufhzxrsqdhoeov97zesjd3ud42czjzno6tbykppb0q2sllrejuqukofjgvoh2meqyo3nmwrvhrrxjjy_wjowcvdf-eyutqxtbpcsvrxzwosy4xzirljn8gab75zz7x9l-wuzbwemg7on1all8m9bux-5uz2yu_7siifpeuvfexnqvcu5-4aze-6xfvs5svlghmixjb1iockmarmeqzkscgzgr_7818pqjn19jvyhz.meyciqdjb9hlkixl4sz_rt8-tj8v7t6tzcbxfjgcuyhbc8ixuwihapwstswmgpu_k43h-va03ffjltif7n-k3qrucylug8il/$all -||shared.outlook.inky.com/link?domain=www.toziba.ir/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxduf1vgjau_s99dqa4t-mtbcbortbrpqqhireoqmmllilisv--8rrkj-fm3pp1jrqbxuzogu6lajgr-gscydidneklueqkyghxataqeskap0d1icdpx5-xhepmyfztb4u_1er9gwqlls0inmoz6zpd1y8ybaougl6eioelie1pd1fvuhzk2mfxau_wb173mbp_9kvnloytl6c1ida15m5hc9eynkkqkaruwsinajexjjmyy87akjxrhm55fe5yxhmndvmrtoiww3ewve8cwlmrcpelfi7smoghdistd2_pyu4jwk0iz-ncvdrjbzn2vt13vv4de76-4cqhacp8i-kpt7tl7cfos3vxc_otje5d44bihawljjdnkjsnzktprjwzkcv_2xpzzdhpl9e5g6k.meucigd6xwariut2lkiettiajcosxyluv7ub6nhbepewswmwaiea4mzpunjaca7lslweyqnda4gpvqjwhufuenzur1jmp64//$all -||shared.outlook.inky.com/link?domain=www.toziba.ir/u0026amp;t=eyj0exaioijkv1qilcjhbgcioijfuzi1nij9.ejxdunfugkaq_jd7tqby28qtte2siucq4akhiquccnh36heusom_93hq0odndjazm7p7jrqbtgtkoxmvihjsn4atsxnae0sfiliaq_yjwemmigieajwaghr4flxxomyqraaocn-olxohlupdgzsxe7prokpvd5qbqawg1wcoobwjkz3ufhzxrsqdhoeov97zesjd3ud42czjzno6tbykppb0q2sllrejuqukofjgvoh2meqyo3nmwrvhrrxjjy_wjowcvdf-eyutqxtbpcsvrxzwosy4xzirljn8gab75zz7x9l-wuzbwemg7on1all8m9bux-5uz2yu_7siifpeuvfexnqvcu5-4aze-6xfvs5svlghmixjb1iockmarmeqzkscgzgr_7818pqjn19jvyhz.meyciqdjb9hlkixl4sz_rt8-tj8v7t6tzcbxfjgcuyhbc8ixuwihapwstswmgpu_k43h-va03ffjltif7n-k3qrucylug8il//$all ||shared.pdffiller.com/1395f7beaf30f1943ac9e1b9800a8fbf/8c7dd922ad47494fc02c388e12c00eac/cdecfead5bd78cb1c29f931bc49ad2db.exe?t=1549302986$all ||shatki.info/templates/ld_benew/images/blue/messg.jpg$all ||shellter-static.s3.amazonaws.com/media/files/5adbc741-fe58-4372-ad03-f27df73dbf1c.exe$all @@ -575408,7 +575679,6 @@ zzznan.com ||store.chonmua.com/wp-content/crbxdfv/$all ||store.chonmua.com/wp-content/xfdvdqie/$all ||stormhansen.com/2556460492/if/$all -||stressing.pw/spike/svchost.exe$all ||studyinassam.com/correcciones/$all ||studyinassam.com/jul2018/en_en/payment-and-address/19484/$all ||studyinassam.com/jul2018/rech/hilfestellung/rechnung-yj-89-92841/$all @@ -575427,13 +575697,14 @@ zzznan.com ||sungardspo.com/6lhjgfdghj.exe$all ||super-registry.s3.eu-central-1.amazonaws.com/installc_sh_directly.exe$all ||superbeaute.ca/wp-content/nachrichten/nachprufung/de_de/04-2019/$all -||superdomain1709.info/c4fxp3oiuoyf.67w$all -||superdomain1709.info/kuycdsjte.jdz$all ||superiorsurfacings.com/pc-not-qgtje/j8t3s/$all ||superlite.com.vn/wp-content/available-hsu0-mnfs/special-warehouse/grx4lzmafww-3ej6ap67ihb2/$all ||superlite.com.vn/wp-content/oct/iesp7ft16sl/$all ||superlite.com.vn/wp-content/overview/jspozvcolfa/$all ||support.indeed.com/attachments/token/rvdxkcofcmeb1pdt1wrikfmxn/$all +||support.pubg.com/attachments/token/t6cno6ywz3wf4svnnwt5weowd/$all +||support.pubg.com/attachments/token/t6cno6ywz3wf4svnnwt5weowd/?name=hsjloader.exe$all +||support.pubg.com/attachments/token/t6cno6ywz3wf4svnnwt5weowd?name=hsjloader.exe$all ||support.zendesk.com/attachments/token/tw5zut6d9vybjph5w71eyzhms/?name=dat+3099+698948277.doc/$all ||surcanal.es/calendar/idi1/$all ||surcanal.es/calendar/oct/$all @@ -575450,6 +575721,7 @@ zzznan.com ||swallowcliff.co.za/e/c5q/.../$all ||swallowcliff.co.za/e/fjytd1xxmp5x0vtgqz66lebyf9ixuqluiw9koix/$all ||swejan.com/wp-content/uploads/inc/fhdzcjpigqu0pt/$all +||swift-cloud.com/storage/doc/statement.doc$all ||swop.cloud/wp-snapshots/7472583792815/8aesu6/t7cotowf42aha7jgfyv04s/$all ||sylvaclouds.eu/20th/document003.exe$all ||sylvaclouds.eu/20th/fabuary-specification-04.exe$all @@ -575528,6 +575800,11 @@ zzznan.com ||talentvalue.com/wp-admin/deoum/$all ||talkischeap.co.za/4-pin-iscru/t7k/$all ||tanvinhdn.com/rumus-jitu-kancq/ccsfilzrtnnxgjm7trsufbq3pr1mcowwjmsz6hnjcaxrpazhkiknu/$all +||target-support.online/exe/softsetting.exe$all +||target-support.online/old/upload/ddd5.exe$all +||target-support.online/old/upload/emter.exe$all +||target-support.online/old/upload/socks.exe$all +||target-support.online/old/upload/test32.exe$all ||taruhanolahraga.com/rqh62hciad1ymgshhmhc$all ||tasnimproperty.co.id/ennvsy.txt$all ||tasteoff.com/q/opdqetybikbrueuyommaober/$all @@ -575562,6 +575839,9 @@ zzznan.com ||terplandia.com/publish_f2/j57dvgxq5b3kbj6ckaxszg/$all ||test.nltu.edu.ua/media/editors/codemirror/mode/gfm/images/aeacf200364da7f5413b6d0c5d656655.zip$all ||textileanalytics.pk/theme-assets/llc/5hhpa7xze182zgtv/$all +||thaddeusarmstrong.com/wp-content/txxwd-me7gh-slgzwqla/$all +||thaddeusarmstrong.com/wp-content/txxwd-me7gh-slgzwqla//$all +||thaddeusarmstrong.com/wp-content/wrx/$all ||thaithienson.net/wp-admin/ekszxo/$all ||thaus.top/wat.exe$all ||the-boathouse.com.au/wp-content/plugins/twcdkiy/back/stub_mpldp25.bin$all @@ -575640,6 +575920,17 @@ zzznan.com ||tinyurl.com/ybyymhnd$all ||tinyurl.com/ydaoeqoy$all ||tipsmainjudipoker.com/wp-includes/ube61/$all +||tldrbox.top/1.exe$all +||tldrbox.top/11.exe$all +||tldrbox.top/2$all +||tldrbox.top/2.exe$all +||tldrbox.top/3$all +||tldrbox.top/32.exe$all +||tldrbox.top/4$all +||tldrbox.top/5$all +||tldrbox.top/6$all +||tldrbox.top/64.exe$all +||tldrbox.top/v$all ||tlsac.pe/wp-touch.php$all ||tnkhanh.info/wp-admin/az0fysfnexo1qfw9si6bvfxs/$all ||tocchientv.com/cgi-bin/gegesa/$all @@ -575721,7 +576012,6 @@ zzznan.com ||ts-prod-assets.tripleseat.com.s3.amazonaws.com/assets/009/485/756/thevillagepub.doc?1545218354$all ||ts-prod-assets.tripleseat.com.s3.amazonaws.com/assets/009/486/201/thevillagepub.doc?1545223316$all ||ts-prod-assets.tripleseat.com.s3.amazonaws.com/assets/010/943/655/inv11533395908.doc?1553863076/$all -||tsapparel.com.my/fd66e6.php$all ||tsg339.com/invoice/$all ||tsrv4.ws/23.exe$all ||tsuburaya-prod.co.jp/wp-content/plugins/wp-ogp/sa.exe$all @@ -575731,7 +576021,6 @@ zzznan.com ||tuerkiyemspor.de/d/2hwekzifbsep6/$all ||tuhoctiengtrung.vn/efiva/bv8-k1f-111875/$all ||tunik.my/wp-admin/balance/u0eco1t53899r/hd81e0hv70qjozexal/$all -||tuoitrethainguyen.vn/moah-ky0x_u-t9/invoice/en_en/new-order/$all ||turbinadordemidias.com.br/wp-content/tzb3f68et95zngff1cm7ev_7b14q45-05068827162/$all ||turbineseuperfil.online/sitetarget/7g/$all ||turbineseuperfil.online/sitetarget/file/8yopx3ztjsbuwlpvwcog/$all @@ -576399,6 +576688,9 @@ zzznan.com ||unikaryapools.com/wp/speech/$all ||unikaryapools.com/wp/ysfirq1/$all ||unitedmdy.com/content/ackr/$all +||unlimitedimportandexport.com/wp-content/plugins/all-in-one-wp-migration/lib/bread.exe$all +||unlimitedimportandexport.com/wp-content/plugins/all-in-one-wp-migration/lib/cvxjr.exe$all +||unlimitedimportandexport.com/wp-content/plugins/all-in-one-wp-migration/lib/jkzse.exe$all ||unsignedonly.com/factures-29-mai/$all ||unsignedonly.com/ups-invoices-docs-062k/02/$all ||unsignedonly.com/ups.com/webtracking/hc-11303672500/$all @@ -576463,7 +576755,6 @@ zzznan.com ||url.emailprotection.link/?bgmvicpuho15c9_q9hiofgnmkaco0q_lujjcaeowkfik_hdtt1uqmbkpovhxykckgjoqoytv_u0g2umkhd4mbi9ms8vo3vliq2clouuaa6no2a7ij5ljfsouoeememvmi/$all ||url.emailprotection.link/?bizyxbw1fdagsfcc1n6ep1awpdx9dr0brnjjqwgyaofpw98limviipvrszjnzzluclpeqqdywfxwnwudvwrljcufuhl2_nha0bs8wz9jmbahcciikbseljewayzbe_cnd/$all ||url.sg/rwtho$all -||url2.mailanyone.net/v1/?m=1hibcm-0003zv-63&i=57e1b682&c=sb1blj46bk32u6f729r5t_slvkx-heewxh20_zdn9-3ktcc0-kn35fykilpydgeyvrbwqwb5h__fk383wtdakqftjlelxz06jbaglri5jmujnydjkasqxwdtg2hn-_be1dzrnthvvhigyhm_tvbew342habp8dtit9jjlieuc2x-ipgdgipe7y_c9jhe69532gmnxozb5wifjfbstzicagmtpg6yxmreaf0sq2dgo-ksy54hetfhn6gwm4kiw2vvcqx17a9bm6ykn8bwpwdjwg/$all ||urldefense.com/v3/__http:/download.tikishop.top/temp/oct/zxpz9h87ye/__;!!fbndfrmfwymjic8!esuixa6kh9x3c2evnf06q3vphe7ce6thjgjxuygtgkahdoypzovx_isni9xonn9idgfjjqtcun8$/$all ||urldefense.com/v3/__https://www.geoffoliver.org/simple-blog.off/vendor/payment/9yiv2xys/__;!!okyw9je!2zzbjlkqkjmstcwtza6cy_dauiy-njmys3cs6uteawgyow8yhyesg5jhjtttdwaxadrnh5k$/$all ||urldefense.com/v3/__https:/www.geoffoliver.org/simple-blog.off/vendor/payment/9yiv2xys/__;!!okyw9je!2zzbjlkqkjmstcwtza6cy_dauiy-njmys3cs6uteawgyow8yhyesg5jhjtttdwaxadrnh5k$/$all @@ -576503,6 +576794,32 @@ zzznan.com ||ussbd.net/wp-admin/scan/xlhuy5brujs4c4sbq/$all ||utenti.info/1.exe$all ||utenti.live/1.exe$all +||uujian.cn/browser/apk/100-2.9.apk$all +||uujian.cn/browser/apk/101-2.9.1.apk$all +||uujian.cn/browser/apk/102-2.9.2.apk$all +||uujian.cn/browser/apk/103-2.9.3.apk$all +||uujian.cn/browser/apk/104-2.9.4.apk$all +||uujian.cn/browser/apk/105-2.9.5.apk$all +||uujian.cn/browser/apk/106-2.9.6.apk$all +||uujian.cn/browser/apk/107-2.9.7.apk$all +||uujian.cn/browser/apk/108-2.9.8.apk$all +||uujian.cn/browser/apk/88-2.7.apk$all +||uujian.cn/browser/apk/89-2.7.1.apk$all +||uujian.cn/browser/apk/90-2.7.2.apk$all +||uujian.cn/browser/apk/91-2.7.3.apk$all +||uujian.cn/browser/apk/92-2.7.4.apk$all +||uujian.cn/browser/apk/93-2.7.5.apk$all +||uujian.cn/browser/apk/94-2.8.apk$all +||uujian.cn/browser/apk/95-2.8.1.apk$all +||uujian.cn/browser/apk/96-2.8.2.apk$all +||uujian.cn/browser/apk/97-2.8.3.apk$all +||uujian.cn/browser/apk/98-2.8.4.apk$all +||uujian.cn/browser/apk/99-2.8.5.apk$all +||uujian.cn/browser/apk/beta.apk$all +||uujian.cn/browser/apk/browser-l.apk$all +||uujian.cn/browser/apk/browser.apk$all +||uujian.cn/browser/apk/m3u8loader.apk$all +||uujian.cn/browser/apk/test.apk$all ||uzkon.com.tr/wp-admin/zzbi71rw0idiacknh4ul059zb8kterjhvfilc1ecvn8/$all ||vaidapt.s3.amazonaws.com/0.zip$all ||valquathailand.com/300rzdxjpah/wire/personal$all @@ -576557,6 +576874,7 @@ zzznan.com ||void.cat/e6d36d4c83b4de23c012b9351f019b8b4b30b020$all ||void.cat/ed7e7fc7d14048bf1cf40565068f487e71169a84$all ||void.cat/fa8ca69f8798d76fd2d9e16c0b0bcf049a9a67e2$all +||vokasi.ub.ac.id/wuk/kuqyslbgavnwlmcuk0qalhxifzp4mgze8anlcewu1pa8fw4lfex0y/$all ||vongu.store/send_newsletter/oi2fmlyjenkrurthxjzw29lxjo6pfbyefqc33nwsgbc05fpcrbybcweoo/$all ||voxechoeffects.weebly.com/uploads/4/2/4/2/42424725/vox_echo_effect..exe$all ||vrau-x.s3.us-east-2.amazonaws.com/0.zip$all @@ -576569,6 +576887,9 @@ zzznan.com ||wallstreetreporter.com/wp-content/plugins/most-popular-posts/1$all ||wallstreetreporter.com/wp-content/plugins/most-popular-posts/2$all ||wallstreetreporter.com/wp-content/plugins/most-popular-posts/3$all +||wasimjee.com/wp-content/themes/host/languages/kia.zip$all +||wasimjee.com/wp-content/themes/host/languages/msg.jpg$all +||wasimjee.com/wp-content/themes/host/ordomain/msg.jpg$all ||watchesprime.com/mohsen/216873730/msqd7lu45/aytzf26989128361969947837wiqexzw/$all ||watchesprime.com/mohsen/ic042-0iin-66982/$all ||watchesprime.com/mohsen/personal_section/individual_area/2416843_pzxoewvbxi8lcpr/$all @@ -576634,6 +576955,8 @@ zzznan.com ||wiratech-europe.com/wp-includes/pages/7635/b9dc-0071/$all ||wiwa-lokal.de/sample-xyz-xlqol/jnwjbgbbcrgiabgfajca7vjdv/$all ||wmi.4i7i.com/11.exe$all +||wodfitapparel.fr/wp-content/themes/cleayn/6o00s4g8/$all +||wodfitapparel.fr/wp-content/themes/fagri/oknuyqlfr/$all ||wordsbyme.hu/ifeanyi/me.exe$all ||workatone.com/fedex/$all ||workex.jobs/blog/718017006/in70g-00089/$all @@ -576723,13 +577046,14 @@ zzznan.com ||yougile.com/user-data/3b4be708-0db9-4c34-b270-4082a3908053/report-review26-10.exe$all ||youmanduo.com/wp-content/1j8nz7/$all ||youthref.org/content/cninqkopm0/$all -||yp.hnggzyjy.cn/common/yz.vbs$all -||ypddf.org/en/nr/$all ||yq001.com/admin/docs/$all ||ytrytx17x.s3.us-east-2.amazonaws.com/p-17-4.dll$all ||yunwu.sx/wp-admin/meggkxntjj8h/$all ||yurdumaku.com/blogs/zqawwa/$all ||yushilimited.uk/content/ptclzsyp48/$all +||yuwaraja.vokasi.ub.ac.id/vendors/https://document/4tb6lng9d2aaadfd/$all +||yuwaraja.vokasi.ub.ac.id/vendors/https:/document/4tb6lng9d2aaadfd/$all +||yuwaraja.vokasi.ub.ac.id/vendors/overview/5utm325651630390125u6bd6ce4nkpml62pph/$all ||ywhmcs.com/110244.exe$all ||zardoubbeauty.com/fullcalendar-bs3-php-mysql-master/d/$all ||zasobygwp.pl/redirect?sig=f88a745272587f579e8ce173b9952c32f161eb9733ec249031b854898cd62375&url=ahr0cdovl2rhbmlydmlucghvdg9ncmfwahkuy29tl3dlzgrpbmcvrklmrs94ohp5nm9nni8=&platform=desktop&brand=wp/$all